decoded365
← All changes
PreviewMicrosoft Purview · Data Loss Prevention

Microsoft Purview: Data Security Investigations – analyze files tied to endpoint DLP alerts

Microsoft Purview is adding a new Data Security Investigations feature that allows admins to launch investigations directly from endpoint DLP alerts to analyze exfiltrated files. This preview capability streamlines the investigation workflow by automatically gathering files that triggered alerts based on specified parameters like time range, users, and endpoints.

Microsoft's description

Speed up analysis of exfiltrated content by launching Data Security Investigations (DSI) from endpoint Data Loss Prevention (DLP) alerts. In DSI, define your endpoint DLP query (for example, time range, users, and endpoints). DSI then automatically gathers the related files that triggered the alerts for review (for example, UserA downloaded a file on 3/1/2026).

View on Microsoft roadmap →