MC1258000 | (Updated) Microsoft Purview: Data Security Investigations – analyze files tied to endpoint DLP alerts
- Service
- Microsoft Purview
- Last Updated
- 2026-07-21T18:21:04.59Z
- Published
- 2026-03-21T16:18:41Z
- Message ID
- MC1258000
Updated July 20, 2026: We have updated the timeline. Thank you for your patience. [Introduction] We’re introducing endpoint Data Loss Prevention (DLP) events as a queryable data source in Data Security Investigations (DSI) in Microsoft Purview. With this update, administrators can build endpoint DLP queries directly in DSI using filters such as date range, and DSI will automatically pull files associated with those events into the investigation for analysis. This integration helps security teams examine endpoint DLP activity at scale, reducing time and effort spent triaging individual alerts and improving the ability to identify patterns and potential data exfiltration scenarios. This messag...
Open Full Notification Browse Message CenterThis utility page supports direct lookup of Message Center ID MC1258000.