21.1 Respond to DLP Alerts in the Microsoft Purview Portal
Key Takeaways
- Every DLP alert moves through Trigger, Notify, Triage, Investigate, Remediate, and Tune; the Purview DLP dashboard retains alerts for 30 days while Defender incidents are retained for six months.
- Microsoft recommends Defender XDR for investigating and managing DLP alerts and the Purview portal for creating and editing DLP policies; Purview uniquely supports an Investigating status and shareable event links.
- Dashboard access requires the Manage alerts role plus DLP Compliance Management or View-Only DLP Compliance Management; matched sensitive content requires Content Explorer Content Viewer (Data classification content viewer).
- The Events tab records the matched item, sensitive information types, whether the user overrode a policy tip, and the override justification; mark a true match or a false positive from Actions.
- User activity summary appears only when Insider Risk Management data sharing is On and the user is in an IRM policy, covering up to 120 days of exfiltration activity.
When a Microsoft Purview Data Loss Prevention (DLP) rule matches, the product can raise an alert so an information security administrator can decide whether sensitive data actually left the organization, whether a user overrode a policy tip, or whether the match is a false positive that should drive policy tuning. Exam SC-401 tests this as an operational skill: you must know the alert lifecycle, which portal to use for which job, which roles see the matched item, and how to document disposition without inventing unpublished product limits.
The six-step DLP alert lifecycle
Microsoft documents every DLP alert—and your interaction with it—as moving through six steps: Trigger, Notify, Triage, Investigate, Remediate, and Tune.
Trigger. The life of a DLP alert starts when the conditions in a policy are matched. Typical reasons to generate an alert include sensitive information (personally identifying data or intellectual property) leaving the organization, inappropriate internal or external sharing, and risky endpoint activity such as downloading sensitive files to removable media. The match fires the actions defined on the rule; an alert is created only if that rule is configured to raise one.
Notify. The generated alert is sent to the DLP alert management dashboard in the Microsoft Purview portal and, for eligible tenants, into the Microsoft Defender portal as an incident. Policies can also email users, administrators, and other stakeholders. In this phase Purview reports DLP policy matches and user overrides. Use Activity explorer (previous chapter) to filter DLP-related activities for reporting or export. Microsoft states that the Microsoft Defender portal retains incidents for six months, while the DLP alert management dashboard retains alerts for 30 days. Your organization's audit log retention policy also controls how long an alert remains visible in the console.
Triage. Analyze the alert and associated logs and decide whether it is a true positive or a false positive. For a true positive, set priority from severity and business impact and assign an owner. For a false positive, unblock the user if a policy action is blocking them and move to the next alert. Defender groups related DLP events into incidents. A classic correlation example from Microsoft: a user downloads a sensitive file from SharePoint, uploads it to a personal OneDrive, and shares it externally—those related DLP alerts can land in a single incident so you triage the story, not three disconnected rows.
Investigate. The assigned owner correlates evidence, determines cause and full impact, and decides on a remediation plan. Primary tools are the Microsoft Defender portal and the Purview DLP Alerts dashboard; Activity explorer and Content explorer add context. Evidence collection for file activities on devices makes matched files (email and documents) easier to retrieve for review.
Remediate. How you respond depends on accuracy (true positive, false positive, or false negative), severity, and impact on the organization. Microsoft's published options include monitor-only with no further action, no further action because the policy already mitigated the risk, user education after an automated block, additional cleanup when the policy did not fully contain the issue, and assigning an Insider Risk Management (IRM) risk level through Adaptive Protection.
Tune. Feed investigation outcomes back into the policy intent statement and configuration: scope, match conditions, actions, and notifications. A cluster of justified overrides or false positives is a signal to tighten SITs, add exceptions, or change from block to tip—not a signal to ignore the queue.
Which portal does which job
Microsoft's current guidance is explicit. The Microsoft Defender XDR dashboard is the recommended location for investigating and managing DLP alerts. The Microsoft Purview portal is the recommended location for creating and editing DLP policies. SC-401 still expects you to operate the Purview Alerts dashboard because that is where you can set an alert status to Investigating, create a shareable event link for someone who does not have DLP console access, and download OneDrive or SharePoint files when you hold the data classification content viewer role.
The Purview portal shows DLP alerts for policies enforced on Exchange email, SharePoint sites, OneDrive accounts, Teams chat and channel messages, devices, instances, on-premises repositories, and Fabric and Power BI. Endpoint DLP and Teams DLP alerts appear in the same DLP alert management dashboard when the tenant is eligible for those locations.
If you are an administrative unit (AU) restricted admin, you see only the DLP alerts for your administrative unit. That AU restriction also flows into the Defender portal (section 21.3).
Permissions versus matched content
To view the DLP alert management dashboard or to edit alert configuration on a DLP policy, you must be in one of these role groups: Compliance Administrator, Compliance Data Administrator, Security Administrator, Security Operator, Security Reader, Information Protection Admin, Information Protection Analyst, or Information Protection Investigator. Applicable Information Protection role groups include Information Protection, Information Protection Admins, Information Protection Analysts, and Information Protection Investigators.
To access the DLP alert management dashboard you also need the Manage alerts role plus either DLP Compliance Management or View-Only DLP Compliance Management.
Seeing that an alert fired is not the same as seeing the matched item. Content preview and the Matched sensitive content and context features require membership in the Content Explorer Content Viewer role group, which has the Data classification content viewer role preassigned. If an admin must see alerts but not the sensitive snippets, create and assign a custom role that omits Data Classification Content Viewer. Download of OneDrive and SharePoint files from an alert also requires the data classification content viewer role.
Investigate an alert in the Purview dashboard
Sign in to the Microsoft Purview portal, open Data loss prevention, then Alerts. Filter the queue, customize columns, and double-click an alert.
- The Details tab opens by default with high-level metadata.
- Summarize with Copilot (when licensed) returns alert severity, title, matched policy name, file name and a link to the file, alert status, and the email address of the user who performed the matching action.
- View details opens the Overview tab: what happened, who performed the actions, and additional policy-match information. From Overview you assign ownership, add comments, and manage disposition. Workflow history is visible here.
- The Events tab lists every event in the alert. Open an event for location (workload), time of activity, user, and entity details such as file path, SHA-1/SHA-256 and device ID on endpoints, or email subject, recipients, and attachments on Exchange. Policy details include DLP policy matched, rule matched, sensitive information types (SIT) detected, actions taken, violating action (endpoint), user overrode policy, and override justification. Use the Actions menu to record whether the event is a true match or a false positive. Open Details to see Other matched conditions (for example recipient domain, document name, or Has sender overridden the policy tip). Endpoint matched-condition data requires Windows 10 x64 (build 1809 or later) or Windows 11, auditing, and Advanced classification scanning and protection; Microsoft documents it for valid E3 and E5 license holders.
- The User activity summary tab appears only when sharing is turned On in Insider Risk Management settings and the user is in scope of an IRM policy. It lists that user's exfiltration activities for up to the past 120 days.
- After you take the required action, set Status to Resolved. While work is in flight, Purview lets you set status to Investigating—a status name the Defender alert model does not use.
You can copy a shareable event link from Actions so a manager or data owner can review one event without DLP console access.
In preview, the Alert Triage Agent view groups alerts as All, Needs attention, Less urgent, or Not categorized. If an alert contains multiple assets, the agent summarizes the top 10 assets that drove the finding. After review, Manage alert assigns an analyst, changes status, or adds comments.
Alert types, aggregation, and timing traps
| I want DLP to… | Window | Aggregation |
|---|---|---|
| One alert when any users send credit-card email (default single-event) | Not admin-configurable: 60 seconds (E5) or 15 minutes (E3) | User-based aggregation Off; multiple users can collapse into one alert for one rule |
| One alert per sender for the same rule | Tenant-configurable 15, 30, 45, or 60 minutes (preview) | User and rule based aggregation On; closing the alert inside the window can still absorb a new match for the same user and rule |
| Alert when a count or volume threshold is met | Rule-level 60–999 minutes | Threshold aggregation; Microsoft documents this for the All users option |
Single-event alerts suit low-volume, high-sensitivity matches (one email with 10 or more customer credit card numbers). Aggregate-event alerts require A5, E5/G5, or an E1/E3 (or G1/G3) subscription plus a qualifying add-on such as Office 365 Advanced Threat Protection Plan 2, Microsoft Purview Suite, or the Microsoft 365 eDiscovery and Audit add-on. Example: 10 emails each with one credit card number sent outside the org over 48 hours, or more than 25 MB exfiltrated by multiple users within 60 minutes.
Two published timing facts are frequent exam traps. It may take up to 3 hours to generate alerts after you configure or modify alert settings in a DLP policy. An alert email, incident report email, and user notification are sent only once per document—sharing the same item twice under a Content is Shared condition still produces one notification.
You generally cannot download an email from an alert when it was deleted: internal-to-external deleted by the sender, external-to-internal deleted by the recipient, or internal-to-internal deleted by both parties.
Do not confuse this DLP Alerts dashboard with Microsoft Defender for Cloud Apps file policy alerts; those are the next chapter.
A compliance analyst opens the Microsoft Purview DLP Alerts dashboard on day 45 to re-check an alert that was never resolved. The same match is still visible as an incident in Microsoft Defender XDR. What should the analyst expect?
An Information Protection Investigator can open DLP alerts but cannot see the matched sensitive snippets or download the SharePoint file from the alert. Which additional access does Microsoft document for content preview and matched sensitive content?
On a DLP alert in Purview, the User activity summary tab is missing even though Events shows a clear SharePoint exfiltration match. What must be true before that tab appears?