20.4 Analyze Purview Activities with Activity Explorer

Key Takeaways

  • Activity explorer reports up to 30 days of labeling, DLP, auto-labeling, and Endpoint DLP activity transformed from the unified audit log
  • It is not real time: core workloads typically appear in 60 to 90 minutes, matching audit ingestion
  • Content explorer shows where classified items live now; Audit search covers broader and older activity; eDiscovery preserves and searches content
  • Filter dropdowns are built from the first 500 records, and endpoint events show only the most restrictive DLP rule
  • Activity explorer cannot place a legal hold or inherit Audit (Premium) one-year retention; export with Export-ActivityExplorerData still covers only about 30 days
Last updated: August 2026

Analyze Purview Activities with Activity Explorer

Quick Answer: Activity explorer is a 30-day, filter-driven view of labeling, DLP, auto-labeling, and Endpoint DLP activity. It reads transformed unified audit log records — it is not real time, not a legal hold, and not a replacement for Audit search or eDiscovery. Use it to see what people did with classified content. Use Content explorer to see where classified files sit. Use Audit when you need older or non-classification events.

Open Activity explorer in the Microsoft Purview portal under information protection / data classification. It answers operational questions: who applied, upgraded, downgraded, or removed a sensitivity label; which DLP rule matched; whether a file was copied to a USB drive or printed; whether Endpoint DLP blocked egress. Microsoft's Activity explorer article was updated 2026-07-23 and still publishes the 30-day reporting window.

What Activity explorer is — and is not

Activity information comes from the Microsoft 365 unified audit logs, is transformed, and is presented with about 50 filters. That 30-day window is independent of Audit (Premium) one-year retention. A label event from 90 days ago may still exist in Audit search and still be gone from Activity explorer.

It is not live. Core workloads (Exchange, SharePoint, OneDrive, and Teams) typically appear in 60 to 90 minutes, matching audit ingestion. Other services can take longer; Microsoft does not guarantee a specific availability time. After you enable a DLP or auto-label policy, wait for the policy to reach the workload and for events to flow. An empty view right after a policy change usually means the pipeline has not caught up, not that the policy failed. Offline devices report Endpoint DLP activity only while they are online and backfill after they reconnect.

If a recent activity is missing, confirm it falls within 30 days, wait for audit latency, then search for the same activity in Audit before you treat the gap as a defect.

Activity explorer versus Content explorer, Audit, and eDiscovery

SC-401 expects you to pick the right pane for the question. These four tools overlap in the portal and confuse candidates.

ToolQuestion it answersTypical window Microsoft publishesHolds content?
Activity explorerWhat did users do with labeled or DLP-matched items?Up to 30 daysNo
Content explorerWhere do labeled or SIT-matched items live right now?Current snapshot (counts can lag; Microsoft cites up to 7 days, and 14 days for some SharePoint files)No; preview requires extra viewer roles
Purview AuditWhat user and admin operations occurred across Microsoft 365?180 days Standard; up to 1 or 10 years with Premium / add-onNo
eDiscoveryWhat content is responsive, and how do we preserve it?Case- and hold-scopedYes, via holds

Content explorer is a catalog of items that have a sensitivity label, retention label, or sensitive information type. Access to the tab and access to item contents are separate: Content Explorer List viewer sees locations; Content Explorer Content viewer can open item content (and is also required to see names that may contain sensitive data). Those roles are not the same as Activity explorer's Information Protection roles.

eDiscovery (SC-401 wording as of 28 July 2026 uses eDiscovery search, not the older Content search label) is how you search and preserve mailbox and site content. Activity explorer cannot place a hold, collect a review set, or export a mailbox PST.

Audit is the system of record for sign-ins, mailbox rules, admin cmdlets, and classification events older than 30 days. Activity explorer is a convenience UI over a subset of those audit records.

Microsoft Purview Posture Reports for Information Protection, DLP, and DSPM also use a rolling 30-day window. Do not confuse those dashboards with Audit retention.

Data classification analytics UIs (Content explorer and Activity explorer) require E5 / A5 / G5 licensing (or Office 365 E5 / listed compliance add-ons). E3 tenants still aggregate Content explorer data, but the analytics interfaces are an E5-tier feature.

Filters, filter sets, and published limits

Filters include date range, activity type, location, sensitivity label, user, client IP, device name, and whether the item is protected. Open the filter pane to see the full dropdown.

Microsoft publishes two performance limits you should remember:

  • Filter dropdown values are built from the first 500 records, so some values may be missing from the list even if they exist in the dataset.
  • For endpoint events, only the most restrictive DLP rule is shown, and filters operate on that rule.

Predefined filter sets include Endpoint DLP activities; sensitivity labels applied, changed, or removed; egress activities; DLP policies that detected activities; network DLP activities; and Protected Browser. You can save your own combinations.

In preview, Microsoft Security Copilot in Purview can turn a natural-language prompt such as "files copied to cloud with sensitive info type credit card number for past 30 days" into a filter set. Treat Copilot output as a draft: review the generated filters before you act.

Export longer-term copies with Export-ActivityExplorerData in Security & Compliance PowerShell. Microsoft still documents that Activity explorer reports on up to 30 days. There is no published switch that extends the explorer itself to 90 days or 1 year. For older classification forensics, search Audit or archive Office 365 Management Activity API output.

Which activities show up

Sensitivity and retention labeling from Word, Excel, PowerPoint, Outlook, SharePoint, OneDrive, Exchange (sensitivity labels only), the Microsoft Purview Information Protection client and scanner, and the MIP SDK includes:

  • Label applied, changed (upgrade, downgrade, or removed), auto-labeling simulation, and file read
  • Client and scanner extras: protection applied, changed, or removed; files discovered

Endpoint DLP on Windows 10, Windows 11, and the three most recent major macOS versions adds file deleted, created, copied to clipboard, modified, read, printed, renamed, copied to a network share, and accessed by an unallowed app.

DLP policy matches come from Exchange, SharePoint, OneDrive, Teams chat and channels, and on-premises SharePoint folders, libraries, and file shares when those locations are in policy.

Microsoft also publishes gaps you should not invent around:

  • Activity explorer does not monitor retention activities for Exchange.
  • Legacy Azure Information Protection labels can appear as GUIDs.
  • Power BI labeling events are not in Activity explorer; use the audit log.
  • Microsoft Defender for Cloud Apps labeling is not in Activity explorer.
  • Outlook does not report sensitivity-label file-read events here.
  • SharePoint and OneDrive do not report sensitivity-label file read or file renamed in this UI.
  • A recommended-label tooltip is not logged until the user applies the label (How applied = Recommended).
  • After you delete a sensitivity label, historical events remain for the 30-day window, but the name becomes the label GUID.
  • A Teams DLP false-positive report shows as DLP info without rule or policy match details and does not generate an incident report.

For Exchange DLP, preview enhanced matched conditions show non-SIT condition name, matched value, and source (header, envelope, or attachment) on the event flyout.

Look at DLPRuleMatch next to the user egress event (CopyToClipboard, CloudEgress). The user-activity record has policy details; DLPRuleMatch has the contextual snippet around the match. Endpoint contextual summary requires the Windows updates Microsoft lists for that feature.

A policy that allows an activity without auditing it still creates an Activity explorer event for the action, but it does not create a DLP-rule-matched event or an alert. Only audited matched rules produce match events and alerts.

Permissions and investigation workflow

An account must be explicitly assigned membership in a documented role or role group. Purview roles: Information Protection Admin, Analyst, Investigator, or Reader. Role groups: Information Protection, Investigators, Analysts, or Admins and Readers together. Microsoft 365 roles: Compliance Admin, Security Admin, Compliance Data Admin. Role groups: Compliance Administrator, Security Administrator, Security Reader.

A practical investigation path:

  1. Pick the question: label downgrades, USB copies, or DLP matches.
  2. Apply a filter set, then narrow by user, device, label, or sensitive information type.
  3. Open the event flyout. For endpoint DLP, pair the egress activity with DLPRuleMatch.
  4. If you need item preview, switch to Content explorer (with viewer roles) or the file's site.
  5. If the event is older than 30 days, or is a sign-in, mailbox rule, or admin cmdlet, switch to Audit.
  6. If legal preservation is required, create an eDiscovery hold. Activity explorer will age out in 30 days regardless of that hold.

Exam traps

  • Activity explorer is not Audit (Premium) and does not inherit one-year audit retention.
  • It is not Content explorer: explorer shows activity, Content explorer shows items at rest.
  • It is not eDiscovery and cannot legally hold mailboxes.
  • Thirty days is the published Activity explorer window; do not invent a 90-day Activity explorer retention.
  • Filter dropdowns can omit values beyond the first 500 records.

Official resources

Loading diagram...
Which Purview tool to open
Test Your Knowledge

How much historical data does Microsoft say Activity explorer reports on?

A
B
C
D
Test Your Knowledge

A compliance analyst needs to see which SharePoint files currently have the Highly Confidential sensitivity label. Which tool is the right first stop?

A
B
C
D
Test Your Knowledge

Why is Activity explorer the wrong tool to preserve a departing employee's mailbox for a legal matter?

A
B
C
D