Microsoft has enriched Exchange Online DLP alerts and Activity Explorer to display every condition that contributed to a policy match—not just the sensitive data type. The feature, listed as launched in the Microsoft 365 Roadmap (ID 562051), gives security teams full context, including sender/recipient details, subject keywords, attachment properties, and message headers, starting with preview availability in May 2026 and general availability in June 2026.

For years, investigators staring at a DLP alert saw only that a Social Security number or credit card number triggered the policy. They then had to stitch together the rest of the picture—who sent it, to whom, whether an attachment was involved, and which other rule conditions were satisfied—often by jumping to message tracing, audit logs, and raw policy definitions. That extra legwork is now sharply reduced.

What Actually Changed

Previously, a Purview DLP alert for Exchange Online would flag the Sensitive Information Type (SIT) that matched—say, “U.S. Social Security Number”—but would not surface the additional Exchange-specific conditions that completed the rule match. A policy might include conditions like “sender is in finance department,” “recipient is outside the organization,” “subject contains ‘payroll’,” or “attachment is a password-protected Excel file.” The alert showed only the SIT, forcing analysts to manually reconstruct the full decision logic.

Now, every non-SIT condition that actually contributed to a policy match appears directly in the DLP alert and the corresponding Activity Explorer event. This includes sender and recipient domains, subject and body keyword matches, attachment characteristics, message headers, and other message properties. The enriched data answers critical questions without needing to pivot to separate investigation tools.

Why This Matters for Investigations

The difference is between knowing what was detected and understanding why the policy fired. Consider a rule intended to prevent the payroll team from emailing bank account details to personal addresses. A match involving a sensitive data type plus an external recipient, a sender from the finance department, and a subject line containing “wire” is a very different scenario from one where an internal user tested a dummy number in a non-sensitive context.

With the new context, a triage analyst can distinguish high-risk incidents in seconds rather than minutes. For example:

  • A match involving a trusted partner domain may point to a policy exception or a known business process.
  • A match with an unknown external recipient, a confidential subject phrase, and a compressed attachment may warrant immediate escalation.
  • Recurring matches from an automated system account may indicate the DLP rule needs refining, not that data is leaking.

The context also makes false-positive dismissal faster and more defensible. Instead of guessing, analysts can see exactly which conditions lined up, document their reasoning, and tune the policy accordingly.

The Conditions Now Visible

Microsoft’s Exchange DLP condition model is broad. The enrichment surfaces:

  • Sender and recipient context: Addresses, domains, membership in specific distribution groups, or directory attributes from Entra ID.
  • Subject and body keywords: Specific words or patterns that elevated the risk beyond the SIT alone.
  • Attachment characteristics: File extensions, whether an attachment is password-protected or unscannable, document size, and content signals.
  • Message headers and properties: Auto-forward status, message importance, encrypted/SMIME indicators, and message type (e.g., automatic reply, calendar item, approval request).

All of these can now appear in the alert record, making the policy’s reasoning transparent. An auto-forward condition combined with a financial SIT, for example, tells a very different story from a normal user-composed message.

What It Means for Your Organization

For Security and Compliance Analysts

Triage becomes substantially faster. You can assess severity at a glance, prioritize incidents that combine sensitive data with risky contexts, and document evidence with fewer manual steps. Activity Explorer gains similar benefits: reviewing a timeline of matches now reveals patterns based on sender domains, subject keywords, or attachment types, not just a flat list of SIT hits.

For DLP Administrators and Policy Tuning

Audit-mode testing becomes far more practical. When you pilot a new policy, you can see exactly which conditions are triggering matches. If a policy generates excessive alerts because a subject keyword is too generic or a recipient domain catches a legitimate partner, you can adjust it with confidence instead of guessing. The enriched data creates a stronger audit trail for regulatory or internal reviews, showing precisely how a policy reached its conclusion.

For Privacy and Access Management

Richer metadata means you must revisit role-based access. The Purview roles required to see alerts—Manage alerts plus DLP Compliance Management or View-Only DLP Compliance Management—now expose more operational detail. Sender and recipient domains, keywords, and attachment descriptors can reveal sensitive business relationships or project code names. Ensure that only staff with a genuine need have access, and distinguish between analysts who triage, investigators who need content previews, and auditors who only require summarized evidence.

How We Got Here

Exchange Online has long been the top channel for accidental data disclosure. Purview DLP policies have combined conditions and actions for years, but the alerting experience lagged behind the policy engine’s sophistication. Early versions of DLP alerts surfaced only the detected data types, forcing investigators to manually correlate policy rules with events. Microsoft gradually added more metadata, but this update represents the first time that all contributing conditions appear in one place without extra hops.

The feature aligns with broader industry demands for explainable security controls. As regulators increasingly expect organizations to demonstrate not just that they protect data but how and why specific actions were taken, transparent audit records become critical.

What to Do Now

  1. Validate the feature in your tenant. Use a non-production DLP policy scoped to Exchange Online. Send test messages that separately trigger SIT-only matches, sender-domain matches, recipient-domain matches, keyword matches, and attachment matches. Check that the enriched context appears in alerts and Activity Explorer.

  2. Review role assignments. Audit who has access to DLP alerts and Activity Explorer. Ensure that visibility into sender domains, recipients, and keywords is limited to staff who require it. Consider creating separate role groups for policy managers vs. incident triage vs. deep investigation.

  3. Tune existing policies with real context. Switch high-volume policies to audit mode temporarily. Use the enriched data to spot overly broad keyword triggers, unintended sender or recipient matches, and attachment conditions that generate noise. Adjust conditions, exceptions, or alert thresholds based on what you actually see.

  4. Adjust alert volume and aggregation settings. Reduce alert fatigue by moving low-risk patterns (e.g., internal test messages) to aggregated alerts, while keeping individual alerts for combinations involving external recipients, sensitive subjects, and attachments.

  5. Handle data sensitivity in ticketing and documentation. When copying alert details into incident tickets, be mindful that subject keywords, sender domains, and attachment names may themselves be confidential. Redact as necessary and train staff to treat alert context with the same care as email content.

Outlook

The enriched data feature is currently listed as launched, with preview in May 2026 and general availability in June 2026. Microsoft continues to refine the experience, and documentation may still reference “preview” in some places. Expect further enhancements that bring similar context to DLP alerts for other workloads like SharePoint, OneDrive, and Teams, making policy matches explainable across the entire Microsoft 365 ecosystem. For now, this improvement turns Exchange Online DLP alerts from opaque triggers into understandable, actionable events—a long-overdue step toward mature data protection operations.