Skip to Content

DLP Alerts

Monitor and investigate Data Loss Prevention policy matches and incidents across Microsoft 365 services.

Alert Dashboard

  • Total alerts — All DLP alerts in the selected period
  • High severity — Critical policy violations
  • Pending review — Alerts awaiting investigation
  • Resolved — Investigated and closed alerts

Alert Details

FieldDescription
PolicyDLP policy that triggered the alert
RuleSpecific rule within the policy
SeverityHigh, Medium, Low
UserUser who triggered the match
ContentFile, email, or message with sensitive data
Action takenBlocked, notified, or logged

Investigation Workflow

  1. Review alert details and matched content
  2. Verify true positive or false positive
  3. Take action (escalate, dismiss, or remediate)
  4. Update alert status and add notes

API Reference

  • GET /api/security/dlp/alerts — List DLP alerts
  • PUT /api/security/dlp/alerts/:id — Update alert status
Last updated on