Microsoft Purview DLP: User-Based Alert Aggregation

User-based alert aggregation in Purview
One of the most frustrating parts of investigating DLP incidents isn’t always the policy itself; it’s the flood of alerts.
When the same user triggers multiple DLP events in a short period, we often end up piecing together several separate alerts to understand a single incident. It adds noise, slows investigations, and makes it harder to focus on what actually matters.
Microsoft is addressing this with a new user-based alert aggregation capability in DLP.
Instead of creating a separate alert for every event, related DLP events from the same user can be grouped into a single alert within a configurable time window, even if they match different DLP rules. The result is less alert fatigue and a better investigation context.
Once the feature rolls out in mid-August 2026, you can enable it from Settings > DLP settings > Alert settings > Event aggregation into alerts, choose User-based aggregation, configure the aggregation window, and save the settings.
 Microsoft Purview DLP: User-Based Alert Aggregation -
It doesn’t affect DLP policy enforcement; the policies continue to work as configured. This update only changes how related alerts are grouped for investigation.
Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.