Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent

Fournisseur
Microsoft
Produit
Microsoft Purview, Microsoft Entra
Type
Sécurité
Date annonce
2026-02-20
Date effet
Date non publiee
Impact
Concerné

En bref

Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent

Ce que dit la source

Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. - Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also - Agent Identity : Now the Triage agent can be deployed with Agent's own identity generated in Microsoft Entra. There won't be a need to have the agent run using the user's identity who was setting up the agent. This provides cleaner audit capabilities. GA date: April CY2026 Preview date: February CY2026 Launched General Availability Preview Worldwide (Standard Multi-Tenant) Microsoft Purview Web

Pour continuer

Lire la source primaire

Choisir votre lecture

Le rôle change l'angle de lecture, pas les faits, la date ni le niveau de preuve.

Lecture pour un commercial

Qui est concerné : The audience described by the Microsoft update is represented by: Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidat

Pourquoi c'est important : The change matters because the official source describes: Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidat

Urgence : Surveiller

Prochaine action : Review affected accounts with the customer using the official announcement.

Opportunités commerciales

  • Use the verified change to open a scoped customer conversation.

Actions techniques

  • Assess whether the documented change intersects the customer's current stack.

Questions à poser au client

  • Does this documented change affect a product or workload in scope?

Risques et objections

  • The official source does not establish facts beyond the quoted material.

Points à confirmer

  • The effective date is unknown and must be confirmed before scheduling action.

Preuves et traçabilité

Chaque extrait est relié à la source primaire et conservé pour vérification.

  • Capture brute
    2026-08-29T09:22:49.319599+00:00
  • Événement
    Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. - Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also - Agent Identity : Now the Triage agent can be deployed with Agent's own identity generated in Microsoft Entra. There won't be a need to have the agent run using the user's identity who was setting up the agent. This provides cleaner audit capabilities. GA date: April CY2026 Preview date: February CY2026 Launched General Availability Preview Worldwide (Standard Multi-Tenant) Microsoft Purview Web
    source
  • Produit Microsoft Purview
    Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. - Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also - Agent Identity : Now the Triage agent can be deployed with Agent's own identity generated in Microsoft Entra. There won't be a need to have the agent run using the user's identity who was setting up the agent. This provides cleaner audit capabilities. GA date: April CY2026 Preview date: February CY2026 Launched General Availability Preview Worldwide (Standard Multi-Tenant) Microsoft Purview Web
    source
  • Produit Microsoft Entra
    Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. - Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also - Agent Identity : Now the Triage agent can be deployed with Agent's own identity generated in Microsoft Entra. There won't be a need to have the agent run using the user's identity who was setting up the agent. This provides cleaner audit capabilities. GA date: April CY2026 Preview date: February CY2026 Launched General Availability Preview Worldwide (Standard Multi-Tenant) Microsoft Purview Web
    source
  • Insight un commercial
    Microsoft Purview: Data Loss Prevention – Enhancements to Data Security Triage Agent Adding below enhancements to Data Security Triage Agent in MS Purview - Metadata supported Custom Instructions (DLP only) : Earlier the agent only supported custom instructions which are related to content (E.g. Focus on alerts related to financial information). Now we also support instructions related to metadata. (E.g. Focus on alerts related to financial information for user Adam in last 20 days) - Consolidated Agent settings : Earlier we had seperate controls for deployment configuration and triggers. We are now merging them into a single view as the settings can be altered anytime and it becomes easier for admins and analysts to change them from single view. - Support for alerts with Non content contains condition (DLP only) : Till now we were showing alerts generated from non-content contains conditions as unsupported. (E.g. Condition = RecipientDomainIs matches and triggers alert, alert is unsupported). Now we are bringing the alerts into triage capability and determining categorization for them also - Agent Identity : Now the Triage agent can be deployed with Agent's own identity generated
    source

Retour au fil public