DLP reporting and alerting capabilities
There are several reporting and alerting capabilities for DLP available within the Microsoft Purview compliance center. Regularly reviewing these will give Microsoft 365 administrators valuable insights into how effectively DLP is configured and working. The reports that are available are as follows:
- DLP Policy Matches: This section shows a count of recent policy matches, all of which you can filter by date, location, policy, or action. Policy matches are shown in this report at a rule level, meaning that the report is better for identifying matches with specific rules and fine-tuning your DLP policies. Clicking into the tile will give you a broader view of the DLP policy match activity, along with related reports on DLP Incidents and DLP false positives and overrides.
- DLP Incidents: This report shows you policy matches over time at an item level. An example of this would be where an email matches different rules but the report shows...