Share via

DLP Policy Renamed in Defender Alerts Console in Microsoft Purview

ZTS 65 Reputation points
2026-06-09T15:45:09.9233333+00:00

Is there any official notification or internal communication regarding the automatic renaming of a DLP policy within the Defender Alerts section? We have reviewed the policy in Purview and compared it against the alerts generated in Microsoft Defender, but it appears that the Defender Alerts are being renamed. Could you clarify why this renaming is occurring?

Microsoft Security | Microsoft Purview
0 comments No comments

2 answers

Sort by: Most helpful
  1. Pilladi Padma Sai Manisha 9,945 Reputation points Microsoft External Staff Moderator
    2026-06-11T06:01:55.0866667+00:00

    Hi @ZTS

    There is currently no Microsoft documentation or official announcement indicating that Microsoft Defender automatically renames Microsoft Purview DLP policies.

    I recommend comparing the Policy ID or Rule ID in Purview and the corresponding Defender alert, as alerts may display historical or differently formatted metadata even when they reference the same policy.

    For reference:

    If the Policy ID matches but the displayed name differs, please consider opening a Microsoft support case with screenshots from both portals for further investigation.

    Was this answer helpful?


  2. AI answer

    2026-06-09T15:45:20.48+00:00

    The behavior is explained by how Microsoft Purview DLP handles policy and rule renames versus existing records.

    In preview, when the display name of a DLP policy or rule is changed in Purview, only new records (new activity explorer events, new alerts, new audit records) will show the updated name. Existing records keep the old name until they age out of the system:

    “You can change the display name of DLP policies and rules. Once you rename a policy or a rule, any existing records retain their previous name in activity explorer events, in alerts and in audit records. New records will reflect the new name in activity explorer events, in alerts and in audit records. These names will remain until the items age out of the system.” (Create and deploy data loss prevention policies)

    Because DLP alerts are surfaced both in the Purview DLP Alerts dashboard and in the Microsoft Defender portal, this rename behavior applies to what is seen in Defender as well:

    • Alerts generated before the rename continue to show the old policy/rule name.
    • Alerts generated after the rename show the new policy/rule name.

    This can look like “automatic renaming” in the Defender Alerts experience when, in fact, it is the result of a manual rename in Purview combined with the record-retention behavior across the two systems.

    There is no indication in the provided documentation of any separate, automatic renaming mechanism that would change policy names only in Defender; the visible change is driven by the Purview-side rename and the fact that existing alert records are immutable with respect to their stored policy name.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.