Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1012244

Microsoft Purview | Endpoint Data Loss Prevention: New Allow and Off modes for each activity

Informational

Message ID

MC1012244
View in Admin Center

Roadmap ID

480731
View in Roadmap

Services

Microsoft Purview

Affected Platforms

Web

Summary

Microsoft Purview Endpoint DLP is adding two new modes, "Off" and "Allow," to the existing "Audit only," "Block," and "Block with override" options. The rollout will occur in March 2025. These modes will be available by default, and prerequisites include specific Defender Antimalware client versions. No admin action is required before the rollout.

Details

Before this rollout, Microsoft Endpoint data loss prevention (Endpoint DLP) supports Audit only, Block, and Block with override on the Create policy page in Microsoft Purview | Endpoint DLP. This rollout will add two new modes: Off and Allow.

This message is associated with Microsoft 365 Roadmap ID 480731.

When this will happen:

General Availability (Worldwide): We will begin rolling out early March 2025 and expect to complete by mid-March 2025.

How this will affect your organization:

The two new modes are:

  • Off: Endpoint DLP will not trigger events or Alerts and will not trigger notifications. You can use this enforcement mode to configure restrictions for a specific group.
  • Allow: Endpoint DLP will not trigger Alerts and will not trigger notifications but will trigger events in Activity explorer.

In Microsoft Purview, the new Allow and Off enforcement modes on the Create policy page for Endpoint DLP:

admin controls

The new modes will be available by default for admins to configure.

What you need to do to prepare:

You will need these prerequisites to use the new modes:

  1. All prerequisites in Onboard Windows devices into Microsoft 365 overview | Microsoft Learn
  2. A Defender Antimalware client version higher than 4.18.25010. To find the version of Microsoft Defender (Windows Defender) Antimalware, follow these steps:
    1. Open Windows Security.
    2. Click on the Settings gear icon.
    3. Look for the About link.
    4. The About page contains the version information for the Windows Defender components.

This rollout will happen automatically by the specified date with no admin action required before the rollout. Review your current configuration to determine the impact for your organization. You may want to notify your admins about this change and update any relevant documentation.

Timeline

📅
Published
Feb 21, 2025
Message published to Message Center
✏️
Updated
Feb 21, 2025
Message content updated
🏁
End Date
Jun 30, 2025
Message timeline ends

Tags

#New feature#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC1013459

Microsoft Purview | Information Protection: On-demand classification of files in SharePoint and OneDrive for business

Feb 21, 2025
MC1006621

Microsoft Purview | Insider Risk Management: New compromised user context in Microsoft Entra

Feb 15, 2025
MC1003343

Microsoft Purview | eDiscovery: Hold limits increased per Hold policy for eDiscovery Premium

Feb 11, 2025
MC1003342

Microsoft Purview | Endpoint Data Loss Prevention: Labeling improvement for non-Office files and PDF files

Feb 11, 2025
MC1000267

Microsoft Purview | Data Loss Prevention: New role for downloading original file evidence for Endpoint

Feb 7, 2025