| MC692755 | Data Loss Prevention – Out-of-box Advanced Hunting queries for Data Loss Prevention incidents in Microsoft 365 Defender |
|---|
| Classification | stayInformed |
|---|---|
| Last Updated | 11/23/2023 00:21:43 |
| Start Time | 11/23/2023 00:21:04 |
| End Time | 03/31/2024 07:00:00 |
| Message Content |
Organizations can click the “Go Hunt” dropdown from the DLP alert page in Microsoft Defender XDR and select from a list of pre-populated queries for common scenarios such as understanding if a file is shared externally, participants of a Teams meetings, and more.
This message is associated with Microsoft 365 Roadmap ID 185708
[When this will happen:] Rollout will begin in late November and is expected to be complete by early December. [How this will affect your organization:]
Note: In this example, we have a SharePoint alert, so the Go Hunt options provided are high value queries such as File shared with, File activity, etc. For alerts from other locations such as Exchange, Teams, and Endpoint, you will see unique out-of-box queries relevant to those alert types.
[What you need to do to prepare:]
There is nothing you need to do to prepare, the “Go Hunt” option will be available in the DLP alerts experience in the Microsoft Defender XDR portal. You can also learn more about Advanced hunting for Microsoft Purview Data Loss Prevention (DLP) incidents – Microsoft Community Hub in the blog post we recently published. |