Forum Discussion

HaraldRau's avatar
HaraldRau
Iron Contributor
Aug 27, 2024

DLP rule match in activity explorer lacks info on detected trainable classifier

Our DLP policies are designed to trigger based on the condition to contain a built-in trainable classifier, such as Source Code, and are applied to Exchange email for all users. While we have not set up any actions or alerts, we do notify users who have sent the content, which works as expected.

 

These activities are logged in the Purview activity explorer as a DLP policy match. However, we've noticed an issue where the activity explorer, as well as the O365 Management API, do not reveal which trainable classifier was detected. Both the explorer and the API report the event but omit details about the triggering trainable classifier. We can reproduce this issue in two tenants.

 

See the screenshot from Activity Explorer where I have customized the columns to show the detected trainable classifiers.

I'm trying to determine if this issue is widespread or specific to our setup. Could anyone verify if they're experiencing the same problem or offer any advice on how to address it?

Thanks a ton in advance!

 

Regards, Harald 

 

1 Reply

  • HaraldRau's avatar
    HaraldRau
    Iron Contributor

    To further analyse this issue, we have activated alerts for the rule that exclusively detects a single built-in trainable classifier. While alerts are getting reported for these DLP policy matches, the detected trainable classifier is not reported back, see screenshot from Purview DLP alerts. 

     

     

Resources