[Introduction]
We’re introducing Phase 2 of always-on diagnostics for Endpoint Data Loss Prevention (DLP). This update enables admins to collect diagnostic traces directly from Windows endpoints and upload them to Microsoft through the Purview portal during support investigations—without involving the employee or information worker . This improves troubleshooting efficiency and helps resolve support cases faster.
This message is associated with Microsoft 365 Roadmap ID 499431.
[When this will happen]
- General Availability (Worldwide): We will begin rolling out in early March 20265 and expect to complete by mid-March 2026.
[How this affects your organization]
Who is affected
- Admins who manage Endpoint DLP in Microsoft Purview
- Organizations using Windows endpoints with Endpoint DLP enabled
What will happen
- Admins can request and retrieve always-on diagnostics directly from Windows endpoints using the Purview portal.
- Users are not interrupted, and no device-side interaction is required.
- Diagnostic traces can be uploaded directly to Microsoft Support using a request number.
- The change reduces time to reproduce issues, collect logs, and resolve support cases.
- Existing Endpoint DLP policies and enforcement remain unchanged.
- This feature requires admin enablement; it is not automatically turned on. Learn more: Always-on diagnostics for Endpoint DLP.
[What you can do to prepare]
- Review the documentation for configuring always-on diagnostics for Endpoint DLP.
- Enable the feature for your organization if you plan to use the enhanced troubleshooting capabilities.
- Update internal helpdesk documentation to ensure support staff know how to request traces from the Purview portal.
- Share the Learn documentation with admins who manage Purview or DLP policies.
Learn more: Always-on diagnostics for endpoint DLP | Microsoft Purview | Microsoft Learn
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
Source: Microsoft
Latest Posts
- Introducing the Amazon EKS Hybrid Nodes gateway for hybrid Kubernetes networking

- Amazon CloudWatch Logs Insights introduces JOIN and sub-query commands

- Amazon Location Service now offers bulk address validation for the United States, Canada, Australia, and the United Kingdom

- AWS Glue now supports OAuth 2.0 for Snowflake connectivity

![Endpoint Data Loss Prevention: Always-on diagnostics for Windows endpoints (Phase 2) [MC1246003] 1 Endpoint Data Loss Prevention: Always-on diagnostics for Windows endpoints (Phase 2) [MC1246003]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-icesky08-1294229-1024x683.webp)




![(Updated) Upcoming change: disabling Teams meeting recording expiration notification emails [MC1245635] 7 (Updated) Upcoming change: disabling Teams meeting recording expiration notification emails [MC1245635]](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-alfonso-escalante-1319242-2533092-96x96.webp)