Release date: 1 September 2026 | Previous version: v26.5.4 (4 August 2026)
Scope: Changes since v26.5.4. The headline is a DLP rework: sources are configured with named policies instead of a single scope and action. This note also covers Data Owners accuracy and shared-mailbox handling.
Action required after upgrade. Existing DLP configuration is not read any more. A one-off migration converts each active source's current setup into a "Default" policy that behaves as before. Until it has run, sources have no policies and nothing is enforced. Sources whose action was Allow are left without a policy, because they were not acting on anything. No existing settings are deleted, so the upgrade can be rolled back.
Features
DLP Policies
DLP is configured with policies instead of a single setting per source
A policy combines a scope (everyone, selected people, groups or departments), the document classes it applies to, and what should happen when a match is found
A source can hold several policies in a priority order, so a stricter rule can cover one department while a lighter one covers everyone else
Policies can be created, edited, reordered and copied to other sources from the DLP Policies page
Everything downstream follows the policies: which mailboxes and sites are monitored, which Exchange rules exist, which Copilot users are watched, and what action an item receives
Audit log
The audit log shows which policy and which document classes decided each item, so enforcement can be traced back to the rule that caused it
Changes
Monitoring of mailboxes, sites and Copilot users now follows the policy scopes
Exchange rules are generated per scope; pattern and keyword-algorithm rules are retired
DLP reads large result sets in pages, so large tenants are no longer capped
Shared mailbox purpose is recorded when it can be resolved, plus a cleanup for mailboxes whose scope no longer matches
Bugfixes
Data Owners
A data owner is cleared once the account behind it no longer exists (fileshare)
Folders owned by a departed person are counted as unowned and appear under the orphan filter, instead of looking properly owned
A deliberately assigned owner is still respected even after the account is gone
Clearing a data owner is recorded as a withdrawal, so the previous owner is not written back on the next run
SharePoint subfolders whose folder name contains characters such as
&now appear on the Data Owners page
DLP
Mail left on hold and policies pointing at deleted document classes are reconciled automatically
Security
log4j was removed from the Java profiler