Share via

Partial Matching in Activity Explorer

Mitch Silberstein 70 Reputation points
2025-10-06T22:16:17.1333333+00:00

I am working in Activity Explorer in Purview. If I filter by "DLP Rule Matched", I get a lot of results for the OneDrive location. If I go into the alerts though, it is not actually hitting all my conditions for the DLP rule even though they have an AND operator. I have verified my condition in the DLP policy is looking for when "Content is shared from Microsoft 365" to external users, but these matches do NOT show that condition.

Does the activity for DLP Rule Matched also show partial DLP rule matches? If yes, what is the source for this information?

Microsoft Security | Microsoft Purview
0 comments No comments

Answer accepted by question author

Jack Dang (WICLOUD CORPORATION) 18,970 Reputation points Microsoft External Staff Moderator
2025-10-07T04:18:53.7466667+00:00

Hi @Mitch Silberstein ,

Thank you for your question and for providing the details. I understand how it can be confusing to see many events in Activity Explorer for a DLP rule when it seems like not all conditions are met.

Here’s some clarification:

  1. Activity Explorer shows DLP matches at a detailed level
    • The events you see in Activity Explorer come from Microsoft 365 audit logs, which record activities related to DLP policies.
    • Some events labeled “DLP Rule Matched” may represent partial matches - meaning only some conditions of your rule were met. They appear for visibility and audit purposes, but they may not constitute a full DLP violation.
  2. Understanding partial vs full matches
    • Your DLP rule uses an AND operator, so technically a violation occurs only when all conditions are met.
    • Activity Explorer may still list events where only some conditions are satisfied, which is why you see entries that don’t fully meet your condition “Content is shared from Microsoft 365 to external users.”
  3. Verifying full matches
    • To check which conditions actually triggered, you can review the alert details in the DLP alerts interface in Purview. This will show which part of the rule matched the activity.
  4. Source of the data
    • These events are derived from the Microsoft 365 audit logs captured by Purview. They include information on the user action, file, location, and which DLP conditions were triggered (fully or partially).

In short: Activity Explorer may display partial DLP matches for audit purposes, and you should confirm full rule matches in the alert details.

Hope this helps! If my answer was helpful - kindly follow the instructions here so others with the same problem can benefit as well.

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.