A secure digital government portal displays a document and verified identity checks beside the U.S. Capitol.
Microsoft Purview has added a file-testing feature that answers a question every data loss prevention (DLP) admin runs into sooner or later: which classifiers actually match this file? Microsoft 365 roadmap item 566323 describes a new option on the main Classification page. You can test a file against one classifier, or against every available classifier at once, to find sensitive information and troubleshoot classification problems. Roadmap 566323 lists the release as Generally Available on the Web platform for GCC, GCC High and DoD, with general availability estimated for August 2026 and a status of Launched.

That cloud list matters. Commercial tenants were told about this months ago, so this entry is mainly news for government-cloud admins who have been waiting for the feature.

What the feature does​

Message center post MC1235742, as archived on community tracking sites, describes it as a new file-testing capability on Purview's main Classification page. It lets users test files against all available Sensitive Information Type (SIT) classifiers to identify sensitive content.

Microsoft's practical summary:

  • A new file-testing option will appear on the main Classification page in Microsoft Purview.
  • Users will be able to upload files and test them against one or all SIT classifiers.
  • The feature is meant to show which classifiers match sensitive content within files.
  • It will be automatically enabled in all tenants, and no policy changes are required.
  • Existing DLP and classification configurations will continue to function as they do today.

The message names the audience as admins and users working with Microsoft Purview Data Loss Prevention (DLP) and data classification capabilities.

In short, this is a diagnostic tool, not an enforcement change. Nothing in Microsoft's description says that uploading a test file triggers a policy action, and your existing rules keep working as before.

The government-cloud timeline​

The rollout reached different clouds at different times:

ItemCloudsTiming
MC1235742 (message center)Tenants generally ("all tenants")CloudScout's summary of the message puts the rollout from late February to April 2026
Roadmap 566323GCC, GCC High, DoDThe M365 Admin roadmap tracker lists Release phase: General Availability, Release date: August CY2026, Platform: Web, Cloud Instance: GCC, GCC High, DoD, Created: 2026-06-18

Two caveats:

  • Roadmap dates are estimates. The Microsoft 365 roadmap describes its dates as estimated and says all information is subject to change. "Launched" with an August 2026 date means the rollout was planned and recorded. It doesn't prove the feature reached your specific tenant that month.
  • The commercial timeline comes from a third-party summary. The late-February-to-April window is CloudScout's summary of MC1235742. If you're in a sovereign cloud, check your own message center rather than relying on it.

Section summary: Commercial tenants were notified in early 2026. Roadmap 566323 covers the GCC, GCC High and DoD rollout, estimated for August 2026.

How it differs from the existing SIT test​

Purview could already test files against classifiers, but only one at a time, starting from the classifier. Microsoft Learn's page on testing sensitive information types (last updated June 22, 2026) documents this workflow:

  1. Prepare two files, for example two Word documents. One should contain content that matches your SIT and the other should contain content that doesn't.
  2. In the Microsoft Purview portal, go to Information Protection > Classifiers > Sensitive info types. Pick the SIT to open its details pane, then choose Test.
  3. Upload a file and choose Test. The documentation says you can only upload and run a simulation for one file at a time.
  4. Review the Match results page and choose Finish.
  5. Repeat for the second file.

Microsoft recommends running this simulation for every SIT you create before using it in a policy. The procedure only supports unencrypted files.

Exact Data Match (EDM) classifiers have their own similar path. Microsoft Learn says to sign in to the Microsoft Purview portal > Information Protection > Classifiers > EDM classifiers, make sure the New EDM experience toggle is on, then select your EDM SIT from the list and then select the Test icon.

Both of these start from a classifier you already suspect. You pick it, then test a file against it. The new Classification page option works the other way: you start with the file and get back the classifiers that match. That's the real change in roadmap 566323.

What we don't know yet: the per-SIT limits above (unencrypted files only, one file per run) are documented for the existing workflow. Microsoft's description of the new feature doesn't say whether the same limits apply. It also says nothing about supported file formats, size limits, how long tests take, or how long uploaded files are kept.

Section summary: The old test checks one chosen classifier against a file. The new option tests a file against one or all classifiers from the Classification page.

The PowerShell route still works​

Administrators who prefer a shell have had a broad testing option for a while. Microsoft documents Test-DataClassification on its EDM testing page, and notes that regardless of the method you use for testing, the test results will include matches for both the specific EDM SIT and for the primary elements that are configured for that EDM SIT.

Purview consultant Seppälä has written that the cmdlet takes a string of text and shows which confidence breakpoints it passed, and that you can test against all or specified SITs. So "test against everything" isn't new for people who script. What's new is a point-and-click version in the portal that works with real files instead of pasted text. That makes it usable for help desk staff and compliance analysts who don't use PowerShell.

Why admins should care​

DLP troubleshooting usually starts with a vague complaint: "Why did my spreadsheet get blocked?" or "Why wasn't this contract flagged?" A test that runs one classifier at a time only helps once you've guessed which classifier is involved. Testing against all classifiers removes the guessing. You can find:

  • Surprise matches. A built-in SIT may be matching content that looks like a credit card or national ID number but isn't.
  • Missing matches. If no classifier matches a file you expected to be flagged, the problem is probably in your SIT definition, not your policy.
  • Overlap. Several classifiers may match the same content, which affects how you set confidence levels and policy conditions.

Microsoft is clear about how far its support goes for custom SITs. Microsoft Learn says Customer Service & Support can't help create custom classifications or regex patterns. Support engineers can offer limited help, such as sample patterns or troubleshooting a pattern that isn't triggering, but they can't promise that custom content matching meets your requirements or obligations. For custom work, then, testing is how you check your own patterns. Microsoft also says Microsoft 365 SITs use the Boost.RegEx 5.1.3 engine, which is worth knowing when a regex that works elsewhere fails here.

Permissions​

Microsoft hasn't published a role list specific to the new Classification page option. The existing SIT test requires a qualifying role in both Purview and Exchange. The Purview role groups listed are:

  • Compliance Administrator
  • Compliance Data Administrator
  • Security Administrator
  • Communication Compliance Admins
  • Information Protection Admins
  • Information Protection Investigators
  • Organization Management

Microsoft Learn separately lists the qualifying Entra roles and Exchange Online role groups. Simulation mode is limited to Communication Compliance Admins, Information Protection Admins, Information Protection Investigators or Organization Management. These are reasonable roles to check first, but that's my inference: Microsoft hasn't confirmed that the new feature uses the same model.

Suggested way to try it​

This is my own advice based on Microsoft's per-SIT guidance, not an official procedure for the new feature:

  1. Make a positive and a negative test file, as Microsoft suggests for single SITs: one that should match and a near-identical one that shouldn't.
  2. Use synthetic data. Microsoft hasn't said how uploaded test files are handled or kept, so don't upload real customer records unless your internal policy allows it.
  3. Run a single-classifier test first, then the all-classifiers test, and compare the results.
  4. Write down unexpected matches before changing any policy. They often point to SIT tuning, not policy changes.
  5. Check encryption. If a file returns nothing, remember that the existing SIT test only supports unencrypted files. It's a sensible first thing to rule out, though Microsoft hasn't documented whether the new feature has the same limit.

Bottom line​

This is a modest but useful change. It doesn't touch your policies, and Microsoft says it's on by default. For GCC, GCC High and DoD admins, roadmap 566323 means the classify-first troubleshooting tool commercial tenants got earlier this year is now arriving in government clouds. Some details are still undocumented, including encrypted file handling, size limits and how long uploads are kept, so test it with synthetic data before relying on it.

 

References

  1. Microsoft Purview: Data Loss Prevention - File Testing Against Sensitive Information Classifiers Microsoft 365 Roadmap 2026-10-05T23:03:05.040986Z
  2. Test a sensitive information type | Microsoft Learn learn.microsoft.com
  3. Microsoft Purview: Data Loss Prevention - File Testing Against Sensitive Information Classifiers - M365 Admin m365admin.handsontek.net