Purview IRM will filter temporary-file activity by filename pattern
Opening a file can set off more file operations than a person intended to perform. Windows and applications such as Microsoft Office and browsers may create, rename, and delete temporary files during ordinary work. Microsoft’s roadmap entry says the Endpoint client audits those operations, leaving Insider Risk Management (IRM) customers with high-volume activity that contributes little to an investigation.
The planned change is built-in filtering for well-known temporary-file naming patterns. Microsoft says matching Endpoint file operations will be excluded from IRM Activity explorer and risk scoring. Activity explorer is the view investigators use to examine a timeline of potentially risky behavior associated with an alert, so the proposal addresses both what analysts see and what contributes to the risk assessment.
This is a deliberately narrow description. Microsoft has described a filter for recognized names associated with temporary files, not a rule that treats every file in a temporary folder—or every routine Endpoint event—as harmless. The roadmap does not publish the patterns, name the affected file-operation types individually, or quantify the expected reduction in activity. Administrators cannot yet calculate how much of their own alert or investigation workload it will remove.
As of September 24, 2026, the feature is listed as In development. October’s preview and November’s general availability are planned months, not completed rollouts. The roadmap metadata lists a web platform and Worldwide, GCC, GCC High, and DoD cloud instances; it does not establish that each environment already has the filter or will receive it on the same day.
Existing IRM global exclusions solve a broader problem
Purview IRM already offers administrators ways to suppress unwanted activity through Global exclusions. Microsoft documents exclusions based on file paths, file types, and keywords, among other categories. Those settings require an administrator to define what should be ignored; the proposed feature would recognize specified temporary filename patterns without asking customers to approximate them using broader exclusions.
The scope of an exclusion determines its cost. A file-path exclusion prevents activities mapped to relevant indicators at that location from generating policy alerts. A file-type exclusion removes the specified type from matching and risk scoring across IRM policies. A keyword exclusion can match text in filenames, paths, or email subject lines, causing related activities to be ignored by policies. None is automatically a precise substitute for a filter aimed at particular temporary filenames.
Microsoft also documents default path exclusions under \Users*\AppData, including \Users*\AppData\Local\Temp. Those defaults address activity at specified locations. A temporary filename produced elsewhere presents a different matching problem, while excluding its entire folder or extension could suppress files an organization wants IRM to assess. Microsoft has not said that roadmap item 560601 will replace or alter the existing path defaults.
For a team already tuning IRM, that is the practical before-and-after: today it can choose customer-defined exclusions with their documented policy-wide effects; Microsoft plans a built-in rule aimed at a more specific source of Endpoint noise. It is a reason to review a proposed broad exclusion carefully, not a reason to remove an existing one before the new behavior can be checked in the tenant.
Risk scoring and investigation visibility need separate checks
The roadmap pairs two outcomes—removing matching operations from Activity explorer and excluding them from scoring—but IRM already has cases where excluded from scoring does not mean absent from every investigative view. Microsoft’s policy documentation says an excluded event can still be included when it forms a relevant step in a detected sequence, such as an obfuscation activity. Its Activity explorer documentation describes ways investigators can view events marked as excluded within sequences.
Those documents explain current exclusion behavior; they do not specify how the forthcoming temporary-file filter will interact with sequence detection. Treating the new filter as either a guarantee that matching events disappear everywhere or a guarantee that sequence views retain them would get ahead of Microsoft’s description. That interaction matters to investigators who depend on the order of file operations to understand an alert.
There is a second operational distinction: the roadmap describes changes to IRM Activity explorer and scoring. It does not describe a change to Windows file handling or establish what happens to records outside those IRM functions. Microsoft has not specified whether the filter is configurable, whether an administrator can turn it off, or whether it applies to earlier activity. These are release-time checks, particularly for teams with established investigation or record-retention procedures.
What this means for you
If temporary-file events are burdening your IRM investigations, keep existing exclusions as narrow as your policies allow and evaluate the built-in filter when it reaches your tenant. The immediate decision is whether a current exclusion hides more relevant activity than the noise it removes; the future decision is whether Microsoft’s filename filter handles your actual workflows well enough to change that exclusion. Microsoft documents the route for reviewing current settings in the Purview portal: Settings → Insider Risk Management → Global exclusions.
A useful preview evaluation would compare representative ordinary file-opening workflows with the security scenarios your IRM policies are meant to catch. Examine what appears in Activity explorer, what is scored, and what contributes to alerts. If sequence detection is part of your investigation process, check its treatment of matching operations as well. This is an evaluation plan, not a Microsoft-published setup procedure for roadmap item 560601.
- Roadmap item 560601 is planned for October 2026 preview and November 2026 general availability; neither date confirms tenant availability today.
- The announced filter targets Endpoint file operations matching well-known temporary filename patterns in IRM Activity explorer and scoring.
- Existing global exclusions can have broader effects: file types are excluded from matching across IRM policies, while excluded paths can prevent policy alerts for activity at those locations.
- Default
AppDatapath exclusions are already documented; filename-pattern filtering addresses a different matching rule. - Before changing policy exclusions in response to the preview, verify the patterns and controls Microsoft makes available and compare scoring, alert, Activity explorer, and sequence results in your own tenant.
Purview IRM’s proposed filter addresses a recognizable administrative trade-off: clearing away application housekeeping without asking teams to silence a wider class of file activity. The October preview is the first planned opportunity to see whether its actual pattern coverage delivers that narrower result for the workflows an organization investigates.