A man reviews files on a monitor as secure ZIP archives move between cloud systems and a web form.
Microsoft has expanded a small Purview feature that should be useful to administrators in its US government clouds. According to Microsoft 365 roadmap item 566321, admins can now export Data Loss Prevention (DLP) policies and sensitivity label publishing policies from the Purview portal as a ZIP file. The file can then be attached to a support ticket. The roadmap entry lists the feature as Launched and General Availability, with an August 2026 GA date. It applies to the Web platform in the GCC, GCC High and DoD cloud instances.

Microsoft describes the feature in plain terms. A new export option appears in two places: the Data Loss Prevention > Policies page and the Information Protection > Label publishing policies page. It lets users download their existing DLP configurations and label policies, including schema, as a ZIP file that can be attached to support tickets to speed up troubleshooting.

Commercial tenants got it first​

This isn't a brand-new feature. Microsoft first announced it to commercial tenants in Message Center post MC1235741 and tracked it under a separate roadmap ID, RM557553. That item carries the same title, "Microsoft Purview: Data Loss Prevention – Export DLP and Label Policy Configurations." A summary of the Message Center post on M365 Admin (HANDS ON tek) said the feature would be rolling out from March to May 2026, and that it aids troubleshooting without affecting policy enforcement or user experience.

Roadmap 566321 appears to bring the same capability to the sovereign government clouds. Government cloud features usually arrive months after commercial ones, so the gap is no surprise. Microsoft's "What's new in Microsoft Purview" page now lists the feature as GA in its shared capabilities section. Microsoft describes it as an export of policy configuration as a ZIP file containing a point-in-time snapshot of all policy configurations in XML format for DLP and sensitivity label publishing policies.

Summary: Commercial tenants got the feature earlier in 2026. The new roadmap item extends it to GCC, GCC High and DoD, with an August 2026 GA date.

What's in the ZIP file​

Microsoft Learn's article "Export policy configuration in Microsoft Purview" explains what the download contains. The ZIP holds an XML file with a point-in-time snapshot of every policy in the current solution. It includes rules, conditions, actions, scoping and priority settings where they apply. Label publishing policies include the labels themselves but no rules or conditions, because those policies don't have any.

The label export covers more than the policies alone. Microsoft's What's New page says that on the Label policies page, the Export to Zip selection includes more detailed information about the policies and all sensitivity labels in your tenant. Keep that in mind before you send the file anywhere.

Microsoft Learn also lists some limits:

  • You can't pick individual policies. The ZIP always contains every policy for that solution.
  • It's read-only. You can't import the file back into a tenant to restore or create policies.
  • It doesn't update. The file shows the configuration at the moment you exported it. Later changes don't appear.
  • CSV export still exists, but it's limited. The Export to CSV option only includes the summary columns from the policies table, such as policy name, status and last modified date.

The Message Center post also says the feature is enabled by default and that existing CSV export remains available, with no impact to users and no change to policy enforcement or behavior.

Summary: The ZIP gives you a complete snapshot of policy settings. It isn't a backup you can restore.

How to export your DLP or label policy configuration​

These steps follow Microsoft Learn:

  1. Sign in to the Microsoft Purview portal.
  2. Go to the policies page for the solution: Data Loss Prevention > Policies or Information Protection > Label publishing policies. If the solution supports export, you'll see Export to zip.
  3. Select Export to zip.
  4. Save the file when prompted. It downloads to your default downloads folder.
  5. Extract the ZIP to get the XML configuration file.

If the option is missing: check that you're on a supported policies page. For government tenants, also remember the August 2026 GA date. Microsoft's roadmap dates are estimates, so the option may not appear in every tenant at the same time.

Reading the export with PowerShell​

The XML can be loaded with standard PowerShell. Microsoft Learn documents this method:

Code:
$p = Import-Clixml -Path "<path to extracted XML file>"
$p | Get-Member -MemberType Properties
$p.DlpCompliancePolicies | Format-Table
$p.DlpComplianceRules | Format-Table

Microsoft notes that Import-Clixml reads the file locally and doesn't connect to any service. Property names differ between solutions, so run the Get-Member line first to see what your export contains. DlpCompliancePolicies and DlpComplianceRules are Microsoft's examples for a DLP export. Microsoft also mentions uploading the XML to Microsoft 365 Copilot for analysis. That's an option, not a requirement.

If you'd rather script the whole thing, a related cmdlet exists. Microsoft's Exchange PowerShell documentation describes Export-PurviewConfig, which exports Microsoft Purview diagnostic configuration data for your organization as a compressed ZIP file containing component-specific diagnostic information. Valid components include ClassificationAndTextExtraction, DLM, DLP and MIPLabels. Microsoft's example exports diagnostic data for the DLP and MIPLabels components and saves the resulting ZIP file to disk. Microsoft Learn's portal export article links to this cmdlet, but the two aren't documented as producing the same file. Don't assume they're interchangeable.

Why it matters, and where to be careful​

The main benefit is shorter support cases. Anyone who has troubleshot a DLP rule that won't fire knows how slow it is to send screenshots and schedule screen-sharing calls. Microsoft Learn says the ZIP lets support engineers review the full policy configuration without a live troubleshooting session. Government cloud admins often face extra rules about who can see their screens, so a file they can review and approve before sending may be easier to work with.

Some caveats:

  • Treat the ZIP as sensitive. It contains your whole policy set and, for label policies, details on every sensitivity label in the tenant. Microsoft's documentation says nothing about redaction or encryption of the downloaded file. Follow your organization's data-handling rules before it leaves your environment, especially in GCC High and DoD.
  • It doesn't migrate policies. People keep asking how to move DLP policies between tenants. One Microsoft Tech Community thread asks how to replicate dev tenant DLP policies across Exchange, Teams, and endpoints exactly in prod. This export doesn't solve that, because it can't be imported.
  • Snapshots can still help with change tracking. Microsoft Learn lists periodic snapshots for version control and change tracking as one use. Comparing a pre-change export with a post-change export is a practical way to see what changed. Just don't call it a backup in your disaster-recovery plan.

Bottom line​

Microsoft's own guidance on preparing is: no action is required, but you may optionally update internal support documentation and use the new export when working with Microsoft Support. For GCC, GCC High and DoD admins, it's worth adding "export the ZIP" to the steps you follow before opening a Purview support ticket.

 

References

  1. Microsoft Purview: Data Loss Prevention - Export DLP and Label Policy Configurations Microsoft 365 Roadmap 2026-10-07T23:01:35.319621Z
  2. Microsoft Purview: Data Loss Prevention - Export DLP and Label Policy Configurations thepurviewpractitioner.com
  3. Export policy configuration in Microsoft Purview | Microsoft Learn learn.microsoft.com