Microsoft Purview Tightens Rules for Custom Sensitive Information Types

Organizations using Microsoft Purview custom Sensitive Information Types (SITs) should be aware of an upcoming change that may require updates to existing regex patterns.

Microsoft is moving forward with enforcing a long-documented rule that allows only one capturing group per regular expression in custom SIT definitions. The goal is to improve the consistency, reliability, and predictability of how sensitive data is identified and classified across Microsoft Purview and Data Loss Prevention (DLP) workloads.

When is this happening?

The rollout is expected to be completed by early July 2026 across all Microsoft cloud environments, including:

  • Worldwide
  • GCC
  • GCC High
  • DoD
Who is affected?

This change primarily impacts:

  • Microsoft Purview administrators
  • Compliance teams managing custom Sensitive Information Types
  • Organizations using custom SITs in DLP, data classification, and compliance solutions

The enforcement applies whether SITs are managed through:

  • The Microsoft Purview portal
  • PowerShell, including:
    • New-DlpSensitiveInformationTypeRulePackage
    • Set-DlpSensitiveInformationTypeRulePackage
What changes?

Once enforcement is in place:

✅ New custom SITs must contain only one capturing group in each regular expression.

❌ Creating a new SIT with multiple capturing groups will be blocked.

❌ Updating an existing SIT that contains multiple capturing groups will fail validation.

❌ Administrators will not be able to save changes to existing SITs until non-compliant regex patterns are updated.

What about existing SITs?

Existing custom SITs that contain multiple capturing groups will continue to work in their current state. However, they become a potential issue the moment you need to modify, update, or re-save them.

In other words, if an existing SIT contains a regex pattern with multiple capturing groups, you’ll need to redesign that pattern to comply with the one-capturing-group rule before any future changes can be saved.

Many organizations rely on custom SITs to identify sensitive business information and power key compliance capabilities such as:

Why does this matter?
  • Data Loss Prevention (DLP)
  • Data classification
  • Compliance monitoring
  • Information protection policies

If a custom SIT cannot be updated because it fails validation, it could delay policy changes, compliance updates, or new data protection initiatives.

What should you do now?

To avoid surprises, Microsoft Purview administrators should proactively:

  1. Audit existing custom SITs
  2. Identify regex patterns that use multiple capturing groups
  3. Redesign patterns to use a single capturing group
  4. Test and validate updated SITs before future modifications are required

🛡️ Jo SNAI Reimagined: Same Mission. New Look. Bigger Impact.

Some characters evolve not because their purpose changes, but because the world around them does.

Since the beginning, Jo SNAI has represented the vision behind Security Nebula AI (SNAI), a place where cybersecurity, artificial intelligence, and innovation converge to create a safer and smarter digital future. As a digital superhero, Jo SNAI has always stood for protection, knowledge, resilience, and the responsible use of emerging technologies.

Today, Jo SNAI unveils a bold new look.

The transition from the original blue design to the new purple powered appearance, is more than a visual refresh. It reflects the growth of Security Nebula AI and the expanding role of AI in cybersecurity, automation, and digital transformation. The new design symbolizes innovation, creativity, intelligence, and the limitless possibilities that emerge when security and AI work together.

While the appearance has evolved, the mission remains unchanged.

Jo SNAI continues to champion the values that define Security Nebula AI: protecting what matters most, empowering people through technology, embracing innovation responsibly, and helping organizations navigate the future with confidence.

In a digital universe where threats grow more sophisticated and opportunities become more exciting, Jo SNAI stands as a reminder that security should never slow innovation, it should enable it.

Welcome to the next chapter of Jo SNAI.

Same hero. New look. Stronger vision.

Security Nebula AI

Cyber Strong. AI Smart. Human First. 💜🛡️✨🚀