Microsoft Purview DLP: Instances Policy Location Retiring in January 2027

Microsoft has announced the retirement of the Instances policy location in Microsoft Purview Data Loss Prevention (DLP), with the change taking effect on January 6, 2027.

Today, organizations using the Instances location rely on the Microsoft Defender for Cloud Apps file policy infrastructure to enforce DLP and auto-labeling policies across supported third-party applications. To simplify policy management and provide a more consistent compliance experience, Microsoft is moving away from this approach and introducing dedicated application-specific policy locations directly within Microsoft Purview.

Supported applications include:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex
What’s Changing?

Instead of creating policies under a generic Instances location, administrators will use dedicated locations for each supported application.

For example:

Current LocationNew Location
Instances (Google Workspace)Google Workspace
Instances (Box)Box
Instances (Dropbox)Dropbox
Instances (Salesforce)Salesforce
Instances (ServiceNow)ServiceNow
Instances (AWS)AWS
Instances (Cisco Webex)Cisco Webex

This change aligns non-Microsoft application protection more closely with the broader Microsoft Purview compliance framework.

Microsoft is introducing these new application locations ahead of the retirement date to allow organizations time to migrate.

Key dates:

  • Dedicated application locations will be rolled out before retirement.
  • January 6, 2027: Instances policy location officially retires.
  • Retirement rollout begins in early January 2027 and is expected to complete by mid-January 2027.
What Happens After January 6, 2027?

Once the retirement takes place:

  • New policies can no longer be created using the Instances location.
  • Existing policies configured with the Instances location will no longer be supported.
  • Organizations should use the new dedicated application locations for all future DLP and auto-labeling policies.
  • Policies that continue to rely on the retired Instances location may no longer be enforced as expected.

If your organization currently uses the Instances location, Microsoft strongly recommends recreating those policies in the new application-specific locations before the retirement deadline.

Recommended Next Steps

To avoid any disruption to DLP enforcement, organizations should begin preparing well before the 2027 deadline.

1. Review Existing Policies

Identify any DLP or auto-labeling policies currently configured through the Instances location.

2. Identify Affected Applications

Determine which non-Microsoft platforms are involved and map them to their new dedicated policy locations.

3. Recreate Policies

Build equivalent policies using the new application-specific locations within Microsoft Purview.

4. Test and Validate

Before retiring legacy policies, verify that policy enforcement, labeling, and user experiences behave as expected.

5. Update Documentation

Review operational procedures, internal documentation, and administrator guidance to reflect the new management model.

6. Notify Stakeholders

Make sure compliance, security, and support teams are aware of the upcoming change and migration timeline.

While the retirement is still several months away, organizations using third-party cloud platforms for collaboration and data storage should start planning their migration strategy now. Moving to dedicated application locations will ensure continued DLP and auto-labeling protection while providing a more streamlined and unified compliance experience within Microsoft Purview.

The bottom line: If you’re using the Instances location today, plan your migration before January 6, 2027. If you’re not, you can safely continue using Microsoft Purview as normal and take advantage of the new dedicated application locations as they become available.

What’s New in Cloud, AI & Security Certifications

Microsoft is rolling out a new wave of Certifications that reflect today’s rapidly evolving cloud, AI, and security landscape. The first beta exams begin this month, with more releases over the next few months, and all new Certifications expected to become generally available later this year.

New Microsoft Certification Beta Timeline (2026)

Machine Learning Operations (MLOps) Engineer Associate
Perfect for professionals who deploy and manage machine learning and generative AI solutions in production.

  • Exam: AI‑300 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

Azure Databricks Data Engineer Associate
Ideal for data engineers who design secure, scalable pipelines using Azure Databricks to support real‑time analytics and AI.

  • Exam: DP‑750 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

SQL AI Developer Associate
Validates your ability to build AI‑powered, modern database applications using best‑practice governance and DevOps approaches.

  • Exam: DP‑800 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

Azure AI Fundamentals
A refreshed Fundamentals Certification focused on building modern AI apps and agents using Microsoft Foundry — great for beginners.

  • Exam: AI‑901 (beta) — April 2026
  • Training: March 2026
  • Go-live: June 2026

Azure AI App and Agent Developer Associate
Aligned with generative and agentic architectures. Covers building generative apps, multistep reasoning workflows, and production‑ready agent solutions.

  • Exam: AI‑103 (beta) — April 2026
  • Training: March 2026
  • Go-live: June 2026

Cybersecurity Business Professional
Validates your ability to recognize risks, apply secure-by-design practices, and support business decision‑making that enables secure AI adoption.

  • Exam: SC‑730 (beta) — April 2026
  • Training: May 2026
  • Go-live: July 2026

Azure AI Cloud Developer Associate
Designed for developers building and monitoring AI solutions on Azure using containers, vector databases, serverless components, and distributed observability.

  • Exam: AI‑200 (beta) — April 2026
  • Training: April 2026
  • Go-live: July 2026

Cloud and AI Security Engineer Associate
Focuses on securing cloud and AI workloads, protecting models, and applying enterprise‑grade security patterns.

  • Exam: SC‑500 (beta) — May 2026
  • Training: July 2026
  • Go-live: July 2026

Windows Server Hybrid Administrator
A unified Certification covering both Azure and on‑premises hybrid administration.

  • Exam: AZ‑802 (beta) — June 2026
  • Training: August 2026
  • Go-live: August 2026

Retiring Certifications: Key Dates & What Replaces Them

As Microsoft updates its Certification portfolio for modern AI‑driven roles, several existing Certifications are scheduled for retirement in 2026. If you hold one of these, make sure you renew it before the retirement date if renewal is available.

You can read more in the official Microsoft article here.