Our DLP policies -- which have been unchanged since February -- suddenly stopped working for specific file attachments.
Here's the kicker though, when we upload the file attachment to Purview using the "test" feature, it successfully detects the sensitive information type.
We even used the "Test-DataClassification" PowerShell cmdlet, and it successfully detects the sensitive info. (With a confidence level of 85.)
BUT, the emails are no longer being blocked like they should be (again, the policies have worked just fine without modification since February.)
We used the Test-Message to check whether the rules would match in a "DLP Rules Tracing Report"...AND they don't.
It says "Predicate ExContentContainsSensitiveInformationPredicate evaluation didn't result in a match" as well as "Predicate AndCondition evaluation didn't result in a match." (What it should say is "Text Matched for for discovered data classification".)
What exactly is going on?
The SIT matches.
The SIT is in the policy (unchanged since February)
The Policy with the SIT doesn't match though.
Weirdly, other emails which don't have these file attachments are being blocked just fine (again, everything matches on the SIT.)
Our policies correctly set "Evaluate Predicate for message or attachment".