Smarter Insider Risk Coverage with Microsoft Purview

Microsoft is making Insider Risk Management in Purview even more useful with the introduction of a Policy Recommendation panel, a feature designed to help admins quickly spot gaps in their current risk coverage and strengthen their defenses.

Let’s face it: even with policies in place, it’s not always easy to know what you might be missing. That’s where this new capability comes in. It analyzes your existing setup and highlights missing or high-impact policies, offering clear, actionable suggestions to improve your security posture.

What’s new?

The Policy Recommendation panel lives directly on the Policies page and automatically reviews your current configuration. Using built-in analytics, it identifies areas where you could increase protection and recommends policies to cover common insider risk scenarios like:

  • Data leakage
  • Data theft
  • IP theft
  • Risky AI usage
  • Other security violations

It’s essentially a built-in advisor that helps you get more value from Insider Risk Management without needing to manually audit everything.

A quick reminder: what Insider Risk Management does

Microsoft Purview Insider Risk Management works by correlating signals across your environment to detect potentially risky behavior, whether intentional or accidental.

It’s also designed with privacy in mind, including:

  • Pseudonymization by default
  • Role-based access controls
  • Audit logs for transparency

So you can investigate risks while still protecting user privacy.

Rollout timeline
  • Public Preview: Mid–June 2026 → Late June 2026
  • General Availability: Mid–July 2026 → Late July 2026

This message is associated with Microsoft 365 Roadmap ID 560600.

Podcast Episode: DSI Investigation templates for common data security scenarios

🎙️ New podcast episode just dropped!
DSI Investigation Templates for Common Data Security Scenarios with Pip & Mara
▶️ Watch now on YouTube

Stay tuned…

Data Security Investigations: Investigation templates for common data security scenarios

Microsoft just made investigations in Purview Data Security a lot simpler and faster. You can now use ready‑made search templates designed for common data security scenarios, so you don’t have to start from scratch every time.

These built‑in templates help standardize the way investigations are run and reduce the amount of manual setup, meaning security analysts can jump straight into the work with minimal input.

The best part? This feature is already available worldwide, requires no administrative setup, and is ready to use out of the box saving valuable time and streamlining the overall investigation process.

What’s new and why it matters

Microsoft is making investigations in Purview Data Security much more approachable by introducing built‑in search templates. These templates are designed for the scenarios analysts deal with most often—like data exfiltration, compromised mailboxes, exposure of personal data, or even risky AI interactions.

Instead of building queries from scratch every time, investigators can now choose a ready‑made template, enter a few basic details (such as a user or site), and get started immediately. This not only speeds things up but also ensures investigations are more consistent across teams. It’s especially helpful for less-experienced analysts, lowering the learning curve and reducing the time needed to get value from the solution.

(This update is tracked under Microsoft 365 Roadmap ID 560326.)

Rollout timeline

  • General Availability (Worldwide): Available now

What this means for your organization

Who it impacts

  • Security analysts and investigators working with Microsoft Purview Data Security Investigations

Where you’ll see it

  • Microsoft Purview (web portal)
  • Data Security Investigations solution

In short, this update removes a lot of the friction from starting an investigation helping teams move faster, stay consistent, and focus on what actually matters: understanding and responding to risks.

Podcast Episode: Microsoft Purview DSPM now includes a new data security agent to strengthen your data protection posture

Pip: When your data security posture needs managing, the last thing you want is to piece together risk signals manually — like assembling furniture with no instructions and half the screws missing.

Mara: Jo SNAI has a post on that exact problem — Microsoft Purview’s DSPM moving to general availability, and what the new Data Security Posture Agent actually changes for security and compliance teams. Let’s start with what that shift means in practice.

Microsoft Purview DSPM Reaches General Availability

Pip: The core question here is what changes when a security feature moves from preview to general availability — and whether GA status actually signals something meaningful for teams already managing data risk in Microsoft 365.

Mara: The post frames the value proposition directly: “Instead of piecing things together manually, you get clear insights, risk signals, and practical recommendations to help improve your overall data security posture.”

Pip: So the upshot is consolidation — one centralized view replacing a fragmented manual process, which for compliance teams managing large Microsoft 365 environments is genuinely significant.

Mara: The headline addition in this release is the Data Security Posture Agent, now fully available. It gives teams a centralized view of data risks, surfaces gaps in their security posture, and provides actionable recommendations with direct remediation steps — not just a dashboard to stare at.

Pip: The rollout window runs from late May through late June 2026, so depending on your organization’s Purview deployment timing, you may already have access or it’s arriving soon.

Mara: One detail worth flagging for teams nervous about migration headaches: the transition from preview is seamless. Existing configurations carry over intact — no policy reconfiguration required.

Pip: Which is a small but real thing. New capability with zero forced rework is not the default in enterprise security tooling.

Mara: The post identifies IT admins, security teams, and compliance professionals as the primary audience — essentially anyone responsible for data protection within Microsoft 365. And notably, no action is required to enable the feature. The recommendation is to explore the new DSPM capabilities, review how the Data Security Posture Agent fits your existing strategy, and brief your compliance teams on what’s now available.

Pip: GA status, seamless rollout, no manual toggle — the barrier to actually using this is now just knowing it exists.

Mara: Which is exactly the kind of update worth surfacing.

Pip: Visibility into data risk without rebuilding your configuration from scratch — that’s a reasonable ask, and apparently now a delivered one.

Mara: More on how these posture tools evolve in practice next time.

Microsoft Purview DSPM now includes a new data security agent to strengthen your data protection posture

Microsoft has officially moved Data Security Posture Management (DSPM) in Microsoft Purview from preview to general availability (GA) and that’s a big step forward for organizations looking to strengthen how they protect sensitive data.

At its core, DSPM helps you understand where your data risks really are, giving you better visibility across your Microsoft 365 environment. Instead of piecing things together manually, you get clear insights, risk signals, and practical recommendations to help improve your overall data security posture.

This release is part of Microsoft’s ongoing investment in enterprise-grade security and compliance tools, making it easier to protect data at scale without added complexity.

What’s New

One of the key additions in this GA release is the Data Security Posture Agent, now fully available.

With it, you can:

  • Get a centralized view of data risks across your environment
  • Identify potential gaps in your security posture
  • Access actionable recommendations to improve protection
  • Take direct steps to remediate risks

The transition from preview to GA is seamless—your existing configurations stay as they are, and there’s no need to reconfigure policies or settings.

Rollout Timeline
  • General Availability (Worldwide): Late May 2026 – Late June 2026

The feature will become available based on your organization’s Microsoft Purview deployment timing.

Who Should Pay Attention

This update is especially relevant for:

  • IT admins
  • Security teams
  • Compliance professionals

Basically anyone responsible for managing or protecting data within Microsoft 365 using Microsoft Purview.

What This Means for You

Good news, no action is required to enable this feature.

That said, it’s a great opportunity to take advantage of what DSPM offers. You might want to:

  • Explore the new DSPM capabilities and see how they fit into your security strategy
  • Learn how to set up and use the Data Security Posture Agent
  • Start using DSPM insights to prioritize and reduce data risks
  • Inform your security and compliance teams about the update
  • Update any internal documentation that references Purview DSPM

Smarter Role Group Management in Microsoft Purview

Managing permissions in Microsoft Purview is about to get a lot easier.

Microsoft is improving the Role groups experience in the Purview compliance portal, introducing a more intuitive interface that helps admins quickly understand and validate permissions—something many of us have struggled with at some point.

What’s new?

Based on customer feedback, the updated UI adds new ways to view role group assignments so you can find what you need faster and with less guesswork.

Instead of digging through multiple layers, admins can now look up permissions from three different perspectives:

  • By Role – see who has specific roles assigned
  • By Member – check which roles a particular user belongs to
  • My permissions – quickly understand your own access and responsibilities

These views are designed to reduce troubleshooting time and give admins clearer visibility into how permissions are structured.

When is this rolling out?
  • Public Preview: Mid-June 2026 → Mid-July 2026
  • General Availability (Worldwide, GCC, GCC High, DoD): Mid-July 2026 → Mid-August 2026

Roadmap ID: 562033

Why this is useful

This update makes it much easier for admins to see who has access to what—without wasting time searching.

Here’s what that means in practice:

  • Faster answers – Instead of clicking around, you can quickly find permissions by role, user, or your own access
  • Less confusion – It’s clearer how permissions are set up, so fewer mistakes or misunderstandings
  • Easier troubleshooting – When someone doesn’t have access (or has too much), you can figure out why much faster
  • Better for audits – You can easily review and confirm permissions when needed
  • No learning curve – Nothing changes in how things work—just a clearer view of what’s already there
How this improves security

This update doesn’t change permissions—but it makes it much easier to spot problems and fix them quickly, which directly improves security.

Here’s how:

  • Better visibility = fewer hidden risks
    You can clearly see who has access to what, making it easier to catch over-permissioned users or unnecessary roles.
  • Faster detection of mistakes
    If someone has access they shouldn’t (or is missing access), you can identify and correct it much faster.
  • Stronger least-privilege control
    It’s easier to ensure people only have the access they actually need—nothing more.
  • Simpler audits and reviews
    During security or compliance checks, you can quickly validate permissions instead of manually piecing things together.
  • Reduced risk of accidental exposure
    Clearer role assignments help prevent misconfigurations that could lead to data leaks or unauthorized access.

Microsoft Purview DSI Gets Smarter with OCR

Microsoft is continuing to strengthen Purview Data Security Investigations (DSI) by adding AI‑powered Optical Character Recognition (OCR) capabilities. This new enhancement allows DSI to read and analyze text that appears inside images, something traditional investigations often miss.

With OCR built in, DSI can now surface sensitive information hidden in screenshots, scanned documents, and embedded visuals within files. The result? Deeper investigations, better context, and more accurate risk detection across your organization.

This update is tracked under Microsoft 365 Roadmap ID 561489.

When is this rolling out?
  • Public Preview (Worldwide):
    Rolling out in late May 2026, with completion expected by early June 2026
  • General Availability (Worldwide):
    Rolling out in mid‑July 2026, with completion expected by late July 2026
Who is impacted?

This update is relevant for:

  • Admins and security analysts using Microsoft Purview Data Security Investigations
  • Organizations investigating data security risks with Purview
What’s changing?

Once OCR is enabled (and it will be on by default), DSI will automatically:

  • Extract text from image‑based content, including:
    • Images
    • Screenshots
    • Visuals embedded in documents
  • Add the extracted text to investigation datasets
  • Improve search, analysis, and risk detection using this newly visible content

The good news?
No workflow changes are required. Existing investigations will continue to work as they do today—just with richer insights.

Even better, all existing Purview controls and protections still apply. Sensitivity labels, DLP policies, and other compliance settings continue to be fully respected.

Why this matters

Sensitive information doesn’t always live in plain text. Credentials, personal data, or confidential details often end up in screenshots or images—especially in collaboration tools. OCR helps close that gap and gives security teams greater visibility into data risks that were previously hard to detect.

What do you need to do?

No action is required before rollout. However, you may want to:

  • Inform your security and compliance teams about the improved image‑based detection
  • Update internal investigation procedures to account for OCR‑driven findings
  • Refresh training materials or documentation that reference DSI capabilities

Microsoft Purview DLP Gets Smarter Troubleshooting with Guided Diagnostics

If you’ve ever tried to troubleshoot why a Data Loss Prevention (DLP) policy behaved the way it did, you’ll know it’s not always obvious what happened behind the scenes. Microsoft is looking to change that.

Microsoft is rolling out a new guided diagnostics experience in Microsoft Purview Data Loss Prevention (DLP), designed to help administrators quickly understand, diagnose, and resolve DLP policy issues. The goal is simple: make DLP behavior easier to explain, easier to fix, and easier to optimize.

This update is tracked under Microsoft 365 Roadmap ID 561032.

When is this coming?
  • Public Preview: Mid‑May 2026 to Mid‑June 2026
  • General Availability (Worldwide): Late June 2026 to July 2026
Who does this affect?

This update is primarily aimed at:

  • Microsoft 365 administrators managing DLP policies in Microsoft Purview
  • Commercial Microsoft 365 tenants

If your organization has Microsoft 365 E5 and Copilot licensing, you’ll also benefit from Security Copilot‑powered insights, which add intelligent recommendations during troubleshooting.

What’s changing?

A new guided diagnostics experience will appear directly in the Microsoft Purview portal, making it much easier to understand what your DLP policies are doing and why.

With this experience, admins can:

  • See the order in which DLP policies are evaluated
  • Understand which conditions were matched
  • Clearly identify what action was taken (allow, block, or audit)

In other words, instead of guessing or piecing together logs, you’ll get a clearer, step‑by‑step explanation of how a DLP decision was made.

Security Copilot‑powered insights (for eligible tenants)

For organizations with the right licensing, Microsoft brings Copilot into the experience to help:

  • Spot potential policy misconfigurations
  • Speed up DLP troubleshooting
  • Get recommendations for improving and optimizing policies
What’s not changing?
  • Existing DLP policies continue to work exactly as they do today
  • Enforcement behavior is unchanged
  • There is no impact on end‑user workflows

This update is purely about visibility and diagnostics, not policy enforcement.

That said, you may want to:

  • Update internal DLP troubleshooting documentation to reference the new guided diagnostics experience
  • Make sure your security and compliance teams are aware of the new diagnostics flow in the Purview portal
  • Review your Copilot and E5 licensing to understand whether Security Copilot‑powered insights will be available in your tenant

Meet the New Cyber Heroes Crew: Morgi & Spot 🐾

🟣 Morgi: The AI Superhero

Morgi is the thinker of the Cyber Heroes Crew, the one who’s always quietly paying attention. Curious, clever, and powered by AI, she has a gift for noticing patterns that others overlook and figuring out what they mean before something goes wrong.

With her softly glowing purple shield by her side, Morgi keeps an eye on the digital world, catching phishing tricks, malware, and even deepfakes in seconds. She doesn’t just spot danger, she explains it in a way people can understand, helping them feel confident instead of overwhelmed.

At heart, Morgi wants everyone to feel safe and informed online. Her mission is simple: make technology smarter, friendlier, and safer for everyone who uses it.

Superpower: Seeing Ahead

Morgi’s strength comes from understanding, reading signals, connecting dots, and knowing what’s likely to happen next. By thinking ahead, she helps everyone stay one step ahead too.

🐾 When Morgi is watching, clarity replaces confusion.

🔵 Spot: The Cybersecurity Hero

Spot is the one who looks out for you when you’re busy, distracted, or just trying to get through your day. Quietly observant and steady by nature, Spot stays close, keeping watch over your data and devices so you don’t have to worry about every little thing online.

With his familiar blue shield always nearby, Spot steps in when something doesn’t feel right, blocking phishing attempts, stopping ransomware, and protecting personal information before it’s ever at risk. He doesn’t make a fuss about it. He just does what needs to be done.

Spot believes safety starts with small moments of awareness. A pause before clicking. A second look at an email. A gentle reminder that it’s okay to slow down. That simple “think before you click” mindset is how Spot helps people stay safe without feeling stressed or overwhelmed.

At the heart of it all, Spot’s role is simple and reassuring:
to stand beside you, quietly protecting your digital world, every step of the way.

What Makes Spot Special

Spot’s strength isn’t flash or noise—it’s presence. He’s patient, dependable, and always paying attention, so you can move through the online world with confidence.

🐾 When Spot is around, you’re not facing the internet alone.

Together

Morgi analyzes. Spot protects.
Side by side, they form the ultimate cybersecurity duo, keeping Jo SNAI’s digital world secure, intelligent, and one step ahead of every threat.

🚀 Stay tuned as Morgi & Spot dive into their next cyber adventure! 🐾🐾

Copilot Cowork is now available in Frontier

Copilot Cowork has officially landed in Frontier for Microsoft 365 Copilot (Premium) users. This release brings a more collaborative way for Copilot to work across apps, handling multi‑step tasks while keeping you in control.

With Copilot Cowork, tasks can span multiple Microsoft 365 apps, with clear user approvals along the way and built‑in progress tracking so you always know what’s happening. It’s designed to feel less like a single command and more like a coworker helping you get things done.

To use Copilot Cowork, users need to be enrolled in Frontier. It currently works with Microsoft‑built agents and uses Anthropic as a subprocessor. For customers in the EU, data boundary controls are in place to help meet regional compliance requirements.

The good news? No admin action is required to get started eligible users can simply explore the experience once Frontier is enabled.

When is this happening?

Copilot Cowork is already rolling out and is available today in Frontier.
General availability for all customers will be announced later—Microsoft will share details once it’s ready for broader release.

What this means for your organization

This update introduces a new way for Copilot to work alongside users—taking on longer, multi‑step tasks across Microsoft 365 apps while keeping people firmly in control. Think of it as Copilot stepping up from quick help to ongoing collaboration.

Who can use Copilot Cowork?

Copilot Cowork is available to:

  • Users with a Microsoft 365 Copilot (Premium) license
  • Users who are enabled for Frontier
  • English‑language users (for now)
Prerequisites and controls to be aware of

Before Copilot Cowork can be used, a few requirements need to be in place:

  • The tenant must be enrolled in the Frontier program
  • Microsoft‑built agents must be enabled
  • Anthropic must be enabled as a subprocessor (this is on by default)

For organizations based in the European Union (EU):

  • Anthropic is turned off by default to meet EU Data Boundary requirements
  • It must be explicitly enabled for Copilot Cowork to function
  • If Anthropic remains off, users may see Copilot Cowork listed but won’t be able to use it

Admins also need to be enrolled in Frontier to see Copilot Cowork listed in the Agent Inventory.

What users can expect

Once available, users can:

  • Install Copilot Cowork directly from the Agent Store in the Microsoft 365 Copilot app
  • Pin it to the left rail for easy access

From there, users can simply describe what they want to achieve—in plain, natural language—and Copilot Cowork will:

  • Create a multi‑step plan based on the user’s Microsoft 365 context
  • Coordinate work across apps like Word, PowerPoint, Outlook, and more
  • Continue working over time, with clear checkpoints and progress tracking

Importantly, Copilot Cowork never acts without permission. It will always propose actions first and wait for explicit user approval before doing things like:

  • Sending emails or Teams messages
  • Scheduling, declining, or rescheduling meetings
  • Editing, moving, or organizing files

Users stay in control at all times—they can pause, adjust, or stop execution whenever they want, and come back later to review progress.

Default behavior and governance

For eligible tenants, Copilot Cowork is enabled by default and respects existing Microsoft 365 permissions and policies. The only exception is where EU Data Boundary settings apply, which may limit functionality unless explicitly configured.