Microsoft 365 Copilot Gets Clearer DLP Notifications

Have you ever wondered why Copilot couldn’t access, process, or return certain content?
Microsoft is making that experience much easier to understand. Previously, users could see different messages depending on how a Microsoft Purview Data Loss Prevention (DLP) policy was triggered, which sometimes made it unclear why content wasn’t available.

With this update, Microsoft 365 Copilot will now display a consistent notification whenever organisational DLP policies prevent access to content. The goal is simple: improve transparency, reduce confusion, and help users understand that Copilot is respecting their organisation’s data protection policies.

What’s Covered?

The new standardized message applies to Microsoft Purview DLP protections across Microsoft 365 Copilot and Copilot Chat, including:

  • Grounding DLP
  • Prompt DLP
  • External Email DLP

Where Will Users See It?

The unified notification can appear across Microsoft 365 Copilot experiences powered by Microsoft 365 Chat orchestration, including:

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot Chat
  • Microsoft Teams Copilot experiences
  • Outlook on the web Copilot experiences
  • Microsoft Edge Copilot experiences
  • Other Microsoft 365 Copilot chat experiences that rely on Microsoft 365 Chat orchestration

Whenever a DLP policy restricts Copilot from using specific content, users will see the same clear message indicating that access to some content has been restricted by an organisational policy.

Rollout Timeline

The feature is now rolling out across all environments:

  • Worldwide: Available from July 15, 2026
  • GCC: Available from July 20, 2026
  • GCC High and DoD: Available from July 23, 2026

What This Means for Your Organisation

Organizations already using Microsoft Purview DLP with Microsoft 365 Copilot or Copilot Chat don’t need to take any action. The update does not change how DLP policies work. Instead, it improves the user experience by providing a clearer and more consistent explanation when content is blocked.

For IT administrators, this is a good opportunity to review existing training materials, user documentation, and support resources to ensure they reflect the new messaging experience.

Bottom line: the protection remains the same, but the explanation gets better. Users gain more clarity on why content is unavailable, while organisations continue to benefit from the same trusted data protection controls.

Data Security Investigations: Investigation templates for common data security scenarios

Microsoft just made investigations in Purview Data Security a lot simpler and faster. You can now use ready‑made search templates designed for common data security scenarios, so you don’t have to start from scratch every time.

These built‑in templates help standardize the way investigations are run and reduce the amount of manual setup, meaning security analysts can jump straight into the work with minimal input.

The best part? This feature is already available worldwide, requires no administrative setup, and is ready to use out of the box saving valuable time and streamlining the overall investigation process.

What’s new and why it matters

Microsoft is making investigations in Purview Data Security much more approachable by introducing built‑in search templates. These templates are designed for the scenarios analysts deal with most often—like data exfiltration, compromised mailboxes, exposure of personal data, or even risky AI interactions.

Instead of building queries from scratch every time, investigators can now choose a ready‑made template, enter a few basic details (such as a user or site), and get started immediately. This not only speeds things up but also ensures investigations are more consistent across teams. It’s especially helpful for less-experienced analysts, lowering the learning curve and reducing the time needed to get value from the solution.

(This update is tracked under Microsoft 365 Roadmap ID 560326.)

Rollout timeline

  • General Availability (Worldwide): Available now

What this means for your organization

Who it impacts

  • Security analysts and investigators working with Microsoft Purview Data Security Investigations

Where you’ll see it

  • Microsoft Purview (web portal)
  • Data Security Investigations solution

In short, this update removes a lot of the friction from starting an investigation helping teams move faster, stay consistent, and focus on what actually matters: understanding and responding to risks.

Microsoft Purview DSI Gets Smarter with OCR

Microsoft is continuing to strengthen Purview Data Security Investigations (DSI) by adding AI‑powered Optical Character Recognition (OCR) capabilities. This new enhancement allows DSI to read and analyze text that appears inside images, something traditional investigations often miss.

With OCR built in, DSI can now surface sensitive information hidden in screenshots, scanned documents, and embedded visuals within files. The result? Deeper investigations, better context, and more accurate risk detection across your organization.

This update is tracked under Microsoft 365 Roadmap ID 561489.

When is this rolling out?
  • Public Preview (Worldwide):
    Rolling out in late May 2026, with completion expected by early June 2026
  • General Availability (Worldwide):
    Rolling out in mid‑July 2026, with completion expected by late July 2026
Who is impacted?

This update is relevant for:

  • Admins and security analysts using Microsoft Purview Data Security Investigations
  • Organizations investigating data security risks with Purview
What’s changing?

Once OCR is enabled (and it will be on by default), DSI will automatically:

  • Extract text from image‑based content, including:
    • Images
    • Screenshots
    • Visuals embedded in documents
  • Add the extracted text to investigation datasets
  • Improve search, analysis, and risk detection using this newly visible content

The good news?
No workflow changes are required. Existing investigations will continue to work as they do today—just with richer insights.

Even better, all existing Purview controls and protections still apply. Sensitivity labels, DLP policies, and other compliance settings continue to be fully respected.

Why this matters

Sensitive information doesn’t always live in plain text. Credentials, personal data, or confidential details often end up in screenshots or images—especially in collaboration tools. OCR helps close that gap and gives security teams greater visibility into data risks that were previously hard to detect.

What do you need to do?

No action is required before rollout. However, you may want to:

  • Inform your security and compliance teams about the improved image‑based detection
  • Update internal investigation procedures to account for OCR‑driven findings
  • Refresh training materials or documentation that reference DSI capabilities

New in Microsoft Purview: Smarter Credential Scanning to Strengthen Your Data Security

Microsoft is rolling out a major update to the Data Security Posture Agent in Microsoft Purview, and it’s a big step forward for organizations looking to stay ahead of credential‑related risks.

The newest addition is a credential scanning capability designed to help you uncover exposed credentials, like Microsoft Entra ID details, private keys, API tokens, and other sensitive access points across your selected data locations. With this update, Purview doesn’t just spot the issues; it also gives you risk scores, AI‑generated insights, confidence levels, and credential categories so you can quickly understand what matters and what needs attention.

All findings are surfaced in one streamlined task board, making it easier than ever to review, confirm, and take action.

This enhancement is listed as Microsoft 365 Roadmap ID 558436.

Rollout Timeline
  • Public Preview: Starts late March 2026, expected to finish by early April 2026
  • General Availability (Worldwide): Starts late June 2026, wrapping up by early July 2026

What This Means for Your Organization

Who will notice the change?

Admins who manage Microsoft Purview and use the Data Security Posture Agent within Microsoft 365 tenants will see the new feature appear under the Explore Agent section.

What’s changing?

A brand‑new credential scanning experience is being introduced, including:

  • LLM-powered detection of exposed credentials across selected data locations
  • Automated identification of:
    • Microsoft Entra ID credentials
    • Private keys
    • API tokens
    • Additional sensitive credential types

Each detection comes with:

  • A risk score
  • AI-generated insights
  • A confidence rating
  • A credential category

And to help you stay organized, Purview provides a task board where you can follow up on findings, track progress, and take recommended actions, all in one place.

How to Prepare

New in Microsoft Defender XDR: AI‑Powered Summaries for DLP Alerts

Microsoft is rolling out a great new capability that will make life much easier for anyone who works with Data Loss Prevention (DLP) alerts. You’ll now start seeing AI‑generated summaries and categorizations, produced by the Microsoft Purview Data Security Triage Agent, directly inside the Microsoft Defender XDR portal.

This means faster triage, clearer insights, and less time manually digging through alert details.

What’s new?

When a DLP alert fires, analysts will now see:

  • A concise AI‑generated summary of what happened
  • A suggested categorization of the alert
  • Context pulled directly from the incident to help speed up investigation

If you’ve already deployed the Triage Agent in Purview, these summaries will show up automatically in your Defender XDR alerts. If not, eligible analysts will be able to deploy it directly from the alert page super handy.

Rollout timeline

Public Preview
Starts: Early April 2026
Completed by: Mid‑April 2026

General Availability (Worldwide)
Starts: Mid‑August 2026
Completed by: Late August 2026

Roadmap ID: 558860

Who is impacted?

This update is especially helpful for:

  • Security analysts and administrators triaging DLP alerts in Defender XDR
  • Organizations already using (or planning to use) Microsoft Purview’s Data Security Triage Agent

Existing DLP policies, enforcement, and user experience remain unchanged.

Wave 3 of Microsoft 365 Copilot – The Ultimate Game Changer

Today Microsoft is rolling out some major updates that truly reshape how AI shows up in everyday work. Here’s what’s new:

  • Wave 3 of Microsoft 365 Copilot
  • More model diversity, with Claude and next‑gen OpenAI models available starting today
  • Agent 365 becoming generally available on May 1 at $15 per user
  • Microsoft 365 E7: The Frontier Suite, also coming May 1, priced at $99 per user

Wave 3 is honestly the biggest shift I’ve seen in Copilot so far. It doesn’t feel like “AI that helps you write or summarize” anymore, it feels like Microsoft is moving Copilot into a true agent that can actually do work for you, not just respond to prompts. And this changes everything in how we’ll use Microsoft 365.

Frontier Transformation – What It Really Means

Microsoft is talking about “Frontier Transformation” but at its core, it’s actually simple: AI should help people achieve their highest goals — not just make processes a little faster.

Copilot Cowork – The game changer

The main highlight is Copilot Cowork, built together with Anthropic (the team behind Claude). What I love about it is that it can finally take on a whole piece of work, break it into steps, run those steps in Word, Excel, PowerPoint, Outlook, and keep you updated as it goes.

Not instantly, but over minutes or even hours.
So instead of: “Write a one‑page summary”
It becomes: “Prepare the full report, build the Excel analysis, create the PowerPoint, and draft the email to the team.”
And it actually moves this work forward across the apps we already use daily.

Edit with Copilot – In-app agentic editing

Another thing I like is that “Agent Mode” is gone.
It’s now simply called Edit with Copilot, and it works right inside the apps:

  • Word: turns your messy draft into something polished
  • Excel: actually builds formulas and charts (not just suggests)
  • PowerPoint: creates slides using your real templates and brand
  • Outlook: drafts or refines emails in the compose window

No more copy-paste. No more losing sensitivity labels. Everything stays governed and saved where it should be.

Work IQ – Copilot that “knows how you work”

Wave 3 also introduces Work IQ, which gives Copilot a deeper understanding of:

  • Your organization’s content
  • Your collaboration patterns
  • The apps and workflows you use
  • The context behind your requests

This is what helps Copilot choose the right model (Claude or OpenAI) depending on the task.

Multi‑model Copilot (Claude + OpenAI)

For the first time, Copilot becomes model-agnostic.
You’ll be able to pick or automatically use:

  • Anthropic Claude (via the Frontier program)
  • OpenAI models

A model selector is coming to Copilot Chat so you can choose which model works best, depending on the task.

New licensing tier: Microsoft 365 E7 “The Frontier Suite”

Microsoft also launched a brand new enterprise tier — their first in 11 years:
Microsoft 365 E7 (The Frontier Suite)

It bundles:

  • M365 E5
  • Copilot
  • Agent 365
  • Additional security + analytics tools

This shows how seriously Microsoft is betting on agentic AI becoming the new standard.

Rollout timeline

Wave 3 features are:

  • Already in research preview for selected customers
  • Expanding via the Frontier Program starting March 2026

With Wave 3, Agent 365, Work IQ, and the new E7 suite, AI is shifting from early experimentation to real, scalable, enterprise-wide value. Microsoft is not only imagining what AI could be it’s giving organizations the tools to build that future right now.

You can read more in the official Microsoft article here.