Microsoft Purview Expands DLP and AutoLabeling to Third-Party Apps

Microsoft is taking another major step toward unified data protection by extending Microsoft Purview Data Loss Prevention (DLP) and autolabeling capabilities beyond the Microsoft ecosystem. Organisations will soon be able to protect and classify data stored in popular third-party applications such as Google Workspace, Box, Salesforce, Dropbox, ServiceNow, AWS, and Cisco Webex, all from within Microsoft Purview.

A Single Compliance Hub for More Applications

Traditionally, organisations managing data across multiple cloud platforms had to rely on separate security and compliance controls for each application. With this update, Microsoft Purview becomes a more centralised compliance solution by allowing administrators to create and manage DLP and autolabeling policies for supported non-Microsoft applications directly from the Purview portal.

The integration is made possible through Microsoft Defender for Cloud Apps connectors, which securely connect these third-party services to Microsoft Purview.

Once the feature is rolled out, dedicated application locations for supported non-Microsoft services will appear in Microsoft Purview. Administrators will be able to:

  • Create and manage Data Loss Prevention (DLP) policies for supported applications.
  • Create and manage Information Protection autolabeling policies.
  • Apply compliance controls from a single management interface.
  • Extend sensitivity labels and data protection policies beyond Microsoft 365 workloads.

Supported Applications

DLP Support

Microsoft Purview DLP will support the following applications:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex

AutoLabeling Support

Autolabeling will initially be available for:

  • Google Workspace
  • Box

Available policy actions and conditions will vary depending on the application and may include content inspection, sensitivity labelling, notifications, quarantine actions, and access controls.

Rollout Timeline

Microsoft plans to release the feature according to the following schedule:

  • Public Preview: Mid-August 2026 to early September 2026
  • General Availability: Early September 2026 through late October 2026

Important Considerations

Organisations currently using Microsoft Defender for Cloud Apps file policies for the same third-party locations should take note: Microsoft recommends disabling or removing those existing file policies before creating equivalent policies in Microsoft Purview. Running both simultaneously could result in unexpected policy enforcement behaviour.

Licensing and Pricing

To use these new capabilities, organisations will need:

  • An eligible Microsoft Purview Enterprise license
  • Connected applications via Microsoft Defender for Cloud Apps

Additionally, customers should review the pricing implications associated with Microsoft Purview At Rest Protection. Usage is billed on a pay-as-you-go basis, with 1,000 files counted as one data asset for billing purposes.

Why This Matters

As organisations continue adopting multi-cloud and multi-platform environments, data often resides well beyond Microsoft 365. This update allows security and compliance teams to apply consistent protection, classification, and governance policies across a broader range of business-critical applications without requiring separate management tools.

By bringing DLP and autolabeling capabilities to leading third-party services, Microsoft is helping organisation simplify compliance operations while strengthening data security wherever sensitive information resides.

This enhancement significantly expands Microsoft Purview’s reach, making it a stronger centralised platform for information protection and compliance. For organisations using a mix of Microsoft and non-Microsoft cloud services, the ability to manage DLP and labeling policies from a single console could reduce complexity, improve governance consistency, and strengthen overall data protection strategies.

🎧 Tune in for all the details!
🎥 Watch the full episode ➡️ here

Microsoft Purview DLP: Instances Policy Location Retiring in January 2027

Microsoft has announced the retirement of the Instances policy location in Microsoft Purview Data Loss Prevention (DLP), with the change taking effect on January 6, 2027.

Today, organizations using the Instances location rely on the Microsoft Defender for Cloud Apps file policy infrastructure to enforce DLP and auto-labeling policies across supported third-party applications. To simplify policy management and provide a more consistent compliance experience, Microsoft is moving away from this approach and introducing dedicated application-specific policy locations directly within Microsoft Purview.

Supported applications include:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex
What’s Changing?

Instead of creating policies under a generic Instances location, administrators will use dedicated locations for each supported application.

For example:

Current LocationNew Location
Instances (Google Workspace)Google Workspace
Instances (Box)Box
Instances (Dropbox)Dropbox
Instances (Salesforce)Salesforce
Instances (ServiceNow)ServiceNow
Instances (AWS)AWS
Instances (Cisco Webex)Cisco Webex

This change aligns non-Microsoft application protection more closely with the broader Microsoft Purview compliance framework.

Microsoft is introducing these new application locations ahead of the retirement date to allow organizations time to migrate.

Key dates:

  • Dedicated application locations will be rolled out before retirement.
  • January 6, 2027: Instances policy location officially retires.
  • Retirement rollout begins in early January 2027 and is expected to complete by mid-January 2027.
What Happens After January 6, 2027?

Once the retirement takes place:

  • New policies can no longer be created using the Instances location.
  • Existing policies configured with the Instances location will no longer be supported.
  • Organizations should use the new dedicated application locations for all future DLP and auto-labeling policies.
  • Policies that continue to rely on the retired Instances location may no longer be enforced as expected.

If your organization currently uses the Instances location, Microsoft strongly recommends recreating those policies in the new application-specific locations before the retirement deadline.

Recommended Next Steps

To avoid any disruption to DLP enforcement, organizations should begin preparing well before the 2027 deadline.

1. Review Existing Policies

Identify any DLP or auto-labeling policies currently configured through the Instances location.

2. Identify Affected Applications

Determine which non-Microsoft platforms are involved and map them to their new dedicated policy locations.

3. Recreate Policies

Build equivalent policies using the new application-specific locations within Microsoft Purview.

4. Test and Validate

Before retiring legacy policies, verify that policy enforcement, labeling, and user experiences behave as expected.

5. Update Documentation

Review operational procedures, internal documentation, and administrator guidance to reflect the new management model.

6. Notify Stakeholders

Make sure compliance, security, and support teams are aware of the upcoming change and migration timeline.

While the retirement is still several months away, organizations using third-party cloud platforms for collaboration and data storage should start planning their migration strategy now. Moving to dedicated application locations will ensure continued DLP and auto-labeling protection while providing a more streamlined and unified compliance experience within Microsoft Purview.

The bottom line: If you’re using the Instances location today, plan your migration before January 6, 2027. If you’re not, you can safely continue using Microsoft Purview as normal and take advantage of the new dedicated application locations as they become available.

Microsoft Purview DSPM now includes a new data security agent to strengthen your data protection posture

Microsoft has officially moved Data Security Posture Management (DSPM) in Microsoft Purview from preview to general availability (GA) and that’s a big step forward for organizations looking to strengthen how they protect sensitive data.

At its core, DSPM helps you understand where your data risks really are, giving you better visibility across your Microsoft 365 environment. Instead of piecing things together manually, you get clear insights, risk signals, and practical recommendations to help improve your overall data security posture.

This release is part of Microsoft’s ongoing investment in enterprise-grade security and compliance tools, making it easier to protect data at scale without added complexity.

What’s New

One of the key additions in this GA release is the Data Security Posture Agent, now fully available.

With it, you can:

  • Get a centralized view of data risks across your environment
  • Identify potential gaps in your security posture
  • Access actionable recommendations to improve protection
  • Take direct steps to remediate risks

The transition from preview to GA is seamless—your existing configurations stay as they are, and there’s no need to reconfigure policies or settings.

Rollout Timeline
  • General Availability (Worldwide): Late May 2026 – Late June 2026

The feature will become available based on your organization’s Microsoft Purview deployment timing.

Who Should Pay Attention

This update is especially relevant for:

  • IT admins
  • Security teams
  • Compliance professionals

Basically anyone responsible for managing or protecting data within Microsoft 365 using Microsoft Purview.

What This Means for You

Good news, no action is required to enable this feature.

That said, it’s a great opportunity to take advantage of what DSPM offers. You might want to:

  • Explore the new DSPM capabilities and see how they fit into your security strategy
  • Learn how to set up and use the Data Security Posture Agent
  • Start using DSPM insights to prioritize and reduce data risks
  • Inform your security and compliance teams about the update
  • Update any internal documentation that references Purview DSPM

Microsoft Purview DLP Gets Smarter Troubleshooting with Guided Diagnostics

If you’ve ever tried to troubleshoot why a Data Loss Prevention (DLP) policy behaved the way it did, you’ll know it’s not always obvious what happened behind the scenes. Microsoft is looking to change that.

Microsoft is rolling out a new guided diagnostics experience in Microsoft Purview Data Loss Prevention (DLP), designed to help administrators quickly understand, diagnose, and resolve DLP policy issues. The goal is simple: make DLP behavior easier to explain, easier to fix, and easier to optimize.

This update is tracked under Microsoft 365 Roadmap ID 561032.

When is this coming?
  • Public Preview: Mid‑May 2026 to Mid‑June 2026
  • General Availability (Worldwide): Late June 2026 to July 2026
Who does this affect?

This update is primarily aimed at:

  • Microsoft 365 administrators managing DLP policies in Microsoft Purview
  • Commercial Microsoft 365 tenants

If your organization has Microsoft 365 E5 and Copilot licensing, you’ll also benefit from Security Copilot‑powered insights, which add intelligent recommendations during troubleshooting.

What’s changing?

A new guided diagnostics experience will appear directly in the Microsoft Purview portal, making it much easier to understand what your DLP policies are doing and why.

With this experience, admins can:

  • See the order in which DLP policies are evaluated
  • Understand which conditions were matched
  • Clearly identify what action was taken (allow, block, or audit)

In other words, instead of guessing or piecing together logs, you’ll get a clearer, step‑by‑step explanation of how a DLP decision was made.

Security Copilot‑powered insights (for eligible tenants)

For organizations with the right licensing, Microsoft brings Copilot into the experience to help:

  • Spot potential policy misconfigurations
  • Speed up DLP troubleshooting
  • Get recommendations for improving and optimizing policies
What’s not changing?
  • Existing DLP policies continue to work exactly as they do today
  • Enforcement behavior is unchanged
  • There is no impact on end‑user workflows

This update is purely about visibility and diagnostics, not policy enforcement.

That said, you may want to:

  • Update internal DLP troubleshooting documentation to reference the new guided diagnostics experience
  • Make sure your security and compliance teams are aware of the new diagnostics flow in the Purview portal
  • Review your Copilot and E5 licensing to understand whether Security Copilot‑powered insights will be available in your tenant

New in Microsoft Defender XDR: AI‑Powered Summaries for DLP Alerts

Microsoft is rolling out a great new capability that will make life much easier for anyone who works with Data Loss Prevention (DLP) alerts. You’ll now start seeing AI‑generated summaries and categorizations, produced by the Microsoft Purview Data Security Triage Agent, directly inside the Microsoft Defender XDR portal.

This means faster triage, clearer insights, and less time manually digging through alert details.

What’s new?

When a DLP alert fires, analysts will now see:

  • A concise AI‑generated summary of what happened
  • A suggested categorization of the alert
  • Context pulled directly from the incident to help speed up investigation

If you’ve already deployed the Triage Agent in Purview, these summaries will show up automatically in your Defender XDR alerts. If not, eligible analysts will be able to deploy it directly from the alert page super handy.

Rollout timeline

Public Preview
Starts: Early April 2026
Completed by: Mid‑April 2026

General Availability (Worldwide)
Starts: Mid‑August 2026
Completed by: Late August 2026

Roadmap ID: 558860

Who is impacted?

This update is especially helpful for:

  • Security analysts and administrators triaging DLP alerts in Defender XDR
  • Organizations already using (or planning to use) Microsoft Purview’s Data Security Triage Agent

Existing DLP policies, enforcement, and user experience remain unchanged.

What’s New in Cloud, AI & Security Certifications

Microsoft is rolling out a new wave of Certifications that reflect today’s rapidly evolving cloud, AI, and security landscape. The first beta exams begin this month, with more releases over the next few months, and all new Certifications expected to become generally available later this year.

New Microsoft Certification Beta Timeline (2026)

Machine Learning Operations (MLOps) Engineer Associate
Perfect for professionals who deploy and manage machine learning and generative AI solutions in production.

  • Exam: AI‑300 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

Azure Databricks Data Engineer Associate
Ideal for data engineers who design secure, scalable pipelines using Azure Databricks to support real‑time analytics and AI.

  • Exam: DP‑750 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

SQL AI Developer Associate
Validates your ability to build AI‑powered, modern database applications using best‑practice governance and DevOps approaches.

  • Exam: DP‑800 (beta) — March 2026
  • Training: Available March 2026
  • Go-live: May 2026

Azure AI Fundamentals
A refreshed Fundamentals Certification focused on building modern AI apps and agents using Microsoft Foundry — great for beginners.

  • Exam: AI‑901 (beta) — April 2026
  • Training: March 2026
  • Go-live: June 2026

Azure AI App and Agent Developer Associate
Aligned with generative and agentic architectures. Covers building generative apps, multistep reasoning workflows, and production‑ready agent solutions.

  • Exam: AI‑103 (beta) — April 2026
  • Training: March 2026
  • Go-live: June 2026

Cybersecurity Business Professional
Validates your ability to recognize risks, apply secure-by-design practices, and support business decision‑making that enables secure AI adoption.

  • Exam: SC‑730 (beta) — April 2026
  • Training: May 2026
  • Go-live: July 2026

Azure AI Cloud Developer Associate
Designed for developers building and monitoring AI solutions on Azure using containers, vector databases, serverless components, and distributed observability.

  • Exam: AI‑200 (beta) — April 2026
  • Training: April 2026
  • Go-live: July 2026

Cloud and AI Security Engineer Associate
Focuses on securing cloud and AI workloads, protecting models, and applying enterprise‑grade security patterns.

  • Exam: SC‑500 (beta) — May 2026
  • Training: July 2026
  • Go-live: July 2026

Windows Server Hybrid Administrator
A unified Certification covering both Azure and on‑premises hybrid administration.

  • Exam: AZ‑802 (beta) — June 2026
  • Training: August 2026
  • Go-live: August 2026

Retiring Certifications: Key Dates & What Replaces Them

As Microsoft updates its Certification portfolio for modern AI‑driven roles, several existing Certifications are scheduled for retirement in 2026. If you hold one of these, make sure you renew it before the retirement date if renewal is available.

You can read more in the official Microsoft article here.

Microsoft Office for the web: Apply sensitivity labels with user-defined permissions

Updated February 13, 2026: The roll-out timeline has been updated!!

Microsoft 365 Office for the web will support applying sensitivity labels with user-defined permissions in Word, Excel, and PowerPoint starting mid-March 2026. This aligns with desktop app permissions dialogs, requires no admin changes, and enhances document access control without compliance impacts.

Office for the web now supports sensitivity labels with user‑defined permissions

Microsoft 365 Office for the web (Word, Excel, and PowerPoint) now includes the ability to apply sensitivity labels with user‑defined permissions, giving organizations greater flexibility and control over document access directly in the browser. This update aligns the web experience with the modern permissions dialog available in the desktop apps.

Roadmap ID: 468888

Rollout timeline

General Availability

  • Worldwide & GCC:
    Rollout begins mid‑March 2026 (previously mid‑February) and is expected to complete by early April 2026 (previously early March).
  • GCCH & DoD:
    Rollout begins mid‑March 2026 (previously mid‑February) and is expected to complete by early May 2026 (previously early April).

Who is affected

Compliance considerations

No new compliance impacts have been identified. Organisations may review the change as needed.

🚀 Strengthening Security in Microsoft Purview & Microsoft 365: Important Update Coming Soon

To further enhance the security and integrity of how Microsoft Purview interacts with Microsoft 365 services—such as Exchange, SharePoint, OneDrive, and Teams—Microsoft is modernizing how role management works within Purview.

Beginning mid‑February through late March 2026, Microsoft Purview will automatically map certain high‑privileged Purview admin roles to three newly created Microsoft Entra roles. This alignment strengthens identity and permission boundaries and ensures that all high‑impact actions (like search or export) are performed only by users with validated permissions in Entra.

đź“… Rollout Timeline

General Availability (Worldwide)
⏳ Begins: Mid‑February 2026
⏳ Complete: Late March 2026

The best part? No customer action is required.

Role assignments will synchronize automatically from Purview to Entra within minutes, ensuring that permissions flow securely and consistently across Microsoft 365.

📝 How to Prepare

  • No action is required—synchronization is fully automated.
  • Be aware that new Purview‑specific Entra roles may appear in audit logs.
  • Avoid assigning these roles directly in Entra.
  • Review your internal documentation and update governance workflows if needed.
  • For deeper technical detail, refer to Microsoft Purview documentation.

🏢 Impact on Your Environment

âś” Who Is Affected

Organizations with admins assigned to high‑privileged Purview roles.

✔ What You’ll See

  • New Purview‑specific Entra roles appearing in audit logs
  • Auto‑generated Entra role assignments, managed solely by Purview
  • No disruption to existing workflows or permissions

âś” What You Need To Do

  • No action required
  • DO NOT manually assign these roles in Entra
  • Update documentation or internal governance policies if referencing these roles
  • Inform your security/compliance teams about the new audit log entries

Compliance & Security Notes

  • No new compliance concerns identified
  • Mapping ensures consistent identity + permission enforcement across M365
  • Supports least‑privileged access by validating roles in both Purview and Entra