Microsoft Purview Autolabeling Gets a Major Scale Upgrade: From 4 Million to 20 Million Items

Microsoft is expanding the capabilities of Microsoft Purview Information Protection, making it easier for organizations to deploy and validate autolabeling policies across significantly larger data environments.  The headline enhancement is a substantial increase in autolabeling simulation capacity, growing from 4 million to 20 million items. For organizations managing large volumes of content across Microsoft 365, this change removes a major limitation when testing and validating labeling strategies before production deployment.

What’s Changing?

With this update, administrators will be able to simulate autolabeling policies against much larger datasets, helping them better understand potential policy impact and identify issues before enabling automatic labeling.

Microsoft is also introducing several improvements aimed at simplifying policy management and providing deeper visibility into how labeling policies perform.

Key Enhancements

Autolabeling simulations now support up to 20 million items

The previous simulation limit of 4 million items has been increased fivefold, allowing organizations to assess policy effectiveness across significantly larger data estates.

Expanded SharePoint targeting

Administrators will now be able to:

  • Select up to 1,000 individual SharePoint sites when configuring an autolabeling policy.
  • Use adaptive scopes that support up to 50,000 SharePoint sites per policy.
  • Filter SharePoint sites using the SiteTemplate property during policy creation, providing more granular control over policy targeting.

Improved reporting and visibility

Microsoft is enhancing the audit and reporting experience with new insights, including:

  • Summaries of the Sensitive Information Types (SITs) detected when labels are applied.
  • A new 30-day processing chart that shows the number of files processed each day, helping administrators track policy throughput and identify trends over time.

These reporting enhancements should make it much easier to understand why labels are being applied and monitor the effectiveness of information protection policies.

Rollout Timeline

Microsoft plans to release these capabilities according to the following schedule:

  • Public Preview: Early September 2026 through mid-September 2026
  • General Availability: Beginning in late October 2026

The features will be enabled automatically as they become available in each tenant.

What Does This Mean for Organizations?

For most organizations, no action is required. Existing autolabeling policies will continue to function exactly as they do today.

However, security and compliance teams may want to revisit policies that were previously constrained by simulation limits or SharePoint scope restrictions. The increased scale opens opportunities to include additional repositories and validate policies against much larger datasets before deployment. Organizations should also consider updating their operational and reporting processes to take advantage of the new SIT visibility and processing metrics.

Compliance Impact

The update does not change how labels work, how Sensitive Information Types are defined, or how customer data is handled.

Instead, Microsoft is increasing the scale at which policies can be evaluated while improving monitoring and reporting capabilities. The added visibility into detected Sensitive Information Types and policy processing activity should help compliance teams better demonstrate and validate their information protection efforts.

Final Thoughts

This is a welcome enhancement for enterprises managing large-scale Microsoft 365 environments. The jump from 4 million to 20 million simulated items, combined with expanded SharePoint coverage and richer reporting, makes Microsoft Purview’s autolabeling capabilities more practical for organizations with complex compliance requirements and large volumes of content. For many Purview administrators, the real value will come from being able to test policies more thoroughly, target more content locations, and gain better insight into exactly how their information protection strategy is performing.

Main Improvements Made

  • Converted formal release-note language into a conversational blog style.
  • Added clear section headings and narrative flow.
  • Focused on business value and real-world impact rather than feature descriptions alone.
  • Reduced repetitive compliance wording while preserving all key technical details.
  • Added a concise conclusion with practical takeaways for administrators and compliance teams.

MS-102 vs. AB-650: More Than a New Certification. A New Era for Microsoft 365 Administrators

When I first saw that Microsoft plans to retire MS-102: Microsoft 365 Administrator and introduce AB-650: Administering Microsoft 365 and AI Services, my immediate reaction wasn’t, “Oh, another certification update.”

Instead, I found myself thinking:  “This is a reflection of how our roles are changing.”

For years, Microsoft 365 administrators have focused on identities, security, compliance, endpoints, licensing, and tenant management. Those responsibilities aren’t going away. But something new is being added to the mix: AI administration.

And that’s exactly what makes the transition from MS-102 to AB-650 so interesting.


The Certification Many of Us Know: MS-102

MS-102 has long been considered the benchmark certification for Microsoft 365 administrators.

The exam validates skills across core areas including:

  • Microsoft 365 tenant management
  • Microsoft Entra ID
  • Identity and access administration
  • Microsoft Defender XDR
  • Microsoft Purview
  • Security and compliance operations

If you’ve spent time administering Microsoft 365 environments, chances are you’ve worked with most of these technologies already.

MS-102 is focused on keeping an organization secure, compliant, productive, and operational.

In many ways, it represents the traditional Microsoft 365 administrator role.

Why Microsoft Is Moving On

Technology never stands still.

Over the last two years, we’ve witnessed something that has fundamentally changed the workplace: the rapid adoption of AI.

Organizations are no longer asking whether they will use AI.

They’re asking:

  • How do we deploy it?
  • How do we govern it?
  • How do we secure it?
  • How do we control access to organizational data?
  • How do we manage AI agents?

These questions weren’t part of a traditional Microsoft 365 administrator’s responsibilities a few years ago.

Today, they are becoming part of everyday conversations.

Enter AB-650

AB-650 isn’t simply a rebranded MS-102.

It’s Microsoft’s acknowledgment that administrators now need a broader skill set.

While the certification still includes core Microsoft 365 administration concepts, it significantly expands into areas such as:

  • Microsoft 365 Copilot administration
  • AI governance
  • AI security
  • AI compliance
  • Agent management
  • Copilot deployment and adoption
  • Organizational AI readiness

In other words, the administrator role is evolving beyond users, devices, and workloads.

We’re now expected to understand and manage intelligent systems as well.


The Biggest Difference

If I had to summarize the difference between the two certifications in a single sentence, it would be this:

MS-102 focuses on managing Microsoft 365. AB-650 focuses on managing Microsoft 365 and AI.

That may sound like a small distinction, but it’s actually a major shift.

The modern workplace increasingly includes:

  • AI assistants
  • Copilot experiences
  • Automation agents
  • Intelligent workflows

Someone needs to govern those capabilities.

Someone needs to secure them.

Someone needs to make sure they are implemented responsibly.

Microsoft clearly sees administrators playing a key role in that future.

Should You Still Take MS-102?

Honestly, I think the answer depends on where you are in your journey.

If you’ve already invested time studying MS-102, I would absolutely consider completing it before retirement.

It’s still a respected certification, and the skills it validates remain highly relevant.

Identity, security, compliance, and administration aren’t becoming less important because AI arrived.

In fact, they’re becoming even more important.

AI simply adds another layer on top.

Who Should Consider AB-650?

If you’re starting fresh today, AB-650 is difficult to ignore.

It’s particularly relevant if you work with:

  • Microsoft 365 Copilot
  • Adoption and change management
  • Security and governance
  • Digital workplace transformation
  • Architecture and consulting roles

The certification aligns closely with the conversations many organizations are having right now around AI readiness and governance.

As someone who has spent much of her career in the Microsoft ecosystem, I see this transition as something bigger than an exam retirement.

I see it as a signal.

A signal that the industry is moving toward a future where administration, security, compliance, user experience, and AI are no longer separate disciplines.

They’re becoming interconnected.

A few years ago, administrators managed users.

Today, we’re beginning to manage users and AI assistants.

Tomorrow, we’ll likely be managing entire ecosystems of human and AI collaboration.

And that’s why I believe the move from MS-102 to AB-650 matters.

It’s not just about earning your next certification.

It’s about understanding where our profession is heading.

What do you think? Would you still pursue MS-102 before it retires, or would you jump directly into AB-650 and the AI-first future?

Microsoft 365 Copilot Gets Clearer DLP Notifications

Have you ever wondered why Copilot couldn’t access, process, or return certain content?
Microsoft is making that experience much easier to understand. Previously, users could see different messages depending on how a Microsoft Purview Data Loss Prevention (DLP) policy was triggered, which sometimes made it unclear why content wasn’t available.

With this update, Microsoft 365 Copilot will now display a consistent notification whenever organisational DLP policies prevent access to content. The goal is simple: improve transparency, reduce confusion, and help users understand that Copilot is respecting their organisation’s data protection policies.

What’s Covered?

The new standardized message applies to Microsoft Purview DLP protections across Microsoft 365 Copilot and Copilot Chat, including:

  • Grounding DLP
  • Prompt DLP
  • External Email DLP

Where Will Users See It?

The unified notification can appear across Microsoft 365 Copilot experiences powered by Microsoft 365 Chat orchestration, including:

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot Chat
  • Microsoft Teams Copilot experiences
  • Outlook on the web Copilot experiences
  • Microsoft Edge Copilot experiences
  • Other Microsoft 365 Copilot chat experiences that rely on Microsoft 365 Chat orchestration

Whenever a DLP policy restricts Copilot from using specific content, users will see the same clear message indicating that access to some content has been restricted by an organisational policy.

Rollout Timeline

The feature is now rolling out across all environments:

  • Worldwide: Available from July 15, 2026
  • GCC: Available from July 20, 2026
  • GCC High and DoD: Available from July 23, 2026

What This Means for Your Organisation

Organizations already using Microsoft Purview DLP with Microsoft 365 Copilot or Copilot Chat don’t need to take any action. The update does not change how DLP policies work. Instead, it improves the user experience by providing a clearer and more consistent explanation when content is blocked.

For IT administrators, this is a good opportunity to review existing training materials, user documentation, and support resources to ensure they reflect the new messaging experience.

Bottom line: the protection remains the same, but the explanation gets better. Users gain more clarity on why content is unavailable, while organisations continue to benefit from the same trusted data protection controls.

Microsoft Purview DLP: Instances Policy Location Retiring in January 2027

Microsoft has announced the retirement of the Instances policy location in Microsoft Purview Data Loss Prevention (DLP), with the change taking effect on January 6, 2027.

Today, organizations using the Instances location rely on the Microsoft Defender for Cloud Apps file policy infrastructure to enforce DLP and auto-labeling policies across supported third-party applications. To simplify policy management and provide a more consistent compliance experience, Microsoft is moving away from this approach and introducing dedicated application-specific policy locations directly within Microsoft Purview.

Supported applications include:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex
What’s Changing?

Instead of creating policies under a generic Instances location, administrators will use dedicated locations for each supported application.

For example:

Current LocationNew Location
Instances (Google Workspace)Google Workspace
Instances (Box)Box
Instances (Dropbox)Dropbox
Instances (Salesforce)Salesforce
Instances (ServiceNow)ServiceNow
Instances (AWS)AWS
Instances (Cisco Webex)Cisco Webex

This change aligns non-Microsoft application protection more closely with the broader Microsoft Purview compliance framework.

Microsoft is introducing these new application locations ahead of the retirement date to allow organizations time to migrate.

Key dates:

  • Dedicated application locations will be rolled out before retirement.
  • January 6, 2027: Instances policy location officially retires.
  • Retirement rollout begins in early January 2027 and is expected to complete by mid-January 2027.
What Happens After January 6, 2027?

Once the retirement takes place:

  • New policies can no longer be created using the Instances location.
  • Existing policies configured with the Instances location will no longer be supported.
  • Organizations should use the new dedicated application locations for all future DLP and auto-labeling policies.
  • Policies that continue to rely on the retired Instances location may no longer be enforced as expected.

If your organization currently uses the Instances location, Microsoft strongly recommends recreating those policies in the new application-specific locations before the retirement deadline.

Recommended Next Steps

To avoid any disruption to DLP enforcement, organizations should begin preparing well before the 2027 deadline.

1. Review Existing Policies

Identify any DLP or auto-labeling policies currently configured through the Instances location.

2. Identify Affected Applications

Determine which non-Microsoft platforms are involved and map them to their new dedicated policy locations.

3. Recreate Policies

Build equivalent policies using the new application-specific locations within Microsoft Purview.

4. Test and Validate

Before retiring legacy policies, verify that policy enforcement, labeling, and user experiences behave as expected.

5. Update Documentation

Review operational procedures, internal documentation, and administrator guidance to reflect the new management model.

6. Notify Stakeholders

Make sure compliance, security, and support teams are aware of the upcoming change and migration timeline.

While the retirement is still several months away, organizations using third-party cloud platforms for collaboration and data storage should start planning their migration strategy now. Moving to dedicated application locations will ensure continued DLP and auto-labeling protection while providing a more streamlined and unified compliance experience within Microsoft Purview.

The bottom line: If you’re using the Instances location today, plan your migration before January 6, 2027. If you’re not, you can safely continue using Microsoft Purview as normal and take advantage of the new dedicated application locations as they become available.

💜🏆Honored to Be Renewed as a Microsoft MVP for a Second Year

Some milestones feel just as special the second time around.

I’m incredibly grateful and honored to share that I have been renewed as a Microsoft Most Valuable Professional (MVP) for another year in M365 Copilot and Microsoft Purview.

When I first received the MVP award, I saw it as both a recognition and a responsibility. A responsibility to continue learning, sharing knowledge, supporting the community, and helping others get the most value from Microsoft technologies.

Over the past year, the pace of innovation has been extraordinary. The rapid evolution of AI, the growing adoption of Microsoft 365 Copilot, and the increasing importance of data security, governance, and compliance through Microsoft Purview have made this an exciting time to contribute to the community.

As I reflect on the past year, I’m grateful for every opportunity to engage with fellow professionals, exchange ideas, share experiences, create content, and learn from some of the brightest minds in the Microsoft ecosystem. The MVP community is filled with individuals who are passionate about helping others succeed, and it is a privilege to be part of it.

This renewal is not just about individual achievements. It represents the value of collaboration, community, and continuous growth. Every conversation, challenge, lesson learned, and connection made along the way has contributed to this journey.

Thank you to Microsoft for this continued recognition and trust. Thank you to the MVP Program team, my colleagues, friends, mentors, customers, and the incredible community members who inspire me every day.

Most importantly, thank you to everyone who shares their knowledge, asks thoughtful questions, provides feedback, and helps make our community stronger. Your contributions are what make this ecosystem thrive.

As I begin my second year as an MVP, I’m excited to continue exploring what’s possible with AI, M365 Copilot, and Microsoft Purview, while giving back to the community that has given me so much.

Here’s to another year of learning, sharing, growing, and making an impact together.

Thank you for being part of the journey. 💜

Joanna Vathis
Microsoft MVP | M365 Copilot | Microsoft Purview

Microsoft Purview Adds Time-Limited Role Assignments to Strengthen Security

Microsoft is enhancing Microsoft Purview with a new capability that allows administrators to assign expiration dates to role group memberships. This update makes it easier to grant temporary administrative access while supporting the principle of least privilege, helping organizations reduce the risk associated with long-term privileged accounts.

With this new feature, administrators can specify how long a user or security group should remain in a Purview role group, choosing a duration anywhere from one day up to two years. Once the assigned period expires, access is automatically removed, helping security and compliance teams maintain tighter control over administrative permissions.

When Will It Be Available?

Microsoft plans to roll out the feature according to the following schedule:

  • Worldwide General Availability: Starting in late July 2026 and expected to complete by late August 2026.
  • GCC, GCC High, and DoD: Starting in late August 2026 and expected to complete by late September 2026.
What Does This Mean for Organizations?

This enhancement primarily benefits:

  • Microsoft Purview administrators
  • Security administrators
  • Compliance teams
  • Organizations managing role-based access through Microsoft Purview

The feature will be available through:

  • Microsoft Purview Compliance Portal
  • Microsoft Purview Role-Based Access Control (RBAC)
Key Benefits

Once the rollout is complete, administrators will be able to:

✅ Assign users or security groups to role groups with a predefined expiration date.

✅ Set assignment durations ranging from 1 day to 2 years.

✅ Apply the capability to both new and existing role assignments.

✅ Reduce the likelihood of forgotten or unnecessary privileged access.

✅ Improve governance, compliance, and security posture with minimal administrative effort.

Importantly, existing role assignments will not be automatically modified, and end-user workflows will remain unchanged.

What Do You Need to Do?

The good news is that no action is required to enable this feature. It will be available by default once deployed, with no additional configuration or policy changes needed.

However, organizations may want to take advantage of the new functionality by:

  • Reviewing privileged access management processes.
  • Using expiration-based assignments for temporary projects, audits, or administrative tasks.
  • Updating internal documentation and operational procedures.
  • Informing Purview administrators about the new capability.

From a compliance perspective, time-limited role assignments help organizations demonstrate stronger control over privileged access.

Many regulatory frameworks and security standards—including ISO 27001, NIST, SOC 2, GDPR accountability requirements, and Zero Trust security principles—expect organizations to follow the principle of least privilege, ensuring users only have access to the resources they need and only for as long as they need it.

🎙️Podcast Episode: Smarter Insider Risk Coverage with Microsoft Purview

🎙️ New podcast episode just dropped!

We’re diving into Smarter Insider Risk Coverage with Microsoft Purview together with Pip & Mara, breaking down what’s new, why it matters, and how it can help organizations stay ahead of insider risks.

If you’re working in security, compliance, or Microsoft 365, this one’s definitely worth a listen 👇

▶️ Watch now on YouTube

Stay tuned…

Smarter Insider Risk Coverage with Microsoft Purview

Microsoft is making Insider Risk Management in Purview even more useful with the introduction of a Policy Recommendation panel, a feature designed to help admins quickly spot gaps in their current risk coverage and strengthen their defenses.

Let’s face it: even with policies in place, it’s not always easy to know what you might be missing. That’s where this new capability comes in. It analyzes your existing setup and highlights missing or high-impact policies, offering clear, actionable suggestions to improve your security posture.

What’s new?

The Policy Recommendation panel lives directly on the Policies page and automatically reviews your current configuration. Using built-in analytics, it identifies areas where you could increase protection and recommends policies to cover common insider risk scenarios like:

  • Data leakage
  • Data theft
  • IP theft
  • Risky AI usage
  • Other security violations

It’s essentially a built-in advisor that helps you get more value from Insider Risk Management without needing to manually audit everything.

A quick reminder: what Insider Risk Management does

Microsoft Purview Insider Risk Management works by correlating signals across your environment to detect potentially risky behavior, whether intentional or accidental.

It’s also designed with privacy in mind, including:

  • Pseudonymization by default
  • Role-based access controls
  • Audit logs for transparency

So you can investigate risks while still protecting user privacy.

Rollout timeline
  • Public Preview: Mid–June 2026 → Late June 2026
  • General Availability: Mid–July 2026 → Late July 2026

This message is associated with Microsoft 365 Roadmap ID 560600.

Podcast Episode: DSI Investigation templates for common data security scenarios

🎙️ New podcast episode just dropped!
DSI Investigation Templates for Common Data Security Scenarios with Pip & Mara
▶️ Watch now on YouTube

Stay tuned…

Data Security Investigations: Investigation templates for common data security scenarios

Microsoft just made investigations in Purview Data Security a lot simpler and faster. You can now use ready‑made search templates designed for common data security scenarios, so you don’t have to start from scratch every time.

These built‑in templates help standardize the way investigations are run and reduce the amount of manual setup, meaning security analysts can jump straight into the work with minimal input.

The best part? This feature is already available worldwide, requires no administrative setup, and is ready to use out of the box saving valuable time and streamlining the overall investigation process.

What’s new and why it matters

Microsoft is making investigations in Purview Data Security much more approachable by introducing built‑in search templates. These templates are designed for the scenarios analysts deal with most often—like data exfiltration, compromised mailboxes, exposure of personal data, or even risky AI interactions.

Instead of building queries from scratch every time, investigators can now choose a ready‑made template, enter a few basic details (such as a user or site), and get started immediately. This not only speeds things up but also ensures investigations are more consistent across teams. It’s especially helpful for less-experienced analysts, lowering the learning curve and reducing the time needed to get value from the solution.

(This update is tracked under Microsoft 365 Roadmap ID 560326.)

Rollout timeline

  • General Availability (Worldwide): Available now

What this means for your organization

Who it impacts

  • Security analysts and investigators working with Microsoft Purview Data Security Investigations

Where you’ll see it

  • Microsoft Purview (web portal)
  • Data Security Investigations solution

In short, this update removes a lot of the friction from starting an investigation helping teams move faster, stay consistent, and focus on what actually matters: understanding and responding to risks.