Microsoft Purview DSPM now includes a new data security agent to strengthen your data protection posture

Microsoft has officially moved Data Security Posture Management (DSPM) in Microsoft Purview from preview to general availability (GA) and that’s a big step forward for organizations looking to strengthen how they protect sensitive data.

At its core, DSPM helps you understand where your data risks really are, giving you better visibility across your Microsoft 365 environment. Instead of piecing things together manually, you get clear insights, risk signals, and practical recommendations to help improve your overall data security posture.

This release is part of Microsoft’s ongoing investment in enterprise-grade security and compliance tools, making it easier to protect data at scale without added complexity.

What’s New

One of the key additions in this GA release is the Data Security Posture Agent, now fully available.

With it, you can:

  • Get a centralized view of data risks across your environment
  • Identify potential gaps in your security posture
  • Access actionable recommendations to improve protection
  • Take direct steps to remediate risks

The transition from preview to GA is seamless—your existing configurations stay as they are, and there’s no need to reconfigure policies or settings.

Rollout Timeline
  • General Availability (Worldwide): Late May 2026 – Late June 2026

The feature will become available based on your organization’s Microsoft Purview deployment timing.

Who Should Pay Attention

This update is especially relevant for:

  • IT admins
  • Security teams
  • Compliance professionals

Basically anyone responsible for managing or protecting data within Microsoft 365 using Microsoft Purview.

What This Means for You

Good news, no action is required to enable this feature.

That said, it’s a great opportunity to take advantage of what DSPM offers. You might want to:

  • Explore the new DSPM capabilities and see how they fit into your security strategy
  • Learn how to set up and use the Data Security Posture Agent
  • Start using DSPM insights to prioritize and reduce data risks
  • Inform your security and compliance teams about the update
  • Update any internal documentation that references Purview DSPM

Meet the New Cyber Heroes Crew: Morgi & Spot 🐾

🟣 Morgi: The AI Superhero

Morgi is the thinker of the Cyber Heroes Crew, the one who’s always quietly paying attention. Curious, clever, and powered by AI, she has a gift for noticing patterns that others overlook and figuring out what they mean before something goes wrong.

With her softly glowing purple shield by her side, Morgi keeps an eye on the digital world, catching phishing tricks, malware, and even deepfakes in seconds. She doesn’t just spot danger, she explains it in a way people can understand, helping them feel confident instead of overwhelmed.

At heart, Morgi wants everyone to feel safe and informed online. Her mission is simple: make technology smarter, friendlier, and safer for everyone who uses it.

Superpower: Seeing Ahead

Morgi’s strength comes from understanding, reading signals, connecting dots, and knowing what’s likely to happen next. By thinking ahead, she helps everyone stay one step ahead too.

🐾 When Morgi is watching, clarity replaces confusion.

🔵 Spot: The Cybersecurity Hero

Spot is the one who looks out for you when you’re busy, distracted, or just trying to get through your day. Quietly observant and steady by nature, Spot stays close, keeping watch over your data and devices so you don’t have to worry about every little thing online.

With his familiar blue shield always nearby, Spot steps in when something doesn’t feel right, blocking phishing attempts, stopping ransomware, and protecting personal information before it’s ever at risk. He doesn’t make a fuss about it. He just does what needs to be done.

Spot believes safety starts with small moments of awareness. A pause before clicking. A second look at an email. A gentle reminder that it’s okay to slow down. That simple “think before you click” mindset is how Spot helps people stay safe without feeling stressed or overwhelmed.

At the heart of it all, Spot’s role is simple and reassuring:
to stand beside you, quietly protecting your digital world, every step of the way.

What Makes Spot Special

Spot’s strength isn’t flash or noise—it’s presence. He’s patient, dependable, and always paying attention, so you can move through the online world with confidence.

🐾 When Spot is around, you’re not facing the internet alone.

Together

Morgi analyzes. Spot protects.
Side by side, they form the ultimate cybersecurity duo, keeping Jo SNAI’s digital world secure, intelligent, and one step ahead of every threat.

🚀 Stay tuned as Morgi & Spot dive into their next cyber adventure! 🐾🐾

Microsoft Purview | DLP protections to prevent sensitive data from leaving your organization through external web search in Microsoft 365 Copilot and Copilot Chat

Microsoft is rolling out an important enhancement to help organizations use Microsoft 365 Copilot more securely. Starting this year, Microsoft Purview Data Loss Prevention (DLP) will include new protections designed specifically for Copilot and Copilot Chat. The goal: prevent sensitive data from being sent to external web search engines during AI‑assisted interactions.

This update introduces real‑time DLP evaluation for prompts that contain Sensitive Information Types (SITs). When Copilot detects protected data in a user’s prompt, it will block any external web search from taking place. Instead, Copilot will continue responding only with internal Microsoft Graph data provided that the user’s licensing allows it.

This feature corresponds with Microsoft 365 Roadmap ID 548671.

Rollout Timeline

Public Preview
Begins: Late March 2026
Completes: Late April 2026

General Availability (Worldwide)
Begins: Late June 2026
Completes: Late July 2026

What This Means for Your Organization
Who Will Be Affected?

This update is relevant for:

  • Organizations using Microsoft 365 Copilot, Copilot Chat, or Copilot Studio agents published to Microsoft 365.
  • Admins who manage Data Loss Prevention policies in the Microsoft Purview portal.
What’s Changing?
New DLP Control for Copilot Web Search

Admins will soon see a new option when configuring DLP policies: the ability to stop Copilot from using external web search when a prompt includes specific sensitive information types.

When this policy is triggered:

  • Copilot will not send content to external web search providers.
  • Copilot will still respond, drawing exclusively from internal Microsoft Graph data sources (assuming the user’s licensing supports this).

New in Microsoft Purview: Smarter Credential Scanning to Strengthen Your Data Security

Microsoft is rolling out a major update to the Data Security Posture Agent in Microsoft Purview, and it’s a big step forward for organizations looking to stay ahead of credential‑related risks.

The newest addition is a credential scanning capability designed to help you uncover exposed credentials, like Microsoft Entra ID details, private keys, API tokens, and other sensitive access points across your selected data locations. With this update, Purview doesn’t just spot the issues; it also gives you risk scores, AI‑generated insights, confidence levels, and credential categories so you can quickly understand what matters and what needs attention.

All findings are surfaced in one streamlined task board, making it easier than ever to review, confirm, and take action.

This enhancement is listed as Microsoft 365 Roadmap ID 558436.

Rollout Timeline
  • Public Preview: Starts late March 2026, expected to finish by early April 2026
  • General Availability (Worldwide): Starts late June 2026, wrapping up by early July 2026

What This Means for Your Organization

Who will notice the change?

Admins who manage Microsoft Purview and use the Data Security Posture Agent within Microsoft 365 tenants will see the new feature appear under the Explore Agent section.

What’s changing?

A brand‑new credential scanning experience is being introduced, including:

  • LLM-powered detection of exposed credentials across selected data locations
  • Automated identification of:
    • Microsoft Entra ID credentials
    • Private keys
    • API tokens
    • Additional sensitive credential types

Each detection comes with:

  • A risk score
  • AI-generated insights
  • A confidence rating
  • A credential category

And to help you stay organized, Purview provides a task board where you can follow up on findings, track progress, and take recommended actions, all in one place.

How to Prepare

New in Microsoft Defender XDR: AI‑Powered Summaries for DLP Alerts

Microsoft is rolling out a great new capability that will make life much easier for anyone who works with Data Loss Prevention (DLP) alerts. You’ll now start seeing AI‑generated summaries and categorizations, produced by the Microsoft Purview Data Security Triage Agent, directly inside the Microsoft Defender XDR portal.

This means faster triage, clearer insights, and less time manually digging through alert details.

What’s new?

When a DLP alert fires, analysts will now see:

  • A concise AI‑generated summary of what happened
  • A suggested categorization of the alert
  • Context pulled directly from the incident to help speed up investigation

If you’ve already deployed the Triage Agent in Purview, these summaries will show up automatically in your Defender XDR alerts. If not, eligible analysts will be able to deploy it directly from the alert page super handy.

Rollout timeline

Public Preview
Starts: Early April 2026
Completed by: Mid‑April 2026

General Availability (Worldwide)
Starts: Mid‑August 2026
Completed by: Late August 2026

Roadmap ID: 558860

Who is impacted?

This update is especially helpful for:

  • Security analysts and administrators triaging DLP alerts in Defender XDR
  • Organizations already using (or planning to use) Microsoft Purview’s Data Security Triage Agent

Existing DLP policies, enforcement, and user experience remain unchanged.

Data Security Investigations introduces new soft purge mitigation action

Microsoft is introducing a new soft purge action in Data Security Investigations (DSI), giving admins a quick and safe way to remove sensitive or overshared files during an investigation. With soft purge, items can be deleted immediately but still recovered later as long as they’re within their deleted‑item retention period, so admins get speed without risking permanent data loss.

This builds on DSI’s growing set of AI‑powered tools like intelligent categorization, AI search, and automated risk insights making it easier than ever for organizations to spot issues and take action fast.

New update coming to Microsoft 365 Roadmap ID 558109. A soft purge action will soon be available in Data Security Investigations (DSI), giving admins a safer and more flexible way to remove sensitive or overshared content during an investigation.

When it’s rolling out
  • General Availability (Worldwide): Begins early April 2026
  • Expected completion: late May 2026

What this means for your organization

Who is affected?

Admins who use Data Security Investigations (DSI) in the Microsoft Purview compliance portal.

What’s changing

A new soft purge option will appear in DSI. With this action, admins can:

  • Remove items that match an investigation query
  • Keep those items recoverable until the retention period expires
  • Act quickly without risking accidental permanent deletion

And the best part:

  • The feature is on by default
  • No configuration needed
  • No changes to existing DLP, labeling, or retention policies
  • End users will not see any changes in their workflows

Once the rollout finishes, the feature simply appears for eligible tenants.

How to prepare

There is nothing you need to do in advance.
If you want to get ahead, you may consider:

  • Reviewing how soft purge works in DSI
  • Updating any internal guidance on investigation processes
  • Informing your security or compliance teams about the new action

Overall, this update gives organizations a safer and more controlled way to remove sensitive content during investigations—without adding extra steps or complexity.

Enhancing AI Analysis in Data Security Investigations: What’s Coming Next

Microsoft Purview is rolling out a series of improvements designed to make AI analysis in Data Security Investigations (DSI) faster, smoother, and easier for analysts to use.

With these updates, items added to an investigation will now be automatically prepared for AI analysis—removing a repetitive manual step and helping analysts get to insights sooner. Purview is also introducing a new standard categorization option, giving organizations a quicker and more cost‑efficient way to group and review investigation items. For deeper insights, advanced categorization, including AI‑generated topics, will continue to be available.

These changes are part of Microsoft 365 Roadmap ID 557556.

Rollout Timeline

  • Public Preview: Mid‑March 2026 → Mid‑April 2026
  • General Availability (Worldwide): Mid‑April 2026 → Mid‑May 2026

What This Means for Your Organization

Who will notice the changes?

  • Microsoft Purview administrators
  • Analysts and security teams using Data Security Investigations
  • Any Microsoft 365 tenant with access to DSI capabilities

What’s changing?

  • Automatic AI preparation:
    Items added to an investigation will automatically get ready for AI analysis. No extra clicks or steps required.
  • New standard categorization option:
    A streamlined way to categorize items, ideal for scenarios where speed and simplicity matter.
  • Advanced categorization remains:
    Organizations can still use richer AI‑powered topic grouping when deeper analysis is needed.
  • No configuration changes needed:
    Everything is enabled by default—no admin setup required.

What users may see

  • Faster time from “item added” to “item ready for analysis”
  • A refreshed UI for choosing between standard and advanced categorization

How to Prepare

There’s nothing you need to configure ahead of time. However, it’s helpful to:

  1. Inform analysts and SOC teams about the new categorization options and automatic AI preparation.
  2. Update internal documentation if you maintain guides or SOPs that describe DSI workflows.
  3. Review training materials so teams know when to choose standard vs. advanced categorization.

✨ Excited to share this new Microsoft webinar that breaks down how Copilot empowers organizations with secure, privacy‑first AI.

🚀 Your Data. Your control. Your Copilot.
💡 The future of AI isn’t just powerful — it’s responsible.

Microsoft’s latest vision for Copilot reinforces something essential:
AI should empower you, not replace you. It should protect your data, not access it. And it should enhance your capabilities, not compromise your privacy.

In this new video, Microsoft breaks down how Copilot is designed with:
🔐 Enterprise‑grade security
🛡️ Built‑in data governance
💼 User control at the center
🤖 AI that respects boundaries and boosts productivity
👉Check also the demo for the New DLP protections for Microsoft 365 Copilot

If you want to understand why responsible AI matters — and how organizations can adopt Copilot with confidence — this is a must‑watch.
YouTube 🎥👉 https://www.youtube.com/watch?v=ukjs4BnmPsM

AI is evolving fast, but one principle must stay constant:
Trust is not optional. Trust is engineered.

DLP Policies Now Block Copilot Processing Across All Storage Locations

Microsoft is improving how Microsoft Purview Data Loss Prevention (DLP) protects content used by Microsoft 365 Copilot. Until now, DLP rules that block Copilot from processing sensitivity‑labeled content only worked when files lived in SharePoint or OneDrive.

With this update, those same protections will work everywhere, including local files stored on a user’s device. Organizations have asked for more consistent protection across all file locations, and this update delivers exactly that.

This change is associated with Microsoft 365 Roadmap ID 557255.

When it’s coming

General Availability (Worldwide + GCC)
Rollout: Late March 2026 → Late April 2026

Who this impacts

  • Organizations using Microsoft Purview DLP to limit what Copilot can access
  • Admins who manage Purview DLP rules
  • Users working with Copilot in Word, Excel, or PowerPoint

What’s changing

DLP rules that block Copilot from processing certain sensitivity-labeled files will now apply to:

  • SharePoint
  • OneDrive for Business
  • Local device storage
  • Any other file location Office apps can open

So if a DLP policy says “Copilot cannot process Confidential files,” then Copilot will not process those files anywhere, including when they’re opened directly from the desktop.

Key notes:

  • Existing DLP rules continue to work as they do today—no reconfiguration needed.
  • The feature turns on automatically for tenants already using relevant DLP policies.
  • Users will experience consistent protection when using Copilot across Word, Excel, and PowerPoint.

How it works (technical detail)

This update doesn’t change what Copilot can do—it changes how Office apps share sensitivity label information with AugLoop (the Copilot orchestration layer).

Today:
AugLoop reads file labels through Microsoft Graph
This only works for SharePoint or OneDrive files

After the update:

  • Office apps will pass the sensitivity label directly to AugLoop
  • This means DLP rules can finally apply to local and other non-cloud storage files too

This results in uniform, predictable DLP enforcement across all file locations.

Updated Announcement: Microsoft Purview – New Purview Agent Deployment Role

Microsoft Purview introduces a new Purview Agent Deployment role added to several built-in role groups, allowing analysts to deploy and manage Purview agents without admin help. Rollout starts late February 2026, improving onboarding and agent use while maintaining existing data access and compliance controls.

Microsoft introducing a new Microsoft Purview Role-Based Access Control (RBAC) role—Purview Agent Deployment—and adding it to several existing built‑in Purview role groups. This enhancement empowers analysts who work with Purview agents to deploy and manage them directly, without requiring administrator involvement. The change streamlines onboarding and supports broader adoption of Purview’s AI‑powered agent capabilities.

This update corresponds to Roadmap ID 551147.

Rollout Timeline

  • General Availability (Worldwide): Begins late February 2026
  • Expected Completion: Mid‑March 2026

Who is affected

  • Administrators managing Purview role groups
  • Analysts deploying or working with Microsoft Purview agents

What’s changing

The new Purview Agent Deployment role will be added to the following built‑in role groups:

  • Compliance Administrator
  • Data Security Management
  • Information Protection
  • Information Protection Analysts
  • Information Protection Investigators
  • Insider Risk Management
  • Insider Risk Management Analyst
  • Insider Risk Management Investigator
  • Purview Agent Management

The Purview Agent Management role group will continue to include the Purview Content Analyst role and retain access to Posture agent capabilities.

Capabilities enabled

Users assigned to these role groups will be able to deploy, use, and manage Purview agents end‑to‑end, including:

  • Data Loss Prevention (DLP) — Data Security Triage Agent
  • Insider Risk Management (IRM) — Data Security Triage Agent
  • Data Security Posture Management (DSPM) — Posture Agent
  • Future Purview agents as they are released

Important:

  • No default data access permissions are modified.
  • No new visibility into customer content is introduced.
  • Organizations can optionally enforce separation of responsibilities by using custom role groups.