Data Security Investigations: Investigation templates for common data security scenarios

Microsoft just made investigations in Purview Data Security a lot simpler and faster. You can now use ready‑made search templates designed for common data security scenarios, so you don’t have to start from scratch every time.

These built‑in templates help standardize the way investigations are run and reduce the amount of manual setup, meaning security analysts can jump straight into the work with minimal input.

The best part? This feature is already available worldwide, requires no administrative setup, and is ready to use out of the box saving valuable time and streamlining the overall investigation process.

What’s new and why it matters

Microsoft is making investigations in Purview Data Security much more approachable by introducing built‑in search templates. These templates are designed for the scenarios analysts deal with most often—like data exfiltration, compromised mailboxes, exposure of personal data, or even risky AI interactions.

Instead of building queries from scratch every time, investigators can now choose a ready‑made template, enter a few basic details (such as a user or site), and get started immediately. This not only speeds things up but also ensures investigations are more consistent across teams. It’s especially helpful for less-experienced analysts, lowering the learning curve and reducing the time needed to get value from the solution.

(This update is tracked under Microsoft 365 Roadmap ID 560326.)

Rollout timeline

  • General Availability (Worldwide): Available now

What this means for your organization

Who it impacts

  • Security analysts and investigators working with Microsoft Purview Data Security Investigations

Where you’ll see it

  • Microsoft Purview (web portal)
  • Data Security Investigations solution

In short, this update removes a lot of the friction from starting an investigation helping teams move faster, stay consistent, and focus on what actually matters: understanding and responding to risks.

Enhancing AI Analysis in Data Security Investigations: What’s Coming Next

Microsoft Purview is rolling out a series of improvements designed to make AI analysis in Data Security Investigations (DSI) faster, smoother, and easier for analysts to use.

With these updates, items added to an investigation will now be automatically prepared for AI analysis—removing a repetitive manual step and helping analysts get to insights sooner. Purview is also introducing a new standard categorization option, giving organizations a quicker and more cost‑efficient way to group and review investigation items. For deeper insights, advanced categorization, including AI‑generated topics, will continue to be available.

These changes are part of Microsoft 365 Roadmap ID 557556.

Rollout Timeline

  • Public Preview: Mid‑March 2026 → Mid‑April 2026
  • General Availability (Worldwide): Mid‑April 2026 → Mid‑May 2026

What This Means for Your Organization

Who will notice the changes?

  • Microsoft Purview administrators
  • Analysts and security teams using Data Security Investigations
  • Any Microsoft 365 tenant with access to DSI capabilities

What’s changing?

  • Automatic AI preparation:
    Items added to an investigation will automatically get ready for AI analysis. No extra clicks or steps required.
  • New standard categorization option:
    A streamlined way to categorize items, ideal for scenarios where speed and simplicity matter.
  • Advanced categorization remains:
    Organizations can still use richer AI‑powered topic grouping when deeper analysis is needed.
  • No configuration changes needed:
    Everything is enabled by default—no admin setup required.

What users may see

  • Faster time from “item added” to “item ready for analysis”
  • A refreshed UI for choosing between standard and advanced categorization

How to Prepare

There’s nothing you need to configure ahead of time. However, it’s helpful to:

  1. Inform analysts and SOC teams about the new categorization options and automatic AI preparation.
  2. Update internal documentation if you maintain guides or SOPs that describe DSI workflows.
  3. Review training materials so teams know when to choose standard vs. advanced categorization.