Things to Know About Microsoft Purview – September 2026 

Albert Hoitingh's avatarPosted by

Reading time (approx.): 15 minutes

Summary 

Microsoft Purview is moving in two connected directions: enforcement is extending beyond Microsoft 365 across applications, endpoints, browsers and networks, while governance is expanding from documents and data into AI systems and autonomous agents. 

The most consequential platform changes include network-layer DLP through Microsoft Entra Global Secure Access, DLP and automatic sensitivity labeling for non-Microsoft connected applications, higher auto labeling throughput, testable policy simulation, stronger privileged-access controls and better evidence of classification and endpoint enforcement. 

At the same time, Purview can constrain the data used to ground Microsoft 365 Copilot, bring Microsoft Agent 365 and Copilot Cowork into the compliance perimeter, extend visibility to Anthropic Claude and cross-cloud AI scenarios, and support aggregate investigation of endpoint data-loss activity. 

Together, these developments shift the executive question from whether individual Purview features are configured to whether sensitive data and AI interactions are consistently classified, monitored, enforced, retained and evidenced across every relevant platform and control layer. Preview capabilities should remain bounded pilots and should not be represented as operating controls. 

September 2026 edition

I decided to create this article to combine material from May, June, July and August 2026 articles on Microsoft Learn, Microsoft Security Blogs and Microsoft Purview Blogs. The information is publically available – links are detailed at the end of the article. My aim is to publish this type of article every month. Beware the length; This article covers (at least) four months.

C-level impact

Strategic implications for the CIO 

Purview is increasingly becoming a unified governance and protection platform across Microsoft 365, non-Microsoft applications, AI services and, in preview, network traffic. This strengthens the case for reducing overlapping security and compliance tools. As AI governance expands across Microsoft, third-party and multi-cloud environments, separate AI governance platforms should be evaluated against Purview rather than adopted by default.

Organizations should require governance approval before introducing new AI assistants, agents or AI-powered services, ensuring retention, discovery and data residency requirements are addressed upfront. Granular endpoint enforcement is now largely a policy and operating-model challenge rather than a technology limitation. At the same time, AI monitoring introduces variable consumption costs that should be actively managed and budgeted.

Strategic implications for the CISO 

Data protection is shifting from endpoints and collaborative environments to the locations where data actually leaves the organization: browsers, AI prompts and network traffic. Purview is expanding visibility and enforcement across these channels, as well as into non-Microsoft platforms such as Box and Google Workspace. Treat external email as a potential AI attack vector, not just a communication channel. New controls that restrict the use of externally sourced content in AI prompts should be evaluated for high-risk scenarios.

Measure DLP coverage by layer (endpoint, browser and network) to identify enforcement gaps. At the same time, shift Insider Risk Management from individual alert handling to broader behavioral and exfiltration pattern analysis. Finally, ensure endpoint controls can be validated through telemetry and include AI agents in incident response processes, with clear ownership, containment procedures and escalation paths.

Strategic implications for the Chief Data Officer 

Classification remains the foundation of AI governance. New simulation and insights capabilities make it easier to validate labeling policies before enforcement, while coverage now extends beyond Microsoft 365 to platforms such as Box and Google Workspace. AI interactions are becoming governed records in their own right. Prompts and responses across Copilot, agents and third-party AI tools require clear policies for retention, discovery and compliance.

Multi-vendor AI visibility is becoming achievable, helping organizations understand which data has been exposed to which AI systems. At the same time, monitoring should be selective to balance regulatory obligations, privacy expectations and cost. Finally, data governance should be measured by platform and enforcement layer. As AI and data estates expand beyond Microsoft services, broad coverage claims are no longer sufficient.


Data loss prevention moves to the network layer

Status: Preview – documented July 2026 

Purview now integrates with Microsoft Entra Global Secure Access so that organizations can intercept and inspect text and AI interactions at the network layer, enforce restrictive actions based on DLP policy, and detect risky user activity through Insider Risk Management.

The business significance is that enforcement no longer depends on the destination being a managed Microsoft application. For organizations whose principal exposure is employees pasting confidential material into unsanctioned AI services, this is the first control point that sits in the path of the traffic rather than on the endpoint alone. 


Data loss prevention policies and sensitivity labeling extend to non-Microsoft connected applications 

Status: Preview – documented August 2026 

Organizations can create DLP policies that protect sensitive data at rest in non-Microsoft connected applications such as Box and Google Workspace. As you might know, this type of functionality is provided using Microsoft Defender for Cloud Apps connectors and the Microsoft 365 classification engine. A single classification model and a single policy authority can now cover both Microsoft and (selected) non-Microsoft.

Status: Preview – documented August 2026 

Alongside the DLP change, auto-labeling policies can now protect sensitive data at rest in non-Microsoft connected apps including Box and Google Workspace, again using Defender for Cloud Apps and the Microsoft 365 classification engine. This matters more than it first appears. Sensitivity labels offer encryption, work in DLP conditions and determine access decisions that AI tools inherit.


Auto-labeling capacity to 500.000 files per day 

Status: Capacity increase announced in the Microsoft Security Blog, 27 August 2026 

Auto-labeling (E5 or E7) is one of the best ways (when done correctly) to ensure that documents get sensitivity labels applied, which in turn make Microsoft 365 Copilot more secure. The initial limit for auto-labeling (SharePoint and OneDrive) is set to 100.000 files per day. But this will increase to 500.000 files per day. As we all know, most tenants hold many, many files (tens of millions is no exception) so this increase is significant.


Simulation mode and policy insights

Status: New – documented August 2026 

Simulation mode is crucial for any activity that will influence the workings with information. DLP and auto labeling both have simulation modes, and I highly recommend using these. As of August 2026, a new Insights tab in the policy details panel gives an at-a-glance view of policy performance, with content that differs depending on whether the policy is in simulation or enforcement mode. This tab only appears for Microsoft 365 content.


Exchange Online DLP classification failures 

Status: Preview – documented July 2026 

Exchange Online DLP policies now detect classification failures caused by timeouts, throttling and other scanning errors. Classification is an integral part of many of Purview functions/solutions and it needs to work correctly. We don’t want to get overburdened by false positives, for instance when the message could not be scanned and is flagged as an issue. So now, administrators can enable classification-failure detection and use the DocumentScanFailures condition to apply different protection actions.


Insider Risk Management single alert queue 

Status: Preview – documented July 2026 

There are multiple items in this category. So let’s dig in. The Triage Agent dashboard and the standard alert dashboard are being combined into a single alerts list, so classic and agent-triaged alerts are managed in one place, with agent summaries and alert and user details available directly on the list.

User profile detail expands with Microsoft Entra signals including office location, employee type, department and last working date, and analysts can now add notes on both alerts and cases, with system-generated notes applied automatically on changes to status, assignment, closure or case escalation.

By the way – I had this conversation not to long ago with an organization; Expanding personal attributes inside an investigative workflow engages works council consultation and data protection assessment requirements in several European jurisdictions, and should not be enabled on the assumption that a technical preview is a legal clearance. 


Permanent deletion under priority cleanup approval

Status: Updated – documented July 2026 

Priority cleanup policies expedite the permanent deletion of (sensitive/redundant) information from mailboxes. Let’s say we have meeting transcripts that are covered by a retention policy for seven years – but these are redundant after six months. Priority cleanup allows us to remove these, when needed.

But this will require oversight and this was provided with an approval workflow. Now this workflows requires three separate approvers: one Priority Cleanup administrator, one retention manager and one eDiscovery administrator. This applies separation of duties (when correctly implemented in the organization itself) to the single most irreversible action the platform can take.


Purview role-group assignments expiration 

Status: Updated – documented July 2026 

As we know, Purview roles (not the Compliance Administrator) are not part of Entra ID Privileged Identity Management and just-in-time-access. Now however, role-group assignments (excluding eDicovery Administrator and eDiscovery Manager) in Microsoft Purview can be configured with an expiration date, so that access is revoked automatically. This is a great addition without requirering additional tooling or licensing. 


Fabric insights, Data Map continuity, and withdrawn scope 

Status: Updated, New and Retired – documented July 2026 

Administrators can now use Microsoft Fabric governance experiences in the OneLake catalog to understand DLP activity and adoption, identifying evaluated workspaces, locating sensitive information, tracking policy adoption and prioritizing high-risk assets. Purview protection policies no longer support Azure SQL Database. I am not sure why this scope has changed. There are some other changes coming, which I will probably do a write-up on in the next article.


Copilot: prevent using external emails

Status: Preview — Data Loss Prevention, June 2026 release notes 

I am still confinced that DLP is one of the greatest and core components of information protection in the new Frontier/Agentic world. And the functionality keeps expanding. A new “Email is received from > External users” condition for the Microsoft 365 Copilot and Copilot Chat policy location prevents Copilot from using externally originated emails. The main reason: the prevent prompt-injection attacks.

This is one of the earlier attack-vectors: sending an email using the html-body to include AI prompts and commands. As the email is opened by the user (your CFO for example), the prompt will be using these credentials. This DLP condition might just become crucial for your tenant protection.


Agent 365 GA

Status: Generally available — May 2026 release notes 

In May, Agent 365 became generally available and also part of the new Microsoft 365 E7 licensing suite. Any organization now has a supported means of establishing what agents are used, requested and what data was involved.


Purview and Anthropic Claude (Enterprise) 

Status: Preview — May 2026 release notes

Organizations can add and configure an Anthropic Claude data connector, after which Claude appears as another AI application alongside Microsoft 365 Copilot, Copilot Studio, ChatGPT Enterprise and others. Activity explorer can be used to see individual Claude interactions — who used it, when, and what kinds of content were involved — in the same way as for other AI applications. 


Extending protection to AWS Bedrock agents 

Status: Guidance published on the Microsoft Purview blog, Microsoft Tech Community, 5 June 2026 

Microsoft has published guidance for extending Microsoft Purview data protection to AWS Bedrock agents for cross-cloud AI governance, addressing the common pattern in which an organization governs with Microsoft 365 and Purview while running AI workloads in more than one cloud. 


Endpoint DLP scope to device groups 

Status: New — Data Loss Prevention, June 2026 release notes 

An Endpoint DLP policy can be scoped to specific device groups — for example, enforcing a policy when Finance users access data from Windows devices but not when the same users work from macOS — using dynamic device groups defined in Microsoft Entra ID. Uniform enforcement was a bottleneck for organizations as it can be disruptive for other users.  


Endpoint DLP telemetry queries 

Status: New — Data Loss Prevention, June 2026 release notes 

Endpoint DLP device configuration and policy-sync attributes can be queried at scale through the DlpInfo column of the DeviceInfo table in Advanced Hunting in the Microsoft Defender portal, instead of relying on point-in-time exports from the Microsoft Purview portal. A separate device health reports dashboard provides monitoring of device onboarding status, policy update readiness and feature readiness for Endpoint DLP. 


Endpoint DLP evidence data source 

Status: Preview (endpoint DLP evidence collection); general availability for notifications; Updated for automatic data preparation — Data Security Investigations, June 2026 release notes 

Investigators can query data captured by endpoint DLP policies on onboarded devices and add the associated content to an investigation scope for AI-assisted analysis, enabling aggregate analysis of endpoint exfiltration events instead of per-alert triage. Data preparation now runs automatically in the background as items are added to scope, removing a manual vectorization step, and email and portal notifications for Data Security Investigations are generally available. 


Selective monitoring of generative AI applications 

Status: Generally available — Insider Risk Management, June 2026 release notes 

For Microsoft Copilot experiences and enterprise AI applications, organizations can now select or deselect which generative AI applications are monitored in Insider Risk Management policy indicators. The two main purposes for this is reducing alert noise and avoiding unnecessary pay-as-you-go billing charges. 


Conclusion 

One of my main themes throughout this blog is one of integration and having an overarching view and protection layer. In a new publised guidance, we frame this from the AI perspective. Data protection in Purview is layered – across endpoint, browser and network – enforcement layers that are complementary rather than alternatives. 

Treating these as seperate entities forms gaps. Enforcment on the managed endpoint alone leaves unmanaged devices and browser-based egress uncovered; one that enforces in the browser alone leaves application and API paths uncovered.

The combined direction of travel is clear and has been clear for the last couple of years: Microsoft Purview is the control plane that spans Microsoft and non-Microsoft data estates, multiple enforcement layers, AI assistants and autonomous agents. Classification reach and throughput are improving at the same time as evidence, investigation and administrative governance become more defensible. 

The practical priority is adoption discipline. Organizations should know which data and AI surfaces are live, what is classified and retained, where enforcement is genuinely operating, what remains in preview and which gaps require compensating controls. That evidence, rather than configuration alone, is the basis for confident AI expansion and credible regulatory assurance. 

Official sources 

Leave a Reply