
💡 Our Technical Review in summary
- Microsoft is introducing a significant evolution of Purview Data Security Posture Management (DSPM), unifying visibility across traditional data and AI-driven environments.
- The update features outcome-based guided workflows, AI observability, and intelligent Security Copilot agents to automate risk triage and policy management.
- Coverage is expanded to include third-party signals from security partners such as BigID, Cyera, OneTrust, and Varonis.
- Enhanced remediation capabilities are included, specifically the ability to perform bulk actions like disabling overshared SharePoint links and conducting item-level analysis in Microsoft Fabric.
Impact
- Timeline: Public Preview begins early December 2025. General Availability (GA) is scheduled to start and complete in June 2026.
- User Interface: Admins will see a new, streamlined interface for DSPM. However, the “Classic” DSPM and “DSPM for AI (Classic)” views will remain accessible for the time being.
- Configuration: Existing policies, configurations, and onboarding steps will carry over automatically. There are no changes to default policies during this rollout.
- Efficiency: Security teams will gain a more centralized view of sensitive data across multi-cloud environments, reducing the need to jump between different consoles.
Action Required
- No immediate action: The transition to the new experience is automated for customers already using Purview DSPM.
- Review Documentation: Monitor Microsoft Learn for updated guidance on AI observability and Security Copilot integration prior to the December 2025 preview.
- Identify Use Cases: Evaluate if third-party integrations (e.g., Varonis, Cyera) are relevant to your environment to take full advantage of the unified signal view.
- Internal Training: Plan to update internal SOPs for security analysts to include the new bulk remediation actions and Copilot-driven triage workflows.
Microsoft Official Update
Service: N/A
Category: planForChange
Severity: normal
Updated March 18, 2026: We have updated the timeline. Thank you for your patience.
[Introduction]
Microsoft is introducing a major evolution of Purview Data Security Posture Management (DSPM) to help organizations strengthen data security and confidently embrace AI. The new DSPM experience unifies visibility and control across traditional data and AI-driven environments, delivering outcome-based guided workflows that turn insights into actionable steps—so teams can prioritize risks and remediate faster. It brings AI observability, enhanced posture reporting, and intelligent Security Copilot agents to automate tasks like triage and policy management.
Purview now also extends coverage beyond Microsoft data with third-party signals from partners like BigID, Cyera, OneTrust, and Varonis, giving security teams a single, streamlined view of sensitive data across clouds and platforms. Additionally, Data Risk Assessments are extended to Fabric and item-level analysis with new remediation actions like bulk disabling of overshared SharePoint links.
This message is associated with Microsoft 365 Roadmap ID 532728.
When this will happen:
- Public Preview (Worldwide): Rollout begins early December 2025 and completes by early April 2026.
- General Availability (Worldwide): Rollout begins early June 2026 (previously early April) and completes by early June 2026 (previously early May).
How this affects your organization:
- Who is affected: Admins managing Microsoft Purview DSPM.
- What will happen:
- Customers will continue to have access to the current DSPM (classic) and DSPM for AI (classic) experiences.
- Existing policies and configurations remain unchanged.
- The new DSPM experience and its features will be available in addition to existing experiences.
- No default policy changes; onboarding steps from classic experiences carry over.
What you can do to prepare:
- No action is required from admins.
- For customers already onboarded to DSPM (classic) and DSPM for AI (classic), onboarding steps will automatically carry over.
Learn more:
- Learn how Microsoft Purview Data Security Posture Management for AI provides data security and compliance protections for Copilots and other generative AI apps | Microsoft Learn (will be updated before rollout)
- Learn about Data Security Posture Management | Microsoft Learn (will be updated before rollout)
Compliance considerations:
| Compliance Area | Explanation |
|---|---|
| AI/ML capabilities interacting with customer data | Security Copilot agents automate triage and policy management. |
| Integration with 3rd party software | Adds signals from BigID, Cyera, OneTrust, and Varonis. |
| Admin reporting and monitoring | Enhanced posture reporting and remediation actions introduced. |
