Microsoft Purview Data Security Posture Management

Microsoft

Formerly Microsoft Purview Data Security Posture Management for AI, DSPM for AI

Vendor

Purview posture tool that discovers AI apps and agents, flags oversharing and risky prompts, and applies DLP to AI use.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • AI observability for Copilot and agents
  • Oversharing risk assessments for SharePoint
  • One-click DLP policies for AI prompts

Practitioner note

Strongest where Microsoft 365 Copilot, Copilot Studio and Foundry agents dominate; third-party AI sites need the Purview browser extension and device onboarding. Full capability requires Microsoft 365 E5 or Purview Suite licensing, and some options use pay-as-you-go billing.

Warning

Microsoft Purview Data Security Posture Management: The standalone DSPM for AI experience is now labelled "classic" and replaced by the unified DSPM, which receives new features (Microsoft Learn, checked 2026-09-30).

Governance posture

Reviewed 2026-09-30
PartialData residency

Follows Microsoft 365 data location commitments (customer data kept in chosen geography); no customer-hosted option.

Source
YesDeployment model

Microsoft-managed SaaS within the Microsoft Purview portal. (saas)

Source
YesAudit logging

AI prompts/responses and agent interactions captured in the Purview unified audit log and activity explorer.

Source
PartialSOC 2

Office 365 SOC 2 Type 2 covers Compliance Manager (commercial) and the Purview portal in GCC/GCC High/DoD; DSPM not named separately.

Source
YesISO 27001

Microsoft Purview portal is listed in the Office 365 ISO 27001 in-scope services (commercial and government).

Source
NoISO 42001

Microsoft's ISO 42001 in-scope list covers Copilot, Copilot Studio, Foundry and Security Copilot, not Purview.

Source
N/AEU AI Act

Data security/compliance tooling, not itself a high-risk AI system; its Compliance Manager templates help map AI regulations. (role: not-applicable)

YesLicense risk

Proprietary Microsoft SaaS tied to Microsoft 365 E5/Purview Suite licensing; no OSS path. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Microsoft Purview Data Security Posture Management's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.