Microsoft Purview Data Security Posture Management
Microsoft
Formerly Microsoft Purview Data Security Posture Management for AI, DSPM for AI
Purview posture tool that discovers AI apps and agents, flags oversharing and risky prompts, and applies DLP to AI use.
Curated by Tiberiu ArvaVerified
Strengths
- AI observability for Copilot and agents
- Oversharing risk assessments for SharePoint
- One-click DLP policies for AI prompts
Practitioner note
Strongest where Microsoft 365 Copilot, Copilot Studio and Foundry agents dominate; third-party AI sites need the Purview browser extension and device onboarding. Full capability requires Microsoft 365 E5 or Purview Suite licensing, and some options use pay-as-you-go billing.
Warning
Governance posture
Reviewed 2026-09-30Follows Microsoft 365 data location commitments (customer data kept in chosen geography); no customer-hosted option.
SourceMicrosoft-managed SaaS within the Microsoft Purview portal. (saas)
SourceAI prompts/responses and agent interactions captured in the Purview unified audit log and activity explorer.
SourceOffice 365 SOC 2 Type 2 covers Compliance Manager (commercial) and the Purview portal in GCC/GCC High/DoD; DSPM not named separately.
SourceMicrosoft Purview portal is listed in the Office 365 ISO 27001 in-scope services (commercial and government).
SourceMicrosoft's ISO 42001 in-scope list covers Copilot, Copilot Studio, Foundry and Security Copilot, not Purview.
SourceData security/compliance tooling, not itself a high-risk AI system; its Compliance Manager templates help map AI regulations. (role: not-applicable)
Proprietary Microsoft SaaS tied to Microsoft 365 E5/Purview Suite licensing; no OSS path. (medium)
SourceEU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from Microsoft Purview Data Security Posture Management's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.