Skip to main content
Cloud / Azure / Products / Microsoft Purview DSPM - Data Security Posture Management

Microsoft Purview DSPM - Data Security Posture Management

Microsoft Purview Data Security Posture Management provides visibility into sensitive data, assesses risk and offers remediation workflows, including for AI apps.

security
Pricing Model Licensed through Microsoft 365; see the Microsoft Purview service description for details
Availability Accessed through the Microsoft Purview portal; some setup tasks are marked preview
Data Sovereignty Coverage spans Microsoft 365, Azure, Fabric and integrated third-party platforms
Reliability SLA per vendor / see the official SLA page SLA

What is Microsoft Purview DSPM?

Microsoft Purview Data Security Posture Management helps organizations discover, protect and investigate sensitive data risks across their digital estate. It provides unified visibility and control for both traditional applications and AI apps and agents, supporting data governance across Microsoft 365, Azure, Fabric and integrated third-party SaaS platforms.

Instead of focusing on infrastructure or endpoints, DSPM centers on the data itself: where it resides, who can access it, how it’s used and whether it’s adequately protected. This matters increasingly because data is constantly moving in AI-driven workplaces. DSPM is part of Microsoft Purview; for an overview of the whole platform, see our page on Microsoft Purview.

Core Features

Continuous scanning and assessment: DSPM continuously scans your environment to identify sensitive data, assess risk and recommend actions to reduce exposure.

Consolidated insights: Insights from data loss prevention, Insider Risk Management, information protection with sensitivity labels and Data Security Investigations converge in a single view.

Data security objectives: Selectable goals such as preventing data exposure in Copilot interactions, preventing oversharing of sensitive data or preventing exfiltration to risky locations guide end-to-end workflows with prioritized actions and one-click policies.

AI observability: An inventory of all AI apps and agents with activity in the last 30 days shows how many are high risk and how many have sensitive interactions, with a breakdown of individual agents and the policies that govern them.

Automated remediation with approval: Actions such as removing public sharing links or applying DLP policies can be automated; you review and approve them, and they are fully audited.

Typical Use Cases

Preventing oversharing: Data risk assessments identify and fix potential oversharing risks using default or custom assessments.

Detecting exfiltration: The risky destinations objective supports proactive AI insights through Data Security Investigations, which continuously analyze recently exfiltrated sensitive data across five risk categories.

Securing AI usage: The activity explorer AI activities tab shows when users browsed to a generative AI site, whether prompts and responses contained sensitive information, and when a DLP rule was matched.

Compliance reporting: Reports help track sensitive data usage, labeling, policy usage and risky behavior of users and AI agents.

Benefits

  • A unified view of data risks instead of multiple solutions and manual audits
  • Coverage of traditional applications and AI apps and agents in one solution
  • Guided workflows with prioritized actions instead of plain finding lists
  • Extended coverage of third-party SaaS and IaaS through partner integrations
  • Audited, approval-based automation of remediation actions

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you in establishing data security posture management: setting up and prioritizing data security objectives, building data risk assessments, securing AI applications and agents, and integrating with existing security and compliance processes.

Contact us for a no-obligation consultation on data security with Microsoft Purview.

Typical Use Cases

Visibility into sensitive data across Microsoft 365, Azure, Fabric and third-party SaaS
Risk assessment and remediation for oversharing and exfiltration
Monitoring AI apps and agents through AI observability
Data risk assessments to prevent oversharing
Traceable incident investigation through audit logs and activity explorer

Technical Specifications

0th Current version with expanded source coverage; the previous versions are now named Data Security Posture Management (classic) and DSPM for AI (classic)
1st Consolidates insights from data loss prevention, Insider Risk Management, information protection with sensitivity labels, and Data Security Investigations
2nd Extends coverage to third-party SaaS and IaaS such as Google Cloud Platform, Snowflake and Databricks, and integrates with partner solutions such as Varonis, Cyera, BigID and OneTrust
3rd Data security objectives as guided workflows, for example prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions, prevent oversharing of sensitive data, prevent exfiltration to risky locations and discover sensitive data in your organization
4th AI observability as an inventory of all AI apps and agents with activity in the last 30 days, including Microsoft Agent 365
5th Asset explorer with an Agent tab for the Data Security Posture Agent and a Standard tab for unlabeled or unclassified data by workload
6th Discover areas: apps and agents, activity explorer with an AI activities tab, and data risk assessments
7th Automated remediation such as removing public sharing links or applying DLP policies, with your review and approval and full auditing
8th Uses Microsoft Security Copilot and AI agents; triage agents filter alerts from DLP and Insider Risk Management
9th Permissions: for example membership in the Entra Compliance Administrator role or the Microsoft Purview Compliance Administrator role group; Security Copilot additionally requires the Data Security Viewer role
10th Setup tasks include, in preview, setting up a Microsoft Sentinel data lake to integrate partner solutions for non-Microsoft data sources

Frequently Asked Questions

What is Microsoft Purview DSPM?

Data Security Posture Management helps organizations discover, protect and investigate sensitive data risks across their digital estate. It provides unified visibility and control for both traditional applications and AI apps and agents, supporting data governance across Microsoft 365, Azure, Fabric and integrated third-party SaaS platforms. DSPM is part of Microsoft Purview; for an overview of the whole platform see our page on [Microsoft Purview](/en/cloud/azure/products/purview/).

How does DSPM differ from the classic versions?

The current documentation covers the version that expands coverage to more data sources, introduces guided workflows for proactive risk management and streamlines data security operations. The previous versions are now named Data Security Posture Management (classic) and DSPM for AI (classic). According to Microsoft, most new features are added only to the current version.

Which questions does DSPM answer?

Microsoft names four practical questions: What data do we have? Where is it stored? Who can access it? How is it protected? Once these are addressed, DSPM can automate remediation steps such as removing public sharing links or applying data loss prevention policies.

What are data security objectives?

Data security objectives are selectable cards for specific security goals. Each guides you through an end-to-end workflow by grouping the relevant Purview solutions such as information protection, DLP, Insider Risk Management and eDiscovery. Each outcome card displays key metrics such as the percentage of data covered by policies or the number of risky sharing incidents.

What role does AI play in DSPM?

DSPM not only secures and governs AI apps and agents but also uses Microsoft Security Copilot and AI agents itself. AI analyzes access patterns, sharing behaviors and policy gaps and prioritizes incidents. Under your guidance, AI agents can take direct action such as removing public sharing links, applying DLP policies or revoking permissions. You review and approve these actions, and they are always audited.

Which permissions are required?

Getting started requires an account with appropriate permissions for security and compliance management, such as membership in the Entra Compliance Administrator role or the Microsoft Purview Compliance Administrator role group. Some activities need additional permissions, such as the Data Security Viewer role to use Security Copilot.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Microsoft Purview DSPM - Data Security Posture Management?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation