Microsoft Purview
Unified data governance and compliance platform covering data classification, sensitivity labeling, data loss prevention, and information protection across Microsoft 365, Azure, and third-party sources.
Capabilities
- AI and Agent Activity AuditObserve Agents Users Data
Captures audit logs of AI and agent activity in Microsoft Purview — user interactions plus agent authoring and configuration changes — so security teams can investigate what agents did and how they were changed. Reduces the risk of missing audit and undetected tampering.
- Communication Compliance for AI InteractionsGovernObserve Users Data
Detects inappropriate, risky, or policy-violating content in AI prompts and responses — including Microsoft 365 Copilot, connected AI apps, and browser-accessed third-party AI tools — using built-in classifiers and custom policies.
- eDiscovery for AI InteractionsGovern Users Agents Data
Lets legal and compliance teams search, place holds on, review, and export the prompts and responses of Microsoft 365 Copilot, agents, and other AI apps in Microsoft Purview eDiscovery — treating a user mailbox or an agent instance as the custodian. Reduces the risk of being unable to preserve or investigate AI interaction data for legal and compliance cases.
- Enterprise AI App ConnectorsObserveGovern Users Data
Connects sanctioned non-Microsoft enterprise AI apps — ChatGPT Enterprise and Anthropic Claude (connector in preview) — to Microsoft Purview so their prompts and responses surface in Data Security Posture Management for AI with auditing, and, for ChatGPT Enterprise, insider risk, communication compliance, eDiscovery, and retention. Brings enterprise AI outside Microsoft under monitoring and compliance, though sensitivity-label, encryption, and DLP enforcement are not supported for these connected apps.
- Entra-registered AI App GovernanceGovernSecure Data
Registers custom, in-house AI apps in Microsoft Entra and integrates them with the Microsoft Purview SDK so their prompts and responses inherit the full Purview control plane — data classification, sensitivity labels, encryption, data loss prevention, insider risk, communication compliance, eDiscovery, retention, and Compliance Manager. Gives apps you build the same data governance as Microsoft Copilot rather than leaving them outside compliance.
- Sensitive Information Types and ClassifiersObserveSecure Data Users
Identifies sensitive data with pattern-based sensitive information types (SITs) and machine-learning trainable classifiers. In AI scenarios these classifiers find sensitive content in user prompts and responses and provide the detection basis that labels, DLP, DSPM reports, and investigation all build on.
Scenarios
- Classify and Label Data Feeding AI
- Detect and Respond to Risky AI Data Activity
- Discover Sensitive Data and AI Risk
- Govern Agent Lifecycle
- Govern AI Data Lifecycle and Retention
- Govern Sanctioned Enterprise AI
- Harden Copilot Studio Agents
- Investigate and Respond to Agent Incidents
- Observe the Agent Estate
- Stream Agent Activity to Security Operations