Microsoft Purview applies data security and compliance controls to AI agents and their prompts, as well as to the data they read, through three layers: an agent inventory in Data Security Posture Management (DSPM), inline data loss prevention (DLP) on Microsoft 365 Copilot prompts, and Microsoft Agent 365, which treats each agent instance as an identity. Its inline prompt control, “Block sensitive information types in prompts,” is in preview, per a Microsoft Learn page updated September 17, 2026 (Microsoft Learn, 2026).
Whether an agent is governed depends on which layer applies and whether that layer blocks or only flags. Microsoft documents both per surface, and both are core AI agent governance questions on any platform.
- DSPM’s AI observability page lists AI apps and agents active in the last 30 days.
- A DLP policy can stop Copilot answering a prompt that contains sensitive information.
- Agent 365 audits an agent instance the way it audits a user.
| Field | Microsoft Learn, September 28, 2026 |
|---|---|
| Inventory | AI observability in the current DSPM (Microsoft Learn) |
| Prompt block | Preview; Copilot returns no response (Microsoft Learn) |
| Agent identity | Agent 365 instances audited like users (Microsoft Learn) |
| Scope limit | Uploaded files aren’t scanned by prompt DLP (Microsoft Learn) |
| Non-Microsoft agents | ChatGPT Enterprise and Claude (Enterprise) agents marked ✕ (Microsoft Learn) |
What is Microsoft Purview’s DSPM for AI, and how does it apply to AI agents?
Purview’s classic DSPM for AI has been replaced by a broader, current DSPM built around AI apps and agents. According to Microsoft’s DSPM for AI considerations page (Microsoft Learn, 2026), the classic tool is “now replaced with a new version that incorporates support for AI apps and agents.”
The agent-specific piece is a page called AI observability. Microsoft’s DSPM overview (Microsoft Learn, 2026) describes it as “an inventory of all AI apps and agents (including recently released Microsoft Agent 365) with activity in the last 30 days, how many are high risk and the total with sensitive interactions.” Per Microsoft’s Agent 365 guidance (Microsoft Learn, 2026), Agent 365 visibility sits on the AI observability page of the current DSPM only, so the version you open matters.
The inventory tracks interactions; cataloging data assets is a separate product, Microsoft Purview Unified Catalog. An inventory answers the same question as an AI agent registry – which agents exist – distinct from the runtime monitoring in context observability vs data observability vs LLM observability. Confirming every agent appears there is a sensible first step in an AI readiness assessment.
How does Purview’s inline DLP block sensitive information in a Copilot prompt?
Microsoft names its inline prompt control “Block sensitive information types in prompts,” a DLP feature currently in preview. According to Microsoft’s DLP for Microsoft 365 Copilot page (Microsoft Learn, 2026), it “is rolling out to all tenants with access to Microsoft 365 Copilot and Copilot Chat,” including Copilot in Word, Excel, and PowerPoint.
It stops the response rather than redacting it. When typed prompt text matches a configured sensitive information type (SIT), such as a credit card number, “Copilot doesn’t respond to the prompt,” and the prompt isn’t used for internal or web searches.
The same policy location carries three related actions:
- A web search block, with no preview label, drops external search as a grounding source while “Copilot continues to generate responses using permitted internal Microsoft 365 data sources.”
- Labeled files and emails can be excluded from responses, though they may still appear as citations.
- An external email block, in preview, keeps outside mail out of grounding, which Microsoft says “helps organizations reduce the risk of prompt injection and untrusted data influence.”
SITs are the detection mechanism teams use to handle PII and sensitive data in AI pipelines, usually following an organization’s data governance taxonomy. A prompt block is only as precise as that list, so who owns it is a governance decision.
Which parts of an AI agent’s prompt does Purview’s inline DLP inspect?
Typed prompt text is in scope for Purview’s prompt DLP; attached files are not. Microsoft’s DLP for Copilot page (Microsoft Learn, 2026) says “DLP can’t scan the contents of files that you upload directly into prompts, so evaluation of the uploaded file for sensitive data doesn’t occur. DLP only checks the text you type into the prompt itself.”
In practice, a card number typed into the prompt triggers the block, while the same number inside an attached spreadsheet falls outside this control’s scope.
Two more scope notes:
- The external email check reads sender metadata only; “The body of the email isn’t inspected.”
- During preview, Copilot in Word, Excel, and PowerPoint might not clearly tell users a prompt was blocked, though it still won’t respond.
The email control addresses one route for prompt injection attacks on AI agents; Microsoft pairs it with labels and detection policies, consistent with layered AI security.
Which agent inputs arrive as files decides how much traffic this control reads.
How is Purview’s DLP-block layer different from its detect-only layer?
Purview governs AI prompts through two kinds of control: DLP policies that stop an action, and Insider Risk Management and Communication Compliance policies that detect and flag.
| Aspect | DLP block layer | Detect-only layer |
|---|---|---|
| Acts on | Prompt text, labeled items, external email metadata | Prompts and responses |
| Action | Copilot doesn’t respond, or content leaves grounding | Flags activity, raises user risk |
| Status | Prompt block in preview | Default policies, no preview label |
| Scope | Microsoft 365 Copilot and Copilot in Office apps | Copilot, agents, other generative AI apps |
According to Microsoft’s DSPM for AI considerations (Microsoft Learn, 2026), the Insider Risk policy “DSPM for AI - Detect risky AI usage” helps “calculate user risk by detecting risky prompts and responses in Microsoft 365 Copilot, agents, and other generative AI apps.” The Communication Compliance policy “DSPM for AI - Unethical behavior in AI apps” “detects sensitive information in prompts and responses” across the same scope.
Prompt coverage is fullest in the detect layer, which reads responses too. Blocking also reaches past Copilot: DSPM for AI’s one-click defaults include a DLP policy blocking prompts with common SITs from reaching AI apps in Microsoft Edge.
The split echoes data governance vs AI governance: one decides what data may be used, the other what an AI system does with it. An enterprise AI agent guardrails checklist or AI risk management register logs a flagged risk and a prevented one separately.
How does Microsoft Agent 365 govern an AI agent as an identity, not just a data source?
Microsoft Agent 365 gives each agent instance an identity that Purview policies target like a person’s. Microsoft’s Purview guidance for Agent 365 (Microsoft Learn, 2026) says new instances are automatically enabled for audit and data classification; for other capabilities, you “include the agent instance in policies as you would a user,” the principle behind AI agent access control.
Audit reaches past human-facing traffic, covering “All agent-to-human, human-to-agent, agent-to-tools, and agent-to-agent interactions.” Logging an agent under its own identity is also a check in the AI-ready data checklist and the idea behind AI agent identity.
DLP scope is narrower. Policies can “Block or audit agent-to-human and human-to-agent for Microsoft Teams, OneDrive or SharePoint, and emails,” and “Because an agent instance is unaware of the block action, the agent owner must actively monitor a DLP policy that uses this configuration.”
Two label details:
- Files must be explicitly shared with an instance, and label encryption must grant it VIEW and EXTRACT rights, a pattern familiar from role-based access control.
- “Newly created content from Agent 365 doesn’t inherit sensitivity labels from the source items.” Copilot in Word, PowerPoint, and Outlook does inherit them, per Microsoft’s Copilot guidance (Microsoft Learn, 2026).
The “Risky AI usage” template, detecting “prompt injection attacks and accessing protected materials,” also appears in Microsoft’s Copilot Studio guidance (Microsoft Learn, 2026). Identity records who acted, which matters when you secure multi-agent systems in the enterprise; naming an owner per agent is still your call.
Which AI agent surfaces does Purview cover today?
Purview sorts AI apps into three categories, per Microsoft Purview’s generative AI overview (Microsoft Learn, 2026): Copilot experiences and agents, Microsoft’s own enterprise copilot products; Enterprise AI apps, such as Microsoft Foundry, Entra-registered apps, Anthropic Claude (Enterprise), and ChatGPT Enterprise; and Other AI apps, detected through browser activity.
Per the same overview, agents “inherit the same security and compliance capabilities as their parent AI app,” and Microsoft’s AI agents page (Microsoft Learn, 2026) summarizes agent-level support:
| Agents from | Information protection | Compliance management | Notes |
|---|---|---|---|
| Microsoft 365 Copilot | ✓ | ✓ | Full support |
| Copilot Studio, Microsoft Foundry | ✓ | ✓ | Protection: classification, labels, DLP, Insider Risk |
| Channel Agent in Teams | ✓ | ✓ | Protection: classification, labels, DLP |
| Security Copilot, Copilot in Fabric, Facilitator | ✓ | ✓ | Protection via classification |
| Entra-registered | ✓ | ✓ | Needs developer integration |
| ChatGPT Enterprise | ✕ | ✕ | Classification and Insider Risk supported |
| Anthropic Claude (Enterprise) | ✕ | ✕ | None listed |
Every listed agent is supported by DSPM, and pay-as-you-go billing may apply. Copilot Studio agents and Azure AI Foundry agents sit among the fullest rows.
For Other AI apps, endpoint DLP on onboarded Windows devices can warn or block pastes of sensitive information into generative AI sites. Where an agent was built decides its row: read coverage per agent, not per platform.
Does Purview’s agent coverage extend to agents outside the native Microsoft stack?
Yes, conditionally, depending on how each agent connects to Purview.
For DLP on Entra-registered custom apps, Microsoft’s Entra-registered app guidance (Microsoft Learn, 2026) states: “Support today is only available for a DLP policy that blocks prompts based on sensitive information types. This requires the configuration of a PowerShell cmdlet that’s scoped to a specific Entra-registered AI app.”
The app honors it through the Purview APIs (Microsoft links a GitHub sample); Insider Risk, Communication Compliance, eDiscovery, and retention are also supported, with a collection policy for prompts and responses. An agent built on Microsoft Agent Framework or another SDK qualifies once registered and integrated.
The two non-Microsoft enterprise apps use connectors:
- ChatGPT Enterprise (Microsoft Learn, 2026) needs a connector scan and pay-as-you-go billing; auditing, classification, Insider Risk, eDiscovery, and retention are supported; labels and DLP are not.
- For Anthropic Claude (Enterprise) (Microsoft Learn, 2026), the connector is in preview with the same parent-app support pattern, and “agents for Anthropic Claude aren’t currently supported.”
That is a dated integration status, not a verdict on any vendor; verify it in your own tenant.
| Question to ask | What Microsoft’s docs answer today |
|---|---|
| Does the control block, or only detect? | Copilot prompt DLP blocks; Insider Risk and Communication Compliance detect |
| Does coverage need developer work? | Yes for Entra-registered agents |
| Does prompt DLP scan uploaded files? | No, only typed text |
| Does agent-created content inherit labels? | Not for Agent 365; yes for Copilot in Word, PowerPoint, Outlook |
| Is agent-to-agent traffic covered? | Audited for Agent 365; DLP covers human-facing directions only |
Check each row against every agent builder in your stack.
Purview’s agent controls are three layers at different stages of release
Purview’s agent controls are three layers at different maturity levels: an inventory in the current DSPM, a preview Copilot prompt block that stops a response outright, and an Agent 365 identity model auditing agent-to-agent traffic like a person’s. Coverage outside Microsoft’s own products exists, conditional on connectors, billing, or developer work.
The same questions fit any written AI governance framework: inline or detect-only, automatic or configured, human-facing or agent-to-agent. Controls on the agent sit alongside readiness work on the data it reads, in what makes data AI-ready.
Fabric IQ raises a parallel set, covered in Fabric AI agent governance questions; the governance and security sessions at FabCon Europe 2026 are in FabCon Europe 2026 sessions by role.
FAQs about Purview’s controls for AI agents
1. What is Microsoft Purview’s DSPM for AI?
Purview’s dashboard for discovering and securing AI usage. The classic version was replaced by a current DSPM covering AI apps and agents directly, including an AI observability page inventorying agents active in the last 30 days.
2. Is Purview’s inline DLP for Copilot prompts generally available, or still in preview?
Still in preview. Microsoft Learn describes “Block sensitive information types in prompts” as a preview feature rolling out to tenants with Microsoft 365 Copilot, on a page updated September 17, 2026. Rollout varies, so check your own tenant.
3. Can Purview DLP scan a file I upload into a Copilot prompt?
No. Microsoft states DLP can’t scan files uploaded directly into prompts and checks only typed prompt text. Sensitive data pasted as text can trigger the block; the same data inside an attached file isn’t evaluated.
4. Does Purview’s inline DLP block a Copilot response entirely, or just part of it?
Entirely. When prompt text matches a configured sensitive information type, Copilot doesn’t respond, and the prompt isn’t used for internal or web searches. A separate action can instead block only external web search while Copilot answers from internal Microsoft 365 sources.
5. What is Microsoft Agent 365, and how does Purview treat its agents?
Purview treats each Agent 365 agent instance as an identity. New instances are automatically enabled for audit and data classification, and you add them to other policies like a user. Audit covers agent-to-agent and agent-to-tools interactions, not just human-facing ones.
6. Are ChatGPT Enterprise and Anthropic Claude Enterprise agents covered by Purview?
At the agent level, Microsoft’s capability table marks both ✕ for information protection and compliance management, though it notes data classification and Insider Risk support for ChatGPT Enterprise agents. Parent apps have separate, connector-based coverage; check Microsoft Learn for current status.
7. What’s the difference between Purview’s DLP-block layer and its detect-only layer?
DLP policies stop an action, such as Copilot answering a sensitive prompt. Insider Risk and Communication Compliance policies detect and flag sensitive content without blocking. The detect layer reads responses as well as prompts; the Copilot prompt block reads prompts only.
8. What do I need to configure for Purview to cover an Entra-registered custom AI agent?
For DLP: a PowerShell cmdlet scoped to that Entra-registered app, plus developer integration with the Purview APIs. Insider Risk, Communication Compliance, eDiscovery, and retention need a collection policy, with pay-as-you-go billing; Microsoft publishes a GitHub sample.
Sources
- DLP for Microsoft 365 Copilot and Copilot Chat, Microsoft Learn
- Considerations for deploying DSPM for AI, Microsoft Learn
- Learn about Data Security Posture Management, Microsoft Learn
- Purview protections for generative AI apps, Microsoft Learn
- Purview for AI agents, Microsoft Learn
- Purview for Microsoft Agent 365, Microsoft Learn
- Purview for Microsoft 365 Copilot, Microsoft Learn
- Purview for Microsoft Copilot Studio, Microsoft Learn
- Purview for Entra-registered AI apps, Microsoft Learn
- Purview for ChatGPT Enterprise, Microsoft Learn
- Purview for Anthropic Claude (Enterprise), Microsoft Learn