Microsoft Purview

Category: tool (data governance, data security & compliance platform — Microsoft) Maturity: adopted — widely deployed across Microsoft 365 / Azure estates First seen: 2026-06-22 Last updated: 2026-09-18

Created 2026-06-22 from S-2026-06-16-microsoft-purview-whats-new (daily vendor-intelligence scan). Capability/availability claims are Microsoft’s own changelog statements; FS suitability not independently verified. Updated 2026-07-06 based on S-2026-07-06-purview-whats-new-recheck — changelog unchanged since 16 June (June wave reinforced, not new); added June DLP/eDiscovery items not previously excerpted and a third-party-reported July “DLP Policy Optimizer” roadmap item. Updated 2026-07-08 based on S-2026-07-01-m365-july-roadmap-purview — July 2026 roadmap wave (Triage Agent remediation via Teams, endpoint DLP archive/FTP-SFTP coverage, DLP alert aggregation, eDiscovery diagnostics, cert-based RMS auth). All items roadmap-stated, not yet on Microsoft’s changelog. Updated 2026-07-13 based on S-2026-06-30-purview-whats-new-july-wave — Microsoft’s changelog now carries a July 2026 section: Purview Network Data Security (DLP × Entra Global Secure Access, preview) and three Insider Risk Management previews (unified alert experience, Entra-sourced user profile details, expanded notes). The roadmap-reported Triage Agent / cleanup / archive-DLP items still do not appear on the changelog. See Tensions for a dating discrepancy with the 07-06 recheck. Updated 2026-07-31 based on S-2026-07-30-microsoft-security-july-roundup — Microsoft’s 30 July monthly roundup publicly announces the Entra Internet Access network-layer integration (same capability family as the changelog’s Network Data Security preview [inference]), re-announces the DLP-for-Copilot external-email exclusion as preview, and confirms the centralized IRM alert experience with the Data Security Triage Agent’s “advanced AI reasoning layer” now GA — partially reconciling the “what ships in July” tension below. Updated 2026-08-06 based on S-2026-08-03-changepilot-m365-august-roundup — August 2026 roadmap/Message Center wave (third-party relay): roadmap 568075 extends Purview DLP to non-Microsoft SaaS apps connected to M365 (rolling out September 2026), and MC1417993 retires Defender for Cloud Apps File Policies on 6 January 2027 with Purview as Microsoft’s designated replacement — consolidating file-governance controls into Purview. Updated 2026-08-07 based on S-2026-07-28-windowsforum-purview-dlp-slaroadmap 568372 adds an out-of-box SLA-based DLP alert reporting dashboard (MTTA/MTTD/MTTR, severity-specific SLA targets, trend history, top exposed sensitive-information types); Preview targeted August 2026, GA targeted September 2026. Roadmap-stated intent relayed by a low-authority source; dates are Microsoft estimates. Updated 2026-08-10 based on S-2026-08-07-m365admin-purview-crosssaas-dlp — Message Center MC1449180 (7 Aug) fills out roadmap 568075: Preview mid-Aug 2026 → GA early Sept–late Oct 2026; named app locations (Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, Cisco Webex; auto-labeling: Google Workspace, Box); PAYG billing (1,000 files = 1 data asset); and a mandatory Defender for Cloud Apps file-policy switch-off for overlapping locations. Refines (does not contradict) the earlier ChangePilot relay’s compressed “September 2026” dating. Updated 2026-08-10 based on S-2026-07-28-windowsnews-purview-dlp-autoresolutionroadmap 568371 adds deterministic, rule-based DLP alert auto-resolution and custom tagging (Preview Aug 2026, GA Sept 2026, Purview on the web, multi-tenant). Low-authority relay with an internal dating inconsistency, flagged on the Source page; audit representation/retention of auto-resolved alerts not yet published by Microsoft. Updated 2026-08-17 based on S-2026-08-14-redmond-purview-external-dlpfirst independent commentary on the cross-SaaS DLP expansion (roadmap 568075 / MC1449180): Tony Redmond (Microsoft 365 for IT Pros, 14 Aug) confirms the MC schedule and app list and adds cost/deployment mechanics — connector setup needs the external platform’s top-level admin (e.g. Google Workspace Super admin); “available policy conditions and actions vary by application” (quarantine may be impossible off-SharePoint); licensing detail unpublished, with Redmond’s own reading being E5 Compliance / E5 IP&G class, plus the At Rest Protection meter at $0.50 per data asset (1,000 files) per month; his assessment is that this is an “esoteric”, enterprise-niche play. Also introduces a minor MC dating discrepancy (6 vs 7 Aug) — see Tensions. Updated 2026-08-28 based on S-2026-08-02-topedia-purview-role-expirationfirst coverage of Purview role-assignment governance, a distinct capability stream from the DLP/DSPM/eDiscovery items above: time-limited role group assignments (expiry from one day to two years, automatic revocation, all role groups except eDiscovery Administrator/Manager, existing assignments unaffected until an admin acts, no pre-expiry user notification) plus a new View-only Role Management role. Rollout dating conflicts between sources — see Tensions. Updated 2026-09-08 based on S-2026-09-04-hoitingh-purview-september — independent practitioner monthly roundup (4 Sep) consolidating Microsoft’s May–Aug 2026 sources. New items folded in below: auto-labeling capacity rises 100k→500k files/day (Microsoft Security Blog, 27 Aug); simulation-mode Insights tab for DLP/auto-labeling policies (Aug); Exchange Online DLP classification-failure detection via a DocumentScanFailures condition (preview, Jul); priority-cleanup permanent deletion now requires three separate approvers (Jul); Fabric OneLake catalog DLP governance views and withdrawal of Azure SQL Database from protection-policy scope (Jul); layered endpoint/browser/network protection guidance (Purview blog, 31 Aug); and AWS Bedrock cross-cloud protection guidance (5 Jun, context). Reinforces (does not change) existing coverage of cross-SaaS DLP/auto-labeling previews, network-layer DLP, role-assignment expiry and the Claude Enterprise connector. Updated 2026-09-16 based on S-2026-09-14-sharepointstuff-m365-roadmap-purview — weekly roadmap digest (14 Sep) adds a Data Lifecycle Management wave: an audited, multi-approver Priority cleanup workflow to bypass legal holds/retention on Exchange (roadmap 392838, Oct 2026); DLP for Microsoft Cowork with one policy across Copilot and Cowork (570845, Oct 2026); Endpoint DLP over Copilot+ PC Recall snapshots (560396, rolling out); Planner retention (486828, launched); a DLM billing-meter change for retained non-M365 GenAI prompts (560324, Dec 2026); last-accessed retention (Jan–Feb 2027); Security Copilot DLP policy insights (472031, Sep 2027). Also re-dates network-layer DLP GA to Sep 2026 (“GA release … has moved”) and departed-user deletion to Nov 2026 — two dating tensions recorded below. All roadmap-stated; Microsoft pages not fetched. Updated 2026-08-14 based on S-2026-07-03-m365admin-purview-dlm-copilot-insights — Message Center MC1413308 / roadmap 561209 (notice dated 3 Jul, captured now because GA is current): Data Lifecycle Management gains AI-driven insights into Copilot and AI app interactions, with retention-policy recommendations surfaced in DSPM; Public Preview late Jul–mid Aug 2026, GA worldwide beginning mid-August 2026 (complete late Aug). Opt-in preview at tenant level; no existing retention policies changed without admin action. Third-party mirror of the Microsoft notice; dates are Microsoft estimates. Updated 2026-09-18 based on S-2026-09-18-weekly-vendor-synthesis (weekly vendor-synthesis): cross-week DG/DM read — the 14 Sep Data Lifecycle Management wave (Priority cleanup, DLP for Cowork, Recall endpoint DLP, DLM billing-meter change) is the week’s dominant retention/legal-hold/DLP theme across the DG/DM watchlist; the audited, multi-approver Priority cleanup design is a citable separation-of-duties control pattern for a Microsoft-estate client’s legal-hold governance, but it sits alongside two re-dated items in the same digest (network DLP GA moved again; departed-user deletion Jul→Nov) that argue for treating the whole wave as roadmap intent, not an operating control, until Microsoft’s own changelog confirms GA. No new contradiction with existing coverage.

What it is

Microsoft Purview is Microsoft’s unified platform for data governance (Unified Catalog, data quality, lineage), data security (DLP, sensitivity labels, Data Security Posture Management) and risk & compliance (eDiscovery, Insider Risk, audit) across the Microsoft 365 / Azure estate plus named external connectors [S-2026-06-16-microsoft-purview-whats-new]. For EU/UK regulated firms it is the in-estate control plane through which Microsoft-centric BCBS 239 data-quality, GDPR classification and EU AI Act / agent-use oversight can be operationalised — but its AI-governance reach is largely confined to the Microsoft ecosystem [inference from capability scope — S-2026-06-16-microsoft-purview-whats-new].

How it’s used

  • Governing employee/agent AI use: June 2026 GA of data security & compliance protections for Microsoft 365 Copilot Cowork; May 2026 GA of protections for Microsoft Agent 365; a DSPM preview connector surfaces Anthropic Claude (Enterprise) interactions alongside Copilot and ChatGPT Enterprise in activity explorer [S-2026-06-16-microsoft-purview-whats-new].
  • Prompt-injection mitigation: a June 2026 DLP preview lets policies stop Copilot using untrusted external email as grounding data [S-2026-06-16-microsoft-purview-whats-new].
  • Data quality / catalogue: May 2026 GA of standalone-asset and incremental data-quality scans and configurable DQ thresholds in Unified Catalog [S-2026-06-16-microsoft-purview-whats-new].
  • Device-conditional DLP: June 2026 adds Endpoint DLP device scoping via Entra ID dynamic device groups (e.g. enforce only on Windows devices for a given user group) and DLP device attributes queryable at scale via Advanced Hunting [S-2026-07-06-purview-whats-new-recheck].
  • Network-layer AI-interaction DLP (July 2026, preview): Purview Network Data Security integrates DLP with Microsoft Entra Global Secure Access to intercept and inspect text and AI interactions at the network layer, enforce DLP restrictive actions, and feed risky-activity detection into Insider Risk Management — targeting sensitive-data leakage to untrusted cloud apps including GenAI platforms, via browsers, apps, APIs and add-ins [S-2026-06-30-purview-whats-new-july-wave]. The roadmap entry for the file-filtering form of this integration (522096) records on 17 July that “the GA release of this item has moved” and, as of the 14 Sep digest, targets September 2026 [S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • DLP for Microsoft Cowork (roadmap 570845, in development, Oct 2026): Purview DLP extends to Microsoft Cowork so admins can run “a single policy across Microsoft 365 Copilot and Cowork” — preventing use of labelled knowledge sources, blocking prompts containing supported sensitive information types, and restricting sensitive prompts from being sent to Bing web search [S-2026-09-14-sharepointstuff-m365-roadmap-purview]. How this relates to the June 2026 GA “data security and compliance protections for Microsoft 365 Copilot Cowork” recorded above [S-2026-06-16-microsoft-purview-whats-new] is not stated by either source — see Open question on the Source page [inference — S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Endpoint DLP over Copilot+ PC Recall snapshots (roadmap 560396, rolling out): custom Endpoint DLP policies can prevent Recall from capturing windows containing restricted sensitivity labels or sensitive information types, integrated with Intune-managed Recall setup, for Copilot+ PC devices only [S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Evidence angle (inference): Recall’s on-device screenshot history is a novel sensitive-data store inside the endpoint; a labelled-content exclusion policy is the kind of control a GDPR Art. 32 / DORA ICT-risk assessment of Copilot+ PC rollouts would need to evidence — the source does not say whether blocked-capture events are logged [inference — S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Priority cleanup — audited legal-hold / retention bypass (roadmap 392838, in development, Oct 2026): described as “the first release of Priority cleanup”, enabling admins “to create a recurring exception to delete items under a broader retention policy and/or legal hold on Exchange workload”; creating one “will require a separate security role, multiple approvers, and will have a complete audit trail” [S-2026-09-14-sharepointstuff-m365-roadmap-purview]. Cf. the July 2026 three-approver requirement reported by Hoitingh below — dating/scope tension recorded in Tensions.
  • Evidence angle (inference): a hold-bypass that is role-segregated, multi-approved and fully audited is the control shape supervisors and internal audit expect around any deletion of data under legal hold (GDPR storage-limitation vs litigation/regulatory-hold obligations; FCA/PRA record-keeping); the evidential value depends on whether the “complete audit trail” is retained and exportable, which the roadmap text does not say [inference — S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Retention scope and mechanics (roadmap, various): retention policies now cover Microsoft Planner content (486828, launched); last-accessed-date retention for SharePoint/OneDrive items is planned (472030 Jan 2027; 565866 Feb 2027); DLM insights and retention-policy recommendations on sensitive OneDrive/SharePoint data are planned (562343, Dec 2026) [S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • DLM billing-meter change (roadmap 560324, Dec 2026): DLM billing moves to retained data volume — non-M365 generative-AI prompts and responses billed at $0.25/GB/month (“equivalent to $6 per one million text messages per month”), each prompt/response treated as a text message retained and deleted per configured retention settings; customers must migrate meters, and Microsoft’s “current analysis” expects a cost-neutral-or-lower impact [S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Evidence angle (inference): volume-based billing for retained AI interaction records introduces a cost incentive that bears on retention-policy design for firms keeping prompts/responses as regulatory records (EU AI Act record-keeping, FCA/PRA); not addressed by the source [inference — S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • DLP Policy Change Insights with Security Copilot (roadmap 472031, Sep 2027): admins will be able to prompt Security Copilot for summaries of DLP policy coverage (locations, classifiers, notifications) across all or selected policies [S-2026-09-14-sharepointstuff-m365-roadmap-purview].
  • Insider-risk triage (July 2026, previews): a unified alert experience merges Triage Agent and Standard alert dashboards into one alerts list with agent-summary preview; user profiles gain Entra signals (office location, employee type, department, last working date); notes are extended across alerts and cases with system-generated audit notes on status/assignment/closure changes [S-2026-06-30-purview-whats-new-july-wave].
  • Evidence angle (inference): network-layer interception of AI prompts plus system-generated case notes would strengthen a Microsoft-estate firm’s GDPR Art. 32 / DORA ICT-risk-monitoring evidence trail — but Microsoft makes no conformity claim and log retention/exportability is not described [inference — S-2026-06-30-purview-whats-new-july-wave].
  • Announced network-layer + IRM triage wave (July 2026 roundup): Microsoft’s 30 July roundup announces Purview’s integration with Entra Internet Access to block sensitive text/file sharing to unmanaged cloud and “shadow AI” apps at the network layer (no explicit GA/preview label in the post; changelog previously said preview), and a centralized IRM alert experience (agentic triage, enriched user details, single alerts view) powered by the Data Security Triage Agent’s advanced AI reasoning layer, now GA, with system-recorded status changes and escalations claimed to “maintain a clear investigation history” [S-2026-07-30-microsoft-security-july-roundup]. Log retention/exportability still undescribed [inference — S-2026-07-30-microsoft-security-july-roundup].
  • Third-party-SaaS DLP coverage (roadmap 568075 / MC1449180, announced intent): Purview DLP and Information Protection auto-labeling extend to non-Microsoft apps connected via Defender for Cloud Apps connectors, with policies created and managed directly in Purview — described by the first relaying source as closing “a significant gap in data security coverage” for firms using third-party SaaS alongside M365 [S-2026-08-03-changepilot-m365-august-roundup]. MC1449180 detail: Public Preview mid-August 2026 (complete early Sept), GA early September–late October 2026; supported DLP locations Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, Cisco Webex (auto-labeling: Google Workspace, Box); conditions/actions “vary by application and may include” content inspection, labeling, notifications, quarantine and access controls; Enterprise-tier licensing with usage billed via the At Rest Protection pay-as-you-go meter (1,000 files = 1 data asset); and Defender for Cloud Apps file policies for the same locations must be turned off or deleted first, as running both “can cause unexpected policy enforcement” [S-2026-08-07-m365admin-purview-crosssaas-dlp]. Earlier view: the ChangePilot relay compressed the rollout to “September 2026” [S-2026-08-03-changepilot-m365-august-roundup] — superseded 2026-08-10 by the fuller MC schedule above. Connector-based mechanism (vs the July network-layer Entra capability) is now asserted by the MC text, no longer only inferred [S-2026-08-07-m365admin-purview-crosssaas-dlp]. Independent analysis (14 Aug) adds the deployment reality: connector configuration requires the external platform’s own top-level admin (e.g. a Google Workspace “Super admin”), actions such as move-to-quarantine may be unavailable off-SharePoint, licensing detail is unpublished (Redmond’s reading: E5 Compliance / E5 IP&G class likely required — author interpretation, not a Microsoft statement), the At Rest Protection meter currently prices a data asset (1,000 files) at $0.50/month, and the overall verdict is an “esoteric”, enterprise-niche capability — “significant work and funding is required to implement the functionality” [S-2026-08-14-redmond-purview-external-dlp].
  • Evidence angle (inference): the per-app variation in enforceable actions means a firm citing cross-SaaS Purview DLP as a GDPR Art. 32 / DORA control must evidence per connected platform which conditions and actions are actually active — the policy existing in Purview does not demonstrate equivalent enforcement across Google Workspace, Box, Salesforce et al.; per-connector testing evidence would be needed [inference — S-2026-08-14-redmond-purview-external-dlp].
  • File-governance consolidation (Message Center, announced): MC1417993 retires Defender for Cloud Apps File Policies on 6 January 2027; Microsoft directs customers to Purview as the replacement for file-activity monitoring and control used in “data governance, DLP, or compliance monitoring” workflows [S-2026-08-03-changepilot-m365-august-roundup].
  • Evidence angle (inference): Microsoft-estate FIs using Defender File Policies as documented controls face a re-platforming with evidence-continuity implications (policy mapping, re-testing, audit-trail preservation) ahead of the January 2027 cut-off — relevant to GDPR Art. 32 and DORA ICT-risk control documentation; whether migrated policies preserve audit history is not described [inference — S-2026-08-03-changepilot-m365-august-roundup].
  • DLP alert auto-resolution and tagging (roadmap 568371, announced intent): deterministic, admin-defined rules auto-close “predictable, low-risk” DLP alerts (e.g. low-severity email to trusted partner domains) and apply custom tags that can drive routing; explicitly “not driven by AI”; detection and event logging continue — only the alert life cycle changes; Preview August 2026, GA September 2026, Purview on the web (multi-tenant); Microsoft has “not yet detailed the exact audit representation or retention for auto-resolved alerts”; positioned as the deterministic complement to the AI-powered Alert Triage Agent [S-2026-07-28-windowsnews-purview-dlp-autoresolution].
  • Evidence angle (inference): auto-resolution moves part of the DLP incident-disposition decision into standing configuration — for a regulated firm the rule set itself becomes a control needing ownership, review cadence and change-control evidence, and the undefined audit representation/retention of auto-resolved alerts is a direct DORA ICT incident-management / FCA-PRA operational-resilience evidence question; whether auto-closed alerts feed the roadmap-568372 SLA metrics is also unstated [inference — S-2026-07-28-windowsnews-purview-dlp-autoresolution].
  • DLP response-operations reporting (roadmap 568372, announced intent): an out-of-box SLA-based DLP alert reporting dashboard in Purview for the web — MTTA/MTTD/MTTR across DLP alerts, historical trends, top exposed sensitive-information types (SITs), and custom SLA definitions per alert severity (high/medium/low); Preview targeted August 2026, GA targeted September 2026, with calculation logic, permissions, retention and export options not yet published [S-2026-07-28-windowsforum-purview-dlp-sla].
  • Evidence angle (inference): native MTTA/MTTD/MTTR reporting against firm-defined severity SLAs would give Microsoft-estate FIs auditable response-time evidence for sensitive-data incidents — usable towards DORA ICT incident-management and FCA/PRA operational-resilience expectations — but whether the metrics are exportable/audit-grade, and which timestamps feed them, is undisclosed [inference — S-2026-07-28-windowsforum-purview-dlp-sla].
  • AI-interaction retention governance (MC1413308 / roadmap 561209, GA from mid-August 2026): Data Lifecycle Management adds AI-driven insights into how Copilot and AI apps are used across the organisation, with “actionable recommendations to strengthen retention policies and improve your data security posture” surfaced in the DSPM experience; Microsoft frames it as “help[ing] organizations govern AI interactions with greater visibility and control”. Preview is tenant-level opt-in (enabled by default once enrolled); existing retention policies are untouched unless admins act. Microsoft’s own compliance table notes the feature “analyzes existing Copilot and AI app interaction data” and introduces AI/ML capability [S-2026-07-03-m365admin-purview-dlm-copilot-insights].
  • Evidence angle (inference): retention governance over AI interaction records is the counterpart to the network-layer and DSPM monitoring items above — for an EU/UK FI it bears on GDPR retention/minimisation of prompt-and-response records (recommendations could pull either way; the notice gives no steer) and on evidencing AI-usage oversight towards EU AI Act record-keeping and FCA/PRA expectations; whether the insights/recommendations are themselves exportable as evidence, and whether “AI apps” extends beyond the Copilot family to the third-party surfaces DSPM connectors see, is not stated [inference — S-2026-07-03-m365admin-purview-dlm-copilot-insights].
  • Role-assignment governance / least privilege (rolling out, Aug–Sept 2026): Purview role group assignments for users and security groups can now carry an expiration date from one day to two years, after which “the assignment is automatically removed, and access is revoked without requiring manual action”; expiry is evaluated in the setting administrator’s local time zone. The capability is optional, covers all role groups except eDiscovery Administrator and eDiscovery Manager, and applies to new and existing assignments — but existing assignments are not changed automatically and “remain permanent until an administrator explicitly sets an expiration”. Expiry dates surface in the Purview Members and My permissions views; users get no notification before expiry; and where a user holds the same role group via both a direct and a security-group assignment, each expiry runs independently and access persists while either remains valid. A companion View-only Role Management role gives read-only visibility of role-group membership and assignments, included by default in Global Reader, Security Reader, Organization Management and Purview Administrators [S-2026-08-02-topedia-purview-role-expiration]. The View-only role details and the related Role-groups-UI item MC1311975 come from search-result summaries only and are lower-confidence.
  • Evidence angle (inference): automatic expiry of privileged compliance-tool access converts a standing-privilege exception into a time-bounded, self-revoking grant — directly useful against DORA ICT access-management and GDPR Art. 32 control expectations, and against the standing-access findings internal audit and FCA/PRA reviews routinely raise on compliance tooling. Two caveats materially limit the evidential value as described: the source does not say whether expiry events are written to the Purview audit log or whether expired assignments remain queryable for look-back evidence — auto-removal that erases history would weaken rather than strengthen an access-recertification trail. The absence of pre-expiry user notification is also an operational-resilience consideration (a compliance administrator silently losing access mid-investigation) [inference — S-2026-08-02-topedia-purview-role-expiration].
  • Classification throughput (announced 27 Aug 2026): SharePoint/OneDrive auto-labeling capacity increases from 100,000 to 500,000 files per day (E5/E7), per the Microsoft Security Blog as relayed by the September roundup — material for large estates holding tens of millions of files [S-2026-09-04-hoitingh-purview-september].
  • Policy simulation insights (Aug 2026): a new Insights tab in the policy details panel shows at-a-glance policy performance for DLP and auto-labeling, with content differing between simulation and enforcement modes; Microsoft 365 content only [S-2026-09-04-hoitingh-purview-september].
  • Exchange DLP scan-failure handling (preview, Jul 2026): Exchange Online DLP detects classification failures from timeouts/throttling/scan errors, and a DocumentScanFailures condition lets admins apply distinct protection actions to unscannable messages — reducing silent classification gaps and false positives [S-2026-09-04-hoitingh-purview-september].
  • Separation of duties on irreversible deletion (Jul 2026): priority-cleanup expedited permanent deletion now requires three separate approvers (a Priority Cleanup administrator, a retention manager, an eDiscovery administrator) [S-2026-09-04-hoitingh-purview-september].
  • Evidence angle (inference): the three-approver workflow gives Microsoft-estate FIs a demonstrable separation-of-duties control over the platform’s “single most irreversible action” (the roundup author’s phrase) — usable towards GDPR retention-governance and internal-audit evidence, provided the firm’s own role assignments genuinely separate the three approvers [inference — S-2026-09-04-hoitingh-purview-september].
  • Fabric governance visibility and scope withdrawal (Jul 2026): Microsoft Fabric governance experiences in the OneLake catalog surface DLP activity/adoption (evaluated workspaces, sensitive-information location, policy adoption, high-risk assets); separately, Purview protection policies no longer support Azure SQL Database, with no reason published — a coverage regression for firms that relied on it [S-2026-09-04-hoitingh-purview-september].
  • Layered-enforcement positioning (31 Aug 2026): Microsoft’s Purview blog frames endpoint, browser and network DLP as complementary layers, arguing enforcement gaps arise when firms treat any single layer as sufficient; the roundup author extends this into a measurement recommendation — track DLP coverage by layer — and cautions that “preview capabilities should remain bounded pilots and should not be represented as operating controls” [S-2026-09-04-hoitingh-purview-september].
  • Cross-cloud AI guidance (5 Jun 2026, context): Microsoft published guidance for extending Purview data protection to AWS Bedrock agents, addressing govern-with-Purview-while-running-AI-elsewhere estates [S-2026-09-04-hoitingh-purview-september].
  • Roadmap (unverified): an AI-powered DLP Policy Optimizer (surfacing overlapping rules, misconfigurations, alert noise) is reported by third parties to begin rolling out July 2026; not yet on Microsoft’s changelog, and not mentioned in the July roadmap summary either [speculative — S-2026-07-06-purview-whats-new-recheck].
  • July 2026 roadmap wave — data-security automation (roadmap-stated, not yet on Microsoft’s changelog): the Data Security Triage Agent pushes remediation requests for DLP “Needs Attention” files to the last modifier via Teams, with progress tracked in DSPM dashboards; automated deletion of departed employees’ inactive OneDrives/mailboxes (the 14 Sep digest now lists this item — roadmap 566527, “content and containers … at scale” — as in development for November 2026 [S-2026-09-14-sharepointstuff-m365-roadmap-purview]; see Tensions); Endpoint DLP gains sensitivity-label detection inside archive files (ZIP) and protection over FTP/SFTP transfers; user-based aggregation of DLP alerts into single alert objects; self-service eDiscovery diagnostics; the RMS connector moves to certificate-based authentication; and Global/Security Reader roles gain wider Purview/Defender role-assignment visibility [S-2026-07-01-m365-july-roadmap-purview].
  • Evidence angle (inference): DSPM-tracked, agent-driven remediation would give Microsoft-estate firms an auditable sensitive-data cleanup trail relevant to GDPR data-protection-by-design and DORA ICT-risk evidence — whether the trail is exportable/audit-grade is not described in the source [inference — S-2026-07-01-m365-july-roadmap-purview].

Theoretical basis

  • depends-on → EU AI Act — third-party guidance frames Purview’s AI controls as supporting EU AI Act training/inference-data governance; Microsoft’s own changelog makes no explicit conformity claim [inference — S-2026-06-16-microsoft-purview-whats-new].

Strengths / weaknesses

  • Strength (asserted): native, auditable governance and posture management over the Microsoft AI surface (Copilot, Agent 365) with connectors reaching ChatGPT Enterprise and Claude Enterprise [S-2026-06-16-microsoft-purview-whats-new].
  • Weakness (scope): AI-governance coverage is largely Microsoft-estate-bound; it is not a general cross-platform catalogue in the Collibra/Atlan sense [inference — S-2026-06-16-microsoft-purview-whats-new].

Tensions

  • The regulatory-alignment framing (EU AI Act/GDPR/DORA) originates from third-party guides, not Microsoft’s changelog, and is labelled inference rather than verified conformity [S-2026-06-16-microsoft-purview-whats-new].

On when the changelog’s July 2026 section appeared:

  • The 6 July recheck [S-2026-07-06-purview-whats-new-recheck] (medium) reported the changelog “unchanged since 16 June 2026” with no July section.
  • A 13 July fetch [S-2026-06-30-purview-whats-new-july-wave] (medium) found the same page carrying ms.date 2026-06-30 / site-updated 2026-07-01 and a July 2026 section.
  • Where they actually disagree: not on content, but on page state at 6 July — either the recheck received a cached/stale copy, or Microsoft back-dated/published the section after 6 July. The July items themselves are not in dispute.
  • Status: unresolved (immaterial to capability facts; noted for provenance hygiene).

On the date of MC1449180:

  • The m365admin relay [S-2026-08-07-m365admin-purview-crosssaas-dlp] (medium) dates the Message Center notice 7 August 2026.
  • Redmond [S-2026-08-14-redmond-purview-external-dlp] (medium) dates it 6 August 2026.
  • Where they actually disagree: only the notice’s publication date; content and schedule agree in full.
  • Status: unresolved (immaterial to capability facts; noted for provenance hygiene).

On the rollout window for time-limited Purview role group assignments:

  • The fetched Topedia post [S-2026-08-02-topedia-purview-role-expiration] (medium, first-hand portal experience with screenshots) states the rollout “should be completed in September 2026”.
  • WebSearch summaries of related third-party coverage (AdminDroid, m365admin.handsontek.net) described the rollout as beginning late July 2026 and expected to complete late August 2026 [low — search-summary only, underlying pages not fetched].
  • Where they actually disagree: only the completion month. The feature mechanics are not in dispute and are consistent across both.
  • Status: unresolved — both are third-party restatements of a Microsoft estimate; no Microsoft Message Center notice for this feature was retrieved. Re-check against a Microsoft primary source.

On when Priority cleanup’s multi-approver hold-bypass exists:

  • Hoitingh [S-2026-09-04-hoitingh-purview-september] (medium) reports, as a July 2026 change, that priority-cleanup expedited permanent deletion “now requires three separate approvers” (Priority Cleanup administrator, retention manager, eDiscovery administrator).
  • The 14 Sep roadmap digest [S-2026-09-14-sharepointstuff-m365-roadmap-purview] (medium) lists “the first release of Priority cleanup” — a recurring exception to delete items under retention/legal hold on the Exchange workload, with “a separate security role, multiple approvers, and … a complete audit trail” — as in development for October 2026 (roadmap 392838).
  • Where they actually disagree: whether the audited multi-approver workflow is already live (Hoitingh) or still to ship (roadmap). A plausible reconciliation is that Hoitingh describes the approver rule on an existing (e.g. SharePoint/OneDrive) priority-cleanup path while the roadmap entry is the Exchange-workload first release — but neither source says so [inference].
  • Status: unresolved — check Microsoft’s changelog / Learn documentation for Priority cleanup workload coverage before citing this as an operating control.

On the delivery date of departed-employee OneDrive/mailbox deletion:

  • The July roadmap wave [S-2026-07-01-m365-july-roadmap-purview] (medium) listed automated deletion of departed employees’ inactive OneDrives and mailboxes among July 2026 items.
  • The 14 Sep digest [S-2026-09-14-sharepointstuff-m365-roadmap-purview] (medium) lists the same capability (roadmap 566527) as in development for November 2026.
  • Where they actually disagree: only the target month; the capability description is consistent. Either the July digest misread the roadmap month or Microsoft has re-dated the item — the 14 Sep digest does not carry an explicit “date moved” note for 566527.
  • Status: unresolved (dating only); treat the capability as not yet shipped.

On what ships in July:

  • Microsoft’s changelog July section [S-2026-06-30-purview-whats-new-july-wave] (medium) lists only Network Data Security and the three IRM previews.
  • Third-party roadmap coverage [S-2026-07-01-m365-july-roadmap-purview] (medium) and [S-2026-07-06-purview-whats-new-recheck] (low, for the Policy Optimizer item) attribute a much larger July wave (Triage Agent Teams remediation, departed-user cleanup, archive/FTP-SFTP DLP, alert aggregation, DLP Policy Optimizer) to Microsoft’s public roadmap.
  • Where they actually disagree: changelog = shipped/preview-confirmed; roadmap = announced intent. Items may yet land later in July.
  • Status: partially reconciled by [S-2026-07-30-microsoft-security-july-roundup] — the 30 July roundup confirms the unified IRM alert experience shipped and the Triage Agent’s AI reasoning layer reached GA (though the roundup describes reasoning-layer GA rather than the roadmap’s Teams-remediation flow specifically); the remaining roadmap items (departed-user cleanup, archive/FTP-SFTP DLP, alert aggregation, DLP Policy Optimizer) are still unconfirmed.

Sources