Microsoft Purview — What’s new (June 2026 changelog)

Tag: S-2026-06-16-microsoft-purview-whats-new Type: report (vendor product changelog — primary) Author(s): Microsoft (Purview docs team) Date of source: 2026-06-16 (page ms.date/updated_at; entries grouped under “June 2026” and “May 2026”) Date ingested: 2026-06-22 Authority weight: medium — primary Microsoft changelog (authoritative on what shipped and its GA/preview status), but self-interested on fitness; FS suitability not independently verified. Raw file: S-2026-06-16-microsoft-purview-whats-new.md. External URL: https://learn.microsoft.com/en-us/purview/whats-new

What it claims

Microsoft’s official “What’s new in Microsoft Purview” changelog (updated 2026-06-16) lists the platform’s recent governance, data-security and compliance shipments. The June 2026 headline is the general availability of data security and compliance protections for Microsoft 365 Copilot Cowork, extending Purview’s labelling, DLP, audit and posture controls over a further Copilot surface. A June DLP preview lets policies stop Copilot from using untrusted external email as grounding data, framed as a prompt-injection mitigation. The May 2026 entries add the GA of a new Data Security Posture Management (DSPM) version (guided workflows for proactive data-risk management “so you can more confidently adopt AI”), GA of data security & compliance protections for Microsoft Agent 365, and DSPM preview support for an Anthropic Claude (Enterprise) connector so Purview can surface individual Claude interactions (who, when, what content) alongside Copilot and ChatGPT Enterprise. On the data-governance side, May 2026 brought GA of standalone-asset and incremental data-quality scans and configurable data-quality thresholds in Unified Catalog. Collectively the changelog positions Purview as a Microsoft-estate control plane for governing data quality plus employee/agent AI use.

Notable quotes

General availability (GA): Data security and compliance protections for Microsoft 365 Copilot Cowork” — June 2026 entry.

“New External users condition … lets DLP policies prevent Copilot from using external email as grounding data, helping reduce prompt injection risk from untrusted senders.” — June 2026 DLP preview.

“Support for Anthropic Claude (Enterprise) … Claude then displays as another AI application alongside Copilot, Copilot Studio, ChatGPT Enterprise … Use activity explorer to see individual Claude interactions …” — May 2026 DSPM preview.

What’s speculative vs. asserted

  • Asserted (verifiable from the changelog): the names, scope and GA/preview status of each feature (Copilot Cowork protections GA; DSPM v2 GA; Agent 365 protections GA; Claude connector in preview; DLP external-email grounding control in preview; DQ scans/thresholds GA).
  • Speculative / marketing: that these let firms “more confidently adopt AI”; any implied EU AI Act / GDPR / DORA sufficiency. The changelog makes no explicit BCBS 239 or EU AI Act conformity claim — regulatory-alignment framing in this wiki is inference from the capability, labelled as such.
  • Scope caveat: Purview’s AI-governance coverage is largely confined to the Microsoft 365 / Azure estate plus named connectors; it is not a general cross-platform data catalogue in the Collibra/Atlan sense.

Topics this feeds

Open questions raised

  • Do Purview’s audit/activity-explorer logs for Copilot, Agent 365 and Claude meet EU AI Act Article 12 logging and DORA evidentiary requirements (retention, immutability, format)? Not stated.
  • Are the new June AI-governance features available under EU data-residency/sovereignty configurations? Not addressed on the page.
  • Any EU/UK regulated-FS reference deployment? None named.