Microsoft Purview changelog July 2026 wave — Network Data Security (Entra GSA) preview; IRM unified alert experience
Tag: S-2026-06-30-purview-whats-new-july-wave
Type: report (vendor changelog)
Author(s): Microsoft (Learn changelog, whats-new.md)
Date of source: 2026-06-30 (page ms.date; site updated 2026-07-01)
Date ingested: 2026-07-13
Authority weight: medium — Microsoft’s changelog is primary and authoritative on availability status, self-interested on fitness for purpose.
Raw file: S-2026-06-30-purview-whats-new-july-wave.md. External URL: https://learn.microsoft.com/en-us/purview/whats-new
What it claims
Microsoft’s Purview changelog now carries a July 2026 section. Its headline item is a DLP preview integrating Purview with Microsoft Entra Global Secure Access (GSA) — branded Purview Network Data Security — which “intercept[s] and inspect[s] text and AI interactions at the network layer”, enforces DLP restrictive actions, feeds risky-activity detection into Insider Risk Management, and aims to stop sensitive data being shared with “untrusted cloud applications through browsers, apps, APIs, and add-ins, including generative AI platforms”. The July section also lists three Insider Risk Management previews: a unified alert experience merging Triage Agent and Standard alert dashboards into one alerts list (with agent-summary preview), expanded user profile details drawn from Entra (office location, employee type, department, last working date), and expanded note capabilities with system-generated notes on status/assignment/closure changes. The June 2026 section is unchanged in substance from prior ingests (Copilot Cowork protections GA, device-scoped Endpoint DLP, external-email Copilot grounding condition, new sensitive information types, etc.).
Notable quotes
“This integration enables organizations to intercept and inspect text and AI interactions at the network layer, enforce restrictive actions based on DLP policies, and detect risky user activity through Insider Risk Management.” — July 2026, Data Loss Prevention
What’s speculative vs. asserted
- Asserted (primary): the July 2026 items above, each explicitly marked “In preview” by Microsoft.
- Speculative / open: fitness of network-layer AI-interaction inspection as regulatory evidence; no conformity claim (GDPR/DORA/EU AI Act) is made by Microsoft — any regulatory framing in synthesis pages is inference.
- Notably absent: the July roadmap items reported by Level Up M365 (S-2026-07-01-m365-july-roadmap-purview — Triage Agent Teams remediation, departed-user data cleanup, archive/FTP-SFTP DLP, alert aggregation) do not appear in this July section; nor does the third-party-reported “DLP Policy Optimizer” (S-2026-07-06-purview-whats-new-recheck).
Topics this feeds
- Microsoft Purview — technology page updated with the July changelog wave and a tension against the 07-06 recheck.
Open questions raised
- Whether Network Data Security’s interception of AI prompts/responses produces retention-grade logs a firm could cite as DORA ICT-monitoring or GDPR Article 32 evidence (not described).
- Timing discrepancy: the 07-06 recheck found the page “unchanged since 16 June”, yet the page now shows
ms.date 2026-06-30— cached fetch or late publication? Unresolved; see Tensions on Microsoft Purview.