What’s new in Microsoft Security: July 2026 (Purview items)

Tag: S-2026-07-30-microsoft-security-july-roundup Type: article (vendor monthly roundup, Microsoft Security Blog) Author(s): Alym Rayani (VP of Marketing, Microsoft Security) Date of source: 2026-07-30 Date ingested: 2026-07-31 Authority weight: medium — first-party vendor announcement of its own product; availability labels are Microsoft’s own and only partially explicit; marketing byline Raw file: S-2026-07-30-microsoft-security-july-roundup.md

What it claims

Microsoft’s July 2026 security roundup (published 30 July) announces three Purview developments. First, Purview now integrates with Microsoft Entra Internet Access to extend data security to the network layer: sensitive data (text and files) being shared with unmanaged cloud and AI apps — Microsoft’s example is an employee uploading customer data into “shadow AI apps” — is detected and blocked in transit, giving organisations “a unified Microsoft solution” for visibility and blocking of sensitive data in motion “without relying on third-party solutions”. Second, a DLP for Microsoft 365 Copilot protection, in preview, lets admins exclude emails from external senders from being referenced, summarised, or used as grounding data for Copilot. Third, a new centralized Insider Risk Management alert experience brings agentic alert triage, enriched user details and expanded analysis into a single view, powered by the Data Security Triage Agent whose “advanced AI reasoning layer” is now generally available, performing multi-step analysis across user, device and data activity signals with system-recorded status changes and escalations “to maintain a clear investigation history”. The same post covers non-Purview items (Project Perception agentic SecOps, Defender prompt-injection protection, Entra passkeys by default, Intune Suite folded into M365 E5 from 1 July 2026).

Notable quotes

“Microsoft Purview now integrates with Microsoft Entra Internet Access to extend data security to the network layer, enabling real-time protection of sensitive data shared with unmanaged cloud and AI apps over the network.” — Purview/Entra section

“…the Data Security Triage Agent includes an advanced AI reasoning layer, now generally available, that performs deeper, multi-step analysis across user, device, and data activity signals…” — IRM section

What’s speculative vs. asserted

  • Asserted with explicit availability: Triage Agent advanced AI reasoning layer — generally available; DLP-for-Copilot external-email exclusion — preview; Intune-in-E5 — effective 1 July 2026.
  • Asserted without explicit release stage: the Entra Internet Access integration and the centralized IRM alert experience carry no GA/preview label in this post. The Purview changelog previously listed the network capability (“Purview Network Data Security”, DLP × Entra Global Secure Access) as preview [S-2026-06-30-purview-whats-new-july-wave]; this post does not supersede that label.
  • Marketing framing (unverified): “unified Microsoft solution … without relying on third-party solutions”; investigation-history claims are not accompanied by retention/exportability detail.
  • Inference (labelled): the Entra Internet Access integration is the announced form of the changelog’s Network Data Security preview (Entra Internet Access is part of Global Secure Access) — same capability family, not a second product.

Topics this feeds

  • Microsoft Purview — technology page updated: network-layer integration announced, IRM unified alert experience + Triage Agent reasoning-layer GA; partially reconciles the “what ships in July” tension.

Open questions raised

  • Is the network-layer integration GA or still preview? The blog omits the label; the changelog said preview.
  • Are the IRM “investigation history” records exportable/retained in an audit-grade form suitable as GDPR Art. 32 / DORA ICT-monitoring evidence? Not described.