Microsoft Purview DSPM Is Now GA: What Changed and How to Start
For years, getting a straight answer to "how exposed are we, really?" meant stitching together reports from DLP, Insider Risk, sensitivity labels, and Data Security Investigations by hand. The new Microsoft Purview Data Security Posture Management (DSPM) experience is built to close that gap — and it's now generally available.
Use Case
A client's security team could see individual signals — a DLP match here, an oversharing alert there, a risky Copilot prompt somewhere else — but had no single view tying them together into an actual posture. Every quarterly review turned into a manual reconciliation exercise across three or four different reports.
What changed in the GA release
The new DSPM experience isn't a rebrand of the classic version — it's a genuinely unified workflow that consolidates data from DLP, Insider Risk Management, sensitivity labels, and Data Security Investigations into one place, then adds a layer of guided remediation on top. A few things stand out:
- Goal-oriented flows. Instead of browsing disconnected reports, you work through posture in defined flows — discover exposure, assess risk, remediate — with the tool telling you what to do next rather than you hunting for it.
- AI and agent observability. DSPM now inventories the AI apps and agents active in your tenant — including agents built in Copilot Studio — with a risk score and posture metrics per agent. If you're rolling out agentic Copilot Studio apps, this is the first place I'd check before your next audit.
- Customizable reports. Beyond the out-of-the-box reports, you can now combine built-in and custom views into dashboards scoped to a role or a specific risk scenario — useful if security, compliance, and IT leadership all want a different slice of the same data.
- Third-party signal ingestion. DSPM can now factor in signals from tools like BigID, Cyera, OneTrust, and Varonis, which matters if your data estate isn't 100% Microsoft-native (and whose is).
Don't confuse the versions: the classic Data Security Posture Management and the classic DSPM for AI are still there, but Microsoft has said most new investment lands in the new unified experience going forward. If you're starting fresh, start in the new one.
Licensing & prerequisites
Before you flip this on for real, get these three things sorted:
- Someone with the Microsoft Purview Compliance Administrator role (or Entra Compliance Administrator) to configure DSPM itself.
- Microsoft Purview Audit activated — DSPM leans on audit signal to populate its findings, and without it you'll see an empty dashboard.
- If you want AI interaction coverage (prompts and responses across Microsoft 365 Copilot, Copilot Chat, and Copilot Studio agents), you'll need Microsoft 365 E5 in the mix — that's the license tier that unlocks interaction-level detail, not just app inventory.
Read-only access for the wider team is cheaper: the Purview Security Reader or Data Security Viewer roles are enough for someone to review findings without being able to change policy.
Getting started
- Sign in to the Microsoft Purview portal → Solutions → DSPM (not "DSPM classic" or "DSPM for AI classic").
- Complete the first-run setup tasks it prompts you for — mainly confirming audit is on and the browser extension is deployed if you want visibility into third-party AI site usage.
- Give it roughly 24 hours to populate before judging the results — recommendations and reports need time to backfill from your tenant's signal.
- Work through the guided recommendations first; they're pre-scoped, low-risk, one-click policies rather than something you have to design from scratch.
- Once the basics are in place, build one custom report per audience — I keep a lean "leadership" view (trendlines only) separate from the "operational" view my team actually acts on day to day.
How I'd roll this out
Treat this the same way you'd treat any new posture tool: pilot it against a business unit you already understand well, so you can sanity-check its findings against what you know is true on the ground. Resist the urge to action every recommendation on day one — the AI agent inventory in particular tends to surface a long tail of low-usage Copilot Studio agents that are worth triaging, not panicking over.
If your organization is already deep into agentic Copilot Studio builds, the AI observability piece alone is worth the licensing conversation — it's the closest thing Purview has today to a single inventory of "what AI is actually running against our data."
Related reading
If you haven't locked down what Copilot can see before enabling it more broadly, start with my earlier piece on protecting your data before enabling Microsoft 365 Copilot — DSPM is the posture layer on top of exactly that groundwork.