Purview DSPM for AI — securing Copilot + public-LLM prompts

Pawan Sharma Published 10 Jun 2026  ·  By Pawan Sharma  ·  AI & Security  ·  14 min read

Generative-AI adoption in Indian enterprise has gone from "interesting exploration" to "your finance team is pasting customer data into ChatGPT and the SOC has no visibility" in 18 months. Microsoft Purview Data Security Posture Management for AI is the operational layer that fixes that — prompt content classification, DLP enforcement on AI prompts, sanctioned-vs-unsanctioned AI app visibility, and the sensitivity-label propagation that makes M365 Copilot safe to roll out. This post is the 30-day activation plan, with the DPDP evidence frame.

3 risks

DSPM for AI addresses

Public-LLM prompt leak, Copilot over-share, sanctioned-AI policy gap.

Purview DSPM

Prerequisite layer

Sensitivity labels + DLP must be live first. AI tier sits on top.

30,000+

AI apps catalogued

Defender for Cloud Apps Catalog tags every known AI service.

DPDP-aligned

Compliance frame

Sec 8(5) reasonable safeguards extends to AI-mediated processing.

Three AI-data-leak risks DSPM for AI addresses

1. Sensitive data into public LLMs

Employees paste customer PII, source code, M&A docs, financial data into ChatGPT / Gemini / Claude. DSPM for AI: endpoint DLP detects, blocks, warns, or audits. Edge browser integration sees the prompt content.

2. M365 Copilot over-share

SharePoint over-permissioned content surfaces to Copilot users who shouldn't see it. DSPM for AI: pre-Copilot Purview rollout fixes the underlying over-share (auto-labelling + DLP); Copilot inherits labels + enforces policy on generated content.

3. Sanctioned-AI policy gap

Internal Azure OpenAI deployment or sanctioned Copilot used without classification policies. DSPM for AI: prompt-content audit + sensitivity-aware response policies on tenant-anchored AI workloads.

The DSPM for AI feature stack

ComponentWhat it does
DSPM for AI dashboardUsage visibility across users + AI apps; risk-scored views; week-over-week trend
Endpoint DLP for AI promptsPrevent paste / file-upload of Restricted-PII into AI apps at the endpoint
Edge browser integrationInspect + classify prompt content sent to web-based AI apps; apply block / warn policies
Sensitivity label inheritance for CopilotRestricted-PII source → Copilot-generated content inherits label + enforcement
Sanctioned AI policy frameworkApproved-AI list + per-app sensitivity policies + auditable usage trail
Defender for Cloud Apps Catalog30,000+ AI services categorised + risk-scored; sanctioned / unsanctioned tagging
Sentinel + Defender XDR integrationAI-prompt-DLP events flow to SIEM + analyst investigation surface

The 30-day activation plan

Prerequisite

Purview Information Protection + DLP must already be production

If sensitivity labels aren't deployed + DLP rules aren't enforcing on the data side, DSPM for AI produces low-signal outputs. Run the standard Purview 30-day plan first (covered in our DPDP post), then roll out DSPM for AI. Trying to skip-ahead is the #1 reason DSPM for AI pilots stall.

1

Days 1-7 — Baseline AI usage visibility

Enable DSPM for AI dashboard. Defender for Cloud Apps Catalog active. Capture 7 days of AI-usage telemetry — which AI apps, who's using them, what sensitivity context.

2

Days 8-14 — Endpoint DLP + Edge browser

Endpoint DLP rules to block Restricted-PII paste into public AI apps. Edge browser integration for content inspection. Start in monitor mode for 7 days; tune false-positives.

3

Days 15-21 — Sanctioned AI policy framework

Define sanctioned-AI list (M365 Copilot + tenant Azure OpenAI workloads). Sensitivity label inheritance configured. Per-app sensitivity policies enforced.

4

Days 22-30 — Incident detection + Sentinel

Flip endpoint + Edge DLP to enforce. Sentinel data connector for AI-prompt-DLP events. First incidents triaged through Defender XDR. Monthly compliance report cadence established.

What you can show your DPO + auditor on day 30

AI app inventory + risk score

Every AI app accessed from corporate endpoints, classified by Defender for Cloud Apps Catalog.

Sensitive-data-into-AI events

Blocked, warned, or audited — full chain-of-custody for DPDP Sec 8(5) evidence.

Sanctioned AI usage profile

Which sanctioned AI (Copilot, Azure OpenAI) is used by which user populations, with sensitivity context.

Copilot over-share remediation

Pre-Copilot Purview auto-labelling + DLP outcomes — what was over-shared and how the labels closed it.

FAQ

What is DSPM for AI specifically protecting against?
Three classes of risk: (1) sensitive data leaking into prompts to public LLMs (ChatGPT, Gemini, Claude via web/app); (2) sensitive data leaking out of M365 Copilot responses because sensitivity labels aren't on the source data; (3) sanctioned-AI use without policy enforcement — your tenant Copilot/Azure OpenAI returning over-shared data because Purview classification is incomplete.
Does DSPM for AI work for non-Microsoft LLMs too?
Yes. Purview's Defender for Cloud Apps connector + Edge browser integration detect prompts sent to ChatGPT / Gemini / Claude / Perplexity and apply DLP policies — block, warn, or audit. Endpoint DLP catches paste-into-AI-app patterns at the endpoint layer.
How does it interact with M365 Copilot specifically?
Purview sensitivity labels propagate through Copilot. If a document is labelled Restricted-PII, Copilot inherits the label on any generated content + enforces policy (no external sharing, no copy-to-non-labelled). The pre-Copilot 'over-share' fixes via auto-labelling + DLP are the actual rollout work — Copilot just inherits.
How does this map to DPDP Act obligations?
DPDP Sec 8(5) reasonable safeguards extends to AI-mediated processing. Purview DSPM for AI gives you: prompt-content classification, AI-usage audit trail, DLP enforcement on prompts containing personal data, sanctioned-vs-unsanctioned AI usage visibility. Same DPDP evidence frame as the broader Purview rollout.
Is this all paid premium tier?
Mix. Foundational DSPM for AI dashboard is included with Microsoft 365 E5 + Compliance E5. Purview Data Security Posture Management for AI premium tier adds advanced AI-specific policies + cross-cloud (AWS Bedrock, GCP Vertex AI) coverage. Defender for Cloud Apps Catalog (~30,000 AI apps tagged) is part of MDA licensing.
What's the rollout order — Purview DSPM general first, then DSPM for AI?
Yes. Sensitivity labels + DLP must be in production before DSPM for AI delivers value — the AI-specific tier is the enforcement layer on top of the classification baseline. Trying to roll out DSPM for AI without the underlying Purview foundation produces low-signal outputs.
Workforce concerns + employee monitoring?
Insider Risk Management (the broader Purview module) runs anonymised by default with DPO-supervised de-anonymisation. DSPM for AI uses the same privacy posture — prompt content classified, but individual prompts only surface to investigators on confirmed risk. Documented privacy-by-design vs blanket-monitoring approach.
What's the 30-day DSPM for AI activation plan?
Prerequisite: Purview Information Protection + DLP baseline already live. Week 1: enable DSPM for AI dashboard; baseline AI usage across users. Week 2: enable Edge / endpoint DLP for prompt content. Week 3: sanctioned-AI policies (M365 Copilot + sanctioned Azure OpenAI) with sensitivity inheritance. Week 4: incident detection + Sentinel integration.

Free Purview DSPM for AI readiness assessment

Inventory your enterprise AI usage, identify the top sensitive-data leak channels, plan the 30-day fix

Ogma audits your current AI-app usage (sanctioned + shadow) via Defender for Cloud Apps Catalog, identifies the top 5 sensitive-data leak channels, and returns a 30-day DSPM for AI activation plan with Purview prerequisite gap analysis.

Request the readiness assessment or explore the Microsoft Purview landing

Related: Purview for DPDP Act · Copilot for Security rollout · 30/60/90 stack rollout

Stay ahead of cyber threats

One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.


Cato Firewall as a Service
Cato ZTNA — Zero Trust Network Access
Cato SASE Solution