This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for AI
--> Identify risks related to Microsoft Copilot and AI apps by using Microsoft Purview Data Security Posture Management (DSPM)
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
This topic focuses on using Microsoft Purview Data Security Posture Management (DSPM) to identify risks associated with Microsoft Copilot and other AI applications.
You should understand how to:
- Discover which AI applications are being used.
- Identify sensitive information involved in AI interactions.
- Detect potential data exposure and oversharing.
- Review prompts, responses, and referenced content when permitted.
- Use DSPM insights and recommendations to prioritize security controls.
- Understand the relationship between DSPM, Microsoft Purview, Microsoft Defender, and Microsoft 365 security controls.
Why AI-related data risks matter
Generative AI applications can make sensitive information easier to discover, summarize, combine, and distribute. A user might ask Copilot to summarize documents, analyze business information, or answer questions using organizational data. If the underlying data is incorrectly shared or insufficiently protected, AI can amplify the exposure by making that information easier to retrieve and use.
Microsoft 365 Copilot is designed to respect existing user permissions. Therefore, many Copilot data-exposure risks are not caused by Copilot bypassing permissions. Instead, they occur because users already have access to information that is too broadly shared, improperly classified, stale, or insufficiently governed.
Microsoft Purview DSPM helps organizations understand these risks by bringing together information about data, users, AI interactions, sensitive information, and existing security controls. It provides analytics, trends, recommendations, and guided actions that help security and compliance teams improve their data security posture.
What is Microsoft Purview DSPM?
Microsoft Purview Data Security Posture Management is a centralized capability for discovering, assessing, and managing data security risks across an organization.
DSPM can help organizations:
- Understand where sensitive data exists.
- Identify how data is accessed and used.
- Detect potential oversharing and exposure.
- Identify risky AI interactions.
- Review recommendations for improving protection.
- Connect findings to Microsoft Purview security and compliance controls.
DSPM for AI provides visibility into AI-related risks, including sensitive data in prompts and responses, risky AI usage, and interactions involving enterprise or third-party AI applications. Microsoft Purview also provides related capabilities through auditing, data classification, sensitivity labels, Data Loss Prevention, Insider Risk Management, and eDiscovery.
Microsoft documentation now distinguishes between the current Data Security Posture Management experience and the earlier DSPM for AI (classic) experience. The current DSPM experience provides broader data-security workflows, while some older one-click policies and documentation may still use the “DSPM for AI” terminology.
Important AI-related risks
1. Overshared data
Oversharing occurs when sensitive information is accessible to more users than necessary.
Examples include:
- A confidential SharePoint site accessible to all employees.
- A document shared through an “Anyone” link.
- A sensitive file available through a broad Microsoft 365 group.
- A former project site that still contains confidential information.
- A document with unique permissions that were never reviewed.
- A file that lacks an appropriate sensitivity label.
When Copilot or an agent can access data through a user’s existing permissions, overshared information may become easier to discover in AI-generated responses. DSPM and related SharePoint governance reports help identify these conditions.
2. Sensitive information in prompts and responses
Users may enter sensitive information into AI applications, such as:
- Customer information.
- Financial data.
- Employee records.
- Intellectual property.
- Credentials or secrets.
- Health-related information.
- Legal or regulatory information.
- Confidential source code.
Microsoft Purview data classification can use sensitive information types and trainable classifiers to identify sensitive data in AI prompts and responses. These findings can appear in Microsoft Purview reports and Activity Explorer.
3. Risky AI usage
Risky AI usage can include:
- Attempted prompt injection.
- Attempts to access protected material.
- Use of AI to expose confidential information.
- Unusual or potentially malicious AI activity.
- Inappropriate use of AI applications.
- Copying sensitive organizational data into an unapproved AI service.
Microsoft Purview Insider Risk Management can use AI-related signals to help identify potentially risky behavior. For example, the risky AI usage policy template can detect activities such as prompt injection attempts and attempts to access protected materials.
4. Use of unapproved third-party AI applications
Employees may use public AI websites without organizational approval. Examples include consumer versions of ChatGPT, Google Gemini, or other generative AI services.
These applications can create risks when users:
- Paste sensitive business information into prompts.
- Upload confidential files.
- Use organizational data in an application without approved controls.
- Circumvent organizational AI policies.
- Use an AI service that does not meet organizational compliance requirements.
Microsoft Purview supports visibility into certain third-party AI interactions. Network-based data security capabilities can help audit prompts and responses through supported Secure Access Service Edge or Security Service Edge integrations. The Microsoft Purview browser extension and onboarded devices may also be required for particular discovery and endpoint DLP scenarios.
Microsoft Purview DSPM capabilities for AI
AI activity discovery
DSPM helps organizations understand which AI applications are being used and how users interact with them.
Depending on the application and configuration, organizations may be able to identify:
- The AI application involved.
- The user or activity associated with an interaction.
- The presence of sensitive information.
- Risk indicators.
- Related prompts and responses.
- Referenced files or data sources.
- Potentially unethical or inappropriate interactions.
The level of detail available depends on the application, licensing, permissions, collection policies, and supported integration.
Sensitive-data insights
DSPM can use Microsoft Purview classification capabilities to identify sensitive information in AI interactions.
Classification may be based on:
- Sensitive information types.
- Trainable classifiers.
- Existing sensitivity labels.
- Other Microsoft Purview classification signals.
These insights help security teams determine whether users are submitting or receiving information that requires additional protection.
Risk assessments and recommendations
DSPM provides data risk assessments and recommendations that help organizations identify security weaknesses and determine appropriate next steps.
Examples of recommendations may include:
- Protecting sensitive data with sensitivity labels.
- Reviewing overshared SharePoint content.
- Capturing AI interactions for investigation or compliance.
- Creating DLP policies.
- Creating Insider Risk Management policies.
- Reviewing risky users or activities.
- Restricting access to sensitive content.
DSPM is not simply a reporting dashboard. Its purpose is to help transform data-discovery findings into practical security and compliance actions.
How to access DSPM
The current Microsoft Purview experience provides DSPM functionality through the Microsoft Purview portal.
A typical workflow is:
- Sign in to the Microsoft Purview portal.
- Open Data Security Posture Management.
- Review the available security objectives, dashboards, assessments, and recommendations.
- Select the relevant AI or data-risk area.
- Review the affected applications, users, data, or activities.
- Drill into details using available reports or Activity Explorer.
- Apply or configure the recommended security controls.
Some older documentation refers to:
Microsoft Purview portal → Solutions → DSPM for AI (classic)
The exact navigation and available capabilities may vary as Microsoft transitions functionality from the classic experience to the current DSPM experience.
Recommended setup tasks
Before DSPM can provide meaningful insights, several prerequisites and setup tasks may be required.
Activate Microsoft Purview Audit
Auditing provides visibility into activities that occur in supported Microsoft services and applications. In many new tenants, auditing is already enabled, but administrators should verify that it is available and configured appropriately.
Configure AI interaction collection
Some AI investigations require collection policies to capture prompts and responses.
For example, Microsoft Purview provides one-click policies for capturing interactions from supported Copilot experiences and enterprise AI applications. These policies allow the interactions to be analyzed by supported Purview solutions such as DSPM, eDiscovery, Data Lifecycle Management, and compliance workflows.
Configure sensitive-data discovery
Organizations can extend insights into sensitive data shared with AI applications by configuring the appropriate data-classification and network-based discovery capabilities.
Onboard devices when required
Device onboarding may be required for scenarios such as:
- Discovering sensitive information shared with third-party AI sites.
- Applying endpoint DLP policies.
- Detecting users who paste sensitive information into public AI applications.
Configure sensitivity labels
Sensitivity labels help classify and protect files, emails, and other supported content. Labels can provide protection even when content is moved or downloaded, depending on the configured label settings.
Configure pay-as-you-go billing when required
Some DSPM and AI-related data storage or processing capabilities require pay-as-you-go billing. The applicable requirements depend on the specific feature and configuration.
Reviewing AI risk dashboards
DSPM for AI can provide reports and dashboards that help security teams identify patterns such as:
- Total AI interactions over time.
- Sensitive interactions by AI application.
- Risky AI usage.
- Potentially unethical interactions.
- Insider Risk severity.
- AI applications associated with sensitive data.
- Activities involving protected material.
Security teams can select View details or similar drill-down options to inspect individual activities in Activity Explorer. The ability to view prompts, responses, and referenced files is controlled by Microsoft Purview permissions and role groups. For example, viewing content details may require membership in an appropriate Content Explorer or related role group.
Why activity-level investigation matters
A dashboard may show that sensitive AI interactions are increasing, but it may not explain:
- Which application is involved.
- Which users are involved.
- What type of sensitive data was used.
- Whether the activity was accidental or intentional.
- Whether a policy violation occurred.
- Which control should be applied.
Activity-level investigation provides the context needed to determine whether the issue requires:
- User education.
- A sensitivity label.
- A DLP policy.
- An Insider Risk Management policy.
- Access remediation.
- An investigation.
- A change to the approved AI application list.
Relationship between DSPM and other Microsoft Purview capabilities
DSPM is not a replacement for all other security and compliance solutions. It provides visibility and recommendations while working with other Microsoft Purview capabilities.
| Capability | Primary purpose in AI risk management |
|---|---|
| DSPM | Discover and assess data-security risks and provide recommendations |
| Microsoft Purview Audit | Record and investigate supported AI and user activities |
| Data classification | Identify sensitive information in supported content and interactions |
| Sensitivity labels | Classify and protect sensitive content |
| Data Loss Prevention | Detect, warn, or block inappropriate sharing of sensitive data |
| Insider Risk Management | Identify potentially risky user behavior |
| Communication Compliance | Detect inappropriate or policy-violating communications |
| eDiscovery | Search and preserve supported AI interaction content for investigations or legal matters |
| Data Lifecycle Management | Retain or delete content according to organizational requirements |
For example, DSPM might identify that users are frequently submitting sensitive information to an AI application. A security team could then use the finding to create a DLP policy, configure an Insider Risk Management policy, or improve sensitivity-label coverage.
Microsoft Copilot and permission-based access
Microsoft 365 Copilot uses the permissions available to the user. This means that an organization should not assume that deploying Copilot automatically creates a new permission model or bypasses SharePoint and Microsoft 365 access controls.
However, existing permissions may be too broad.
For example:
- A user may belong to a large group that has access to a confidential site.
- A document may be shared with everyone in the organization.
- A file may be available through an overly broad sharing link.
- A site may contain outdated information that is still accessible.
- A sensitive document may not have an appropriate label or protection.
In these cases, Copilot may make the information more discoverable, but the underlying problem is usually the organization’s data-access or governance configuration. DSPM and SharePoint data-access governance capabilities help identify these issues.
Important distinction: DSPM versus SharePoint data-access governance
Both DSPM and SharePoint data-access governance can help identify exposure risks, but they serve different purposes.
DSPM
DSPM focuses on the broader data-security posture, including:
- Sensitive data.
- AI interactions.
- Risk trends.
- Recommendations.
- Data exposure.
- User and application activity.
- AI-related security objectives.
SharePoint data-access governance
SharePoint data-access governance reports focus more directly on SharePoint and OneDrive permissions, sharing links, and access patterns.
Examples include:
- Site permissions across the organization.
- Site permissions for individual users.
- Sites or files shared with everyone in the organization.
- Sites or files shared with everyone except external users.
- Sharing-link activity.
- Sensitivity labels applied to files.
- Site-access reviews.
These reports can help identify the underlying access configuration that may cause sensitive data to be exposed to Copilot or other authorized users.
Recommended process for identifying AI-related data risks
Step 1: Identify approved AI applications
Create an inventory of:
- Microsoft 365 Copilot.
- Microsoft Copilot Studio agents.
- Microsoft Security Copilot.
- Enterprise AI applications.
- AI applications connected through Microsoft Entra.
- AI applications built with Microsoft Foundry.
- Approved third-party AI applications.
- Unapproved or consumer AI applications.
This inventory helps distinguish expected business use from potentially unauthorized AI usage.
Step 2: Identify sensitive data
Review the organization’s use of:
- Sensitive information types.
- Sensitivity labels.
- Trainable classifiers.
- Confidentiality classifications.
- DLP policies.
- Data-retention requirements.
AI-risk detection is more effective when sensitive data has already been classified consistently.
Step 3: Configure the required collection and auditing
Verify that:
- Microsoft Purview Audit is enabled.
- Required AI interaction collection policies are configured.
- Devices are onboarded where required.
- Network integrations are configured for supported third-party AI scenarios.
- Required licensing and billing prerequisites are satisfied.
Step 4: Review DSPM dashboards and recommendations
Look for:
- Sensitive AI interactions.
- Risky AI usage.
- High-risk applications.
- Repeated policy violations.
- Users interacting with sensitive data.
- AI activities involving protected material.
- Recommendations for improving security posture.
Step 5: Investigate individual activities
Use available drill-down capabilities to determine:
- Which user performed the activity.
- Which AI application was used.
- What data was involved.
- Whether the data was sensitive.
- Whether the activity was permitted.
- Whether the activity was accidental or suspicious.
- Which policy or control should be applied.
Step 6: Remediate the underlying risk
Possible actions include:
- Applying or improving sensitivity labels.
- Reducing SharePoint permissions.
- Removing unnecessary sharing links.
- Restricting access to sensitive sites.
- Creating DLP policies.
- Creating Insider Risk Management policies.
- Blocking or restricting unapproved AI applications.
- Educating users.
- Archiving or deleting unnecessary content.
- Reviewing AI agent permissions and data sources.
Step 7: Monitor continuously
AI usage and data exposure change over time. Organizations should regularly review:
- New AI applications.
- New agents.
- Changes to permissions.
- New sensitive-data findings.
- Risk trends.
- DLP incidents.
- Insider Risk alerts.
- Newly overshared content.
- Changes in AI application usage.
Licensing and permissions considerations
The available DSPM capabilities depend on the organization’s licensing, tenant configuration, application support, and assigned administrative roles.
Some capabilities may require:
- Microsoft Purview licensing.
- Microsoft 365 licensing.
- Microsoft Defender licensing.
- Pay-as-you-go billing.
- Appropriate Microsoft Entra or Microsoft Purview roles.
- Device onboarding.
- Audit configuration.
- AI interaction collection policies.
- Supported application integrations.
For example, some AI investigations require additional permissions before administrators can view prompt and response text or referenced files. Administrators should follow least-privilege principles and assign only the roles necessary for the investigation or compliance task.
Common exam traps
Trap 1: Assuming Copilot bypasses permissions
Copilot generally works with the permissions available to the user. The issue may be that the user already has excessive access.
Trap 2: Confusing DSPM with DLP
DSPM primarily helps discover, assess, and understand risks. DLP is used to enforce policies that can warn, block, or restrict certain data-sharing activities.
Trap 3: Confusing Audit with DSPM
Audit provides activity records. DSPM provides broader risk analysis, dashboards, assessments, and recommendations.
Trap 4: Assuming every AI application is monitored automatically
Coverage depends on the application, integration, licensing, configuration, and collection policies.
Trap 5: Assuming all prompt and response content is visible to every administrator
Viewing detailed content is controlled by permissions and role groups.
Trap 6: Treating every risk finding as proof of malicious behavior
A DSPM finding may indicate potential exposure or risky activity. It requires investigation and context before a conclusion is reached.
Trap 7: Confusing sensitivity labels with permissions
A sensitivity label can classify and protect content, but labeling alone does not necessarily replace SharePoint permissions or correct an incorrectly configured access group.
Trap 8: Ignoring third-party AI applications
AI risks can exist outside Microsoft Copilot. Microsoft Purview can provide supported visibility into certain enterprise and third-party AI scenarios, but coverage is not universal.
Summary
Microsoft Purview DSPM helps organizations identify and manage risks associated with Microsoft Copilot and other AI applications.
The most important concepts are:
- AI can amplify existing data oversharing.
- Microsoft 365 Copilot generally respects existing permissions.
- DSPM provides centralized visibility into data-security risks.
- DSPM for AI can identify sensitive AI interactions and risky usage.
- Microsoft Purview Audit provides activity records.
- Data classification identifies sensitive information.
- Sensitivity labels classify and protect content.
- DLP can enforce data-sharing restrictions.
- Insider Risk Management helps identify potentially risky behavior.
- Activity Explorer supports detailed investigation when the administrator has the required permissions.
- AI-risk monitoring requires appropriate configuration, licensing, and collection policies.
- DSPM findings should lead to investigation, remediation, and continuous monitoring.
Practice Exam Questions
Question 1
An organization wants to identify whether users are submitting sensitive information to Microsoft Copilot and other supported AI applications. Which Microsoft Purview capability is the best starting point?
A. Microsoft Purview Data Lifecycle Management
B. Microsoft Purview Communication Compliance
C. Microsoft Purview Records Management
D. Microsoft Purview Data Security Posture Management
Answer: D
Explanation: Microsoft Purview DSPM provides dashboards, assessments, and recommendations for identifying data-security risks, including sensitive information involved in AI interactions. Data Lifecycle Management focuses on retention and deletion, while Communication Compliance focuses primarily on inappropriate communications.
Question 2
A user asks Microsoft 365 Copilot to summarize a confidential document. The user can access the document because it is shared with a large Microsoft 365 group. What is the most likely underlying security issue?
A. Copilot has bypassed SharePoint permissions.
B. Copilot has trained its model on the document.
C. Copilot has disabled the document’s sensitivity label.
D. The document may be overshared through existing permissions.
Answer: D
Explanation: Microsoft 365 Copilot generally respects the user’s existing permissions. The likely problem is that the document is accessible to more users than necessary through the group’s permissions.
Question 3
An administrator needs to investigate individual AI activities and, where authorized, view the prompts, responses, and referenced files. Which capability should the administrator use?
A. Activity Explorer in Microsoft Purview
B. Azure Resource Graph
C. Azure Policy compliance results
D. Microsoft Defender for Containers
Answer: A
Explanation: Activity Explorer can provide detailed information about supported AI activities. Viewing prompt, response, and referenced-file content requires the appropriate Microsoft Purview permissions and role-group membership.
Question 4
Which Microsoft Purview capability is primarily responsible for identifying sensitive information in AI prompts and responses?
A. Microsoft Purview eDiscovery
B. Microsoft Purview Data Lifecycle Management
C. Microsoft Purview data classification
D. Microsoft Purview resource locks
Answer: C
Explanation: Data classification uses sensitive information types, trainable classifiers, and other classification mechanisms to identify sensitive information in supported AI interactions.
Question 5
An organization wants to capture supported Copilot prompts and responses so they can be analyzed for security and compliance purposes. What should the organization configure?
A. An Azure subscription lock
B. A Microsoft Entra access package
C. A network security group
D. An appropriate Microsoft Purview AI interaction collection policy
Answer: D
Explanation: Some AI interaction scenarios require collection policies to capture prompts and responses. The collected information can then be used by supported Purview solutions for investigation, compliance, and risk analysis.
Question 6
A security team wants to detect potentially risky behavior such as prompt injection attempts and attempts to access protected material. Which Microsoft Purview capability is most relevant?
A. Data Lifecycle Management
B. Insider Risk Management
C. Records Management
D. Information Barriers only
Answer: B
Explanation: Microsoft Purview Insider Risk Management can use AI-related signals and a risky AI usage policy template to help identify potentially risky or suspicious user behavior.
Question 7
Which statement best describes the relationship between DSPM and Data Loss Prevention?
A. DSPM replaces all DLP policies.
B. DLP identifies all AI applications, while DSPM blocks them.
C. DSPM helps identify risks and recommend actions, while DLP can enforce data-sharing controls.
D. DSPM and DLP are identical capabilities with different names.
Answer: C
Explanation: DSPM provides visibility, assessments, analytics, and recommendations. DLP is used to detect, warn about, or block certain activities involving sensitive information.
Question 8
An organization wants to investigate whether employees are using consumer AI websites and submitting sensitive company information. Which combination may be required for supported third-party AI scenarios?
A. Microsoft Purview capabilities, appropriate collection or network integration, and device onboarding where required
B. Azure Bastion and Azure Firewall only
C. Azure Backup and resource locks
D. Microsoft Defender for Containers and Azure Kubernetes Service
Answer: A
Explanation: Visibility into third-party AI usage depends on supported integrations and configuration. Some scenarios require network-based discovery, the Microsoft Purview browser extension, and onboarded devices.
Question 9
An administrator sees an increase in sensitive AI interactions in a DSPM dashboard. What should the administrator do next?
A. Immediately delete all AI applications.
B. Investigate the detailed activities and determine the appropriate remediation.
C. Disable Microsoft Entra ID for all users.
D. Remove all sensitivity labels.
Answer: B
Explanation: A dashboard finding is an indicator of potential risk, not necessarily proof of malicious activity. The administrator should investigate the affected users, applications, data, and circumstances before selecting a remediation.
Question 10
Which statement about viewing AI prompts and responses in Microsoft Purview is correct?
A. Every Microsoft 365 administrator can automatically view all prompt and response content.
B. Prompt and response content is always publicly visible to all security analysts.
C. Prompt and response content can be viewed only by the AI application owner.
D. Access to detailed content is controlled by Microsoft Purview permissions and applicable role groups.
Answer: D
Explanation: Detailed AI interaction content is protected by role-based access controls. Administrators need the appropriate permissions and role-group membership to view prompts, responses, and referenced files where supported.
Go to the SC-500 Exam Prep Hub main page
