Discover and Manage AI activity by using DSPM for AI (Part 1) (AB-900 Exam Prep)

This post is a part of the AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals Exam Prep Hub.
This topic falls under these sections:
Understand data protection and governance tasks for Microsoft 365 and Copilot (35–40%)
   --> Identify data protection and governance risks for Microsoft 365 and Copilot
      --> Discover and Manage AI activity by using DSPM for AI


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

As organizations increasingly adopt AI-powered tools such as Microsoft 365 Copilot, administrators face a new challenge: understanding how AI accesses, processes, and exposes organizational data. Traditional security tools focus on protecting users, devices, and data, but AI introduces new considerations. AI assistants can summarize documents, answer questions, generate reports, and analyze data from across an organization’s Microsoft 365 environment. If permissions are overly broad or sensitive information is poorly governed, AI can unintentionally surface information to users who already have access but should not necessarily see it in a summarized or easily discoverable form.

To address these challenges, Microsoft introduced Microsoft Purview Data Security Posture Management (DSPM) for AI, a solution designed to help organizations discover AI usage, identify potential security risks, understand data exposure, and strengthen governance before and during AI adoption.

For the AB-900 exam, you are not expected to configure DSPM for AI. Instead, you should understand:

  • What DSPM for AI is
  • Why organizations use it
  • How it discovers AI activity
  • How it helps identify risks
  • How it integrates with Microsoft Purview
  • The types of recommendations it provides

What Is Microsoft Purview DSPM for AI?

Microsoft Purview DSPM for AI is a governance and security solution that provides visibility into how artificial intelligence applications interact with organizational data.

Rather than preventing AI usage, DSPM for AI helps administrators answer important questions such as:

  • Which AI applications are employees using?
  • What sensitive information is being accessed?
  • Are AI tools exposing confidential content?
  • Are permissions overly broad?
  • Are Microsoft 365 Copilot users accessing highly sensitive data?
  • Where should security controls be strengthened?

Think of DSPM for AI as a risk discovery and governance solution specifically designed for AI workloads.


What Does “Data Security Posture Management” Mean?

The term Data Security Posture Management (DSPM) refers to continuously evaluating an organization’s data environment to identify security weaknesses before they become incidents.

DSPM focuses on questions such as:

  • Where is sensitive data stored?
  • Who has access?
  • Is the data properly classified?
  • Are security policies protecting it?
  • Could AI expose it more easily?

When AI is introduced, DSPM expands these questions to include:

  • Which AI tools are interacting with company data?
  • Which users are using AI?
  • What content is AI accessing?
  • Could AI reveal confidential information?
  • Are there oversharing risks?

Rather than reacting after a breach occurs, DSPM promotes proactive risk management.


Why Organizations Need DSPM for AI

Many organizations begin using AI before fully understanding their existing data environment.

Common issues include:

  • Excessive file permissions
  • Sensitive documents shared too broadly
  • Unlabeled confidential data
  • Legacy SharePoint permissions
  • Public Teams channels
  • Old collaboration sites
  • Inactive security policies

Without visibility into these issues, AI may legally retrieve information based on existing permissions—even though administrators were unaware those permissions existed.

DSPM for AI helps organizations discover these weaknesses before they become security problems.


Core Capabilities of DSPM for AI

Microsoft Purview DSPM for AI provides several major capabilities.

1. Discover AI Usage

DSPM identifies where AI is being used throughout the organization.

Examples include:

  • Microsoft 365 Copilot
  • Microsoft Copilot Chat
  • AI-enabled Microsoft services
  • Supported third-party AI applications

Administrators gain visibility into:

  • AI adoption
  • AI usage trends
  • Departments using AI
  • Types of AI interactions

This helps organizations understand how quickly AI is being adopted.


2. Discover Sensitive Data Exposure

DSPM evaluates whether AI has access to sensitive organizational data.

Examples include:

  • Financial reports
  • HR records
  • Customer information
  • Legal documents
  • Intellectual property
  • Healthcare information
  • Personally identifiable information (PII)

The solution identifies locations where sensitive information may be accessible through AI.


3. Identify Oversharing Risks

One of the most important concepts for the AB-900 exam is oversharing.

Oversharing occurs when users have legitimate permissions to data that administrators did not intend them to have.

For example:

  • A confidential SharePoint library inherits incorrect permissions.
  • Hundreds of employees can read executive documents.
  • Microsoft 365 Copilot can summarize those documents for anyone with existing access.

The problem is not Copilot.

The problem is the underlying permissions.

DSPM helps identify these situations.


4. Inventory AI Applications

Organizations often have many AI applications in use.

DSPM helps administrators discover:

  • Approved AI tools
  • Newly adopted AI tools
  • Shadow AI applications
  • AI usage across departments

This visibility supports governance decisions.


5. Monitor AI Interactions

DSPM can provide insights into how AI interacts with organizational content.

Examples include:

  • Documents accessed
  • Sensitive data locations
  • AI usage frequency
  • Common AI workflows
  • Business units using AI

Administrators gain a better understanding of AI usage patterns without reading users’ private prompts or monitoring employee productivity.


How DSPM for AI Discovers AI Activity

DSPM analyzes signals across Microsoft 365 services to understand AI usage.

These signals may include:

  • User activity
  • Data access
  • File classifications
  • Permissions
  • Labels
  • Microsoft Graph relationships
  • Microsoft Purview metadata

Rather than simply counting AI prompts, DSPM builds a broader picture of how AI interacts with organizational data.


Microsoft Graph’s Role

One important concept for the AB-900 exam is understanding the relationship between Microsoft Graph and DSPM.

Microsoft Graph acts as the intelligence layer connecting Microsoft 365 services.

DSPM uses Microsoft Graph signals to understand:

  • Which files users can access
  • Collaboration relationships
  • SharePoint permissions
  • Teams memberships
  • OneDrive access
  • Email relationships
  • Microsoft 365 activity

This allows DSPM to identify situations where AI could expose sensitive information because users already possess excessive permissions.


Data Sources Evaluated by DSPM

DSPM evaluates multiple Microsoft 365 services.

Examples include:

SharePoint Online

  • Sensitive document libraries
  • Overshared sites
  • Confidential folders
  • File permissions

OneDrive

  • Shared personal files
  • External sharing
  • Sensitive documents
  • Personal work data

Microsoft Teams

  • Shared files
  • Team memberships
  • Collaboration spaces
  • Shared conversations

Exchange Online

  • Email data
  • Mailbox access
  • Shared mailboxes
  • Sensitive communications

Microsoft 365 Copilot

DSPM evaluates how Copilot interacts with organizational data by examining:

  • Available permissions
  • Data sources
  • Sensitive information exposure
  • Governance controls

Types of Risks DSPM Can Identify

DSPM helps identify a variety of AI-related risks.

Overshared Content

Examples include:

  • Everyone can access HR documents.
  • Finance reports are visible to the entire company.
  • Sensitive SharePoint sites inherit incorrect permissions.

Sensitive Information Exposure

Examples include:

  • Credit card numbers
  • Passport numbers
  • Social Security numbers
  • Customer records
  • Healthcare data
  • Intellectual property

Excessive Permissions

Users frequently accumulate permissions over time.

DSPM identifies situations where users have access to more information than necessary.

This supports the principle of least privilege.


Unclassified Sensitive Data

Organizations often possess sensitive information that has never been classified.

DSPM can identify repositories containing:

  • Unlabeled confidential documents
  • Sensitive spreadsheets
  • Legal contracts
  • Financial reports

This allows administrators to apply Microsoft Purview Information Protection labels.


Shadow AI

Shadow AI refers to employees using AI tools that have not been approved by the organization.

Examples might include:

  • Public AI chat services
  • AI writing assistants
  • AI coding assistants
  • AI document summarizers

DSPM helps organizations understand where unmanaged AI usage exists so appropriate governance decisions can be made.


Key Exam Tips

For the AB-900 exam, remember these important points:

  • DSPM for AI is primarily a visibility and governance solution, not an AI blocking solution.
  • It helps organizations discover, understand, and reduce AI-related risks.
  • It identifies oversharing, sensitive data exposure, and permission issues.
  • DSPM works closely with other Microsoft Purview solutions to improve an organization’s overall AI security posture.
  • Microsoft Graph provides much of the contextual information that enables DSPM to evaluate AI data access and potential risks.
  • The goal is not to restrict productive AI use, but to ensure that AI operates within an organization’s existing security, compliance, and governance framework.

Go to Part 2 of this topic.


Go to the AB-900 Exam Prep Hub main page

Leave a comment