Skip to content

Commit 6ff142c

Browse files
committed
update module
1 parent 8a69d10 commit 6ff142c

14 files changed

Lines changed: 150 additions & 14 deletions
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
### YamlMime:ModuleUnit### YamlMime:ModuleUnit
2+
uid: learn.describe-purview-data-solutions.describe-data-security-posture-management
3+
title: Describe Data Security Posture Management
4+
metadata:
5+
title: Describe Data Security Posture Management
6+
description: "Describe Data Security Posture Management in Microsoft Purview."
7+
ms.date: 04/01/2026
8+
author: wwlpublish
9+
ms.author: ceperezb
10+
ms.topic: unit
11+
durationInMinutes: 10
12+
content: |
13+
[!include[](includes/6a-describe-data-security-posture-management.md)]

learn-pr/wwl-sci/describe-purview-data-solutions/7-knowledge-check.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -51,18 +51,6 @@ quiz:
5151
isCorrect: false
5252
explanation: "Incorrect. Device availability and reliability are infrastructure concerns handled outside of insider risk management. Insider risk management focuses on detecting and responding to risky or malicious activities by people within the organization."
5353

54-
- content: "An organization has a DLP policy that detects sensitive financial information. A user attempts to share a sensitive spreadsheet via Microsoft Teams. What action can the DLP policy take?"
55-
choices:
56-
- content: "Automatically delete the file from the user's OneDrive."
57-
isCorrect: false
58-
explanation: "Incorrect. DLP doesn't automatically delete files. Instead, DLP can block the sharing, show the user a policy tip explaining why the action was prevented, and optionally allow the user to override the block with a justification."
59-
- content: "Show the user a policy tip and block the sharing."
60-
isCorrect: true
61-
explanation: "Correct. DLP policies can display a policy tip that warns the user their action may violate policy, and can block the sharing of the sensitive item in Teams."
62-
- content: "Move the file to a quarantine location and notify the user's manager."
63-
isCorrect: false
64-
explanation: "Incorrect. Moving content to a quarantine location is a protective action that applies to data at rest, not to active sharing in Teams chat. For Teams chat, DLP can block the sharing and show a policy tip to the user."
65-
6654
- content: "An organization wants its DLP controls to automatically tighten for users identified as high-risk by Insider Risk Management, without requiring admins to manually update policies. Which capability should the organization configure?"
6755
choices:
6856
- content: "Sensitivity label policies."
@@ -74,3 +62,15 @@ quiz:
7462
- content: "Trainable classifiers."
7563
isCorrect: false
7664
explanation: "Incorrect. Trainable classifiers are used to identify types of content for classification. They don't adjust DLP controls based on insider risk. Adaptive protection is the feature that connects insider risk levels to DLP and other protective controls."
65+
66+
- content: "An organization needs a unified view of its sensitive data risks across Microsoft 365, Azure, and third-party platforms like Google Cloud Platform. The organization also wants to monitor how AI apps interact with sensitive data. Which Microsoft Purview solution provides this capability?"
67+
choices:
68+
- content: "Content explorer."
69+
isCorrect: false
70+
explanation: "Incorrect. Content explorer provides a snapshot of classified items in your organization, but it doesn't provide unified posture management across Microsoft and non-Microsoft environments or AI observability. Data Security Posture Management provides those capabilities."
71+
- content: "Data Security Posture Management."
72+
isCorrect: true
73+
explanation: "Correct. Data Security Posture Management provides unified visibility into data risks across Microsoft 365, Azure, Fabric, and third-party SaaS platforms. It includes AI observability dashboards that monitor how AI apps and agents interact with sensitive data."
74+
- content: "Insider Risk Management."
75+
isCorrect: false
76+
explanation: "Incorrect. Insider Risk Management focuses on detecting, investigating, and acting on risky activities by users within the organization. Data Security Posture Management is the solution that provides a unified view of data risks across your entire digital estate, including AI interactions."
Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
Microsoft Purview is a comprehensive set of integrated data security, data governance, and data compliance solutions that help organizations secure and govern their entire data estate while meeting compliance requirements. This module focuses on Microsoft Purview data security solutions.
22

3-
Microsoft Purview helps organizations protect sensitive data through information protection, data loss prevention, and insider risk management—working together to secure data across its lifecycle, wherever it lives. Adaptive protection brings these solutions together by automatically applying the right level of controls based on each user's current risk level.
3+
Microsoft Purview helps organizations protect sensitive data through information protection, data loss prevention, and insider risk management—working together to secure data across its lifecycle, wherever it lives. Adaptive protection brings these solutions together by automatically applying the right level of controls based on each user's current risk level. Data Security Posture Management provides a unified view of your organization's data security landscape across Microsoft and non-Microsoft environments, including visibility into AI interactions.
44

55
After completing this module, you're able to:
66

@@ -9,3 +9,4 @@ After completing this module, you're able to:
99
- Describe how Microsoft Purview Data Loss Prevention helps organizations prevent the inappropriate sharing of sensitive data.
1010
- Describe how Microsoft Purview Insider Risk Management helps minimize internal risks.
1111
- Describe how adaptive protection in Microsoft Purview dynamically applies data protection controls based on insider risk levels.
12+
- Describe how Data Security Posture Management in Microsoft Purview provides unified visibility into data risks across Microsoft and non-Microsoft environments.

learn-pr/wwl-sci/describe-purview-data-solutions/includes/2-identify-sensitive-data.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,12 @@ Trainable classifiers can be used as conditions for auto-labeling with sensitivi
4444
> [!NOTE]
4545
> Classifiers only work with items that aren't encrypted.
4646
47+
## Data classification and AI interactions
48+
49+
Data classification plays an important role in securing AI interactions. Sensitive information types and trainable classifiers can identify sensitive data in user prompts and responses when users interact with AI apps like Microsoft 365 Copilot. For example, if a user pastes credit card numbers or health records into an AI prompt, the same SITs that protect those items in email and documents can detect them in the AI interaction.
50+
51+
The resulting classification information surfaces in Microsoft Purview reports and in Activity explorer within Data Security Posture Management (DSPM), where admins can review AI-related activities alongside traditional data classification insights. This visibility helps organizations understand how sensitive data flows through AI interactions and whether additional protection policies are needed.
52+
4753
## Understand and explore the data
4854

4955
Data classification can involve large numbers of documents and emails. To help administrators derive insights and understanding, the **Explorers** section under Information Protection in the Microsoft Purview portal provides two tools for reviewing classified content at a glance.

learn-pr/wwl-sci/describe-purview-data-solutions/includes/4-describe-data-loss-prevention.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,12 @@ The user can then find out more about why their message was blocked by selecting
6767

6868
DLP policies applied to Microsoft 365 services, including Microsoft Teams, can help users across organizations to collaborate securely and in a way that's in line with compliance requirements.
6969

70+
### Data loss prevention and AI interactions
71+
72+
DLP capabilities extend to AI interactions to help prevent sensitive data from being shared through generative AI apps. Windows devices onboarded to Microsoft Purview can be configured with endpoint DLP policies that warn or block users from sharing sensitive information with third-party generative AI sites accessed through a browser. For example, a DLP policy can prevent a user from pasting credit card numbers into ChatGPT, or display a warning that the user can override with a justification.
73+
74+
This protection helps organizations adopt AI tools while maintaining control over sensitive data. DLP policies for AI interactions work alongside the existing DLP capabilities for email, documents, and chat—providing a consistent layer of data protection across all the ways users work with sensitive information.
75+
7076
## Integration with Microsoft Security Copilot
7177

7278
Microsoft Purview Data Loss Prevention supports integration with Microsoft Security Copilot, through the standalone and embedded experiences.

learn-pr/wwl-sci/describe-purview-data-solutions/includes/5-describe-insider-risk-management.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,10 @@ Insider risk management addresses these common scenarios:
4949
- **Risky user behavior**: Employment stressor events—such as poor performance reviews or demotions—can trigger risky behavior. Policies use HR data connectors to bring affected users into scope and score related risk indicators.
5050
- **Forensic evidence**: Insider risk management supports visual evidence capturing for online and offline devices, giving investigators screen captures to better assess and respond to potentially risky activities.
5151

52+
### Insider risk management and AI interactions
53+
54+
As AI tools become part of everyday work, new risks emerge from inappropriate or unauthorized AI usage. Insider Risk Management includes a **Risky AI usage** policy template that detects activities such as prompt injection attacks, accessing protected materials, and sending sensitive data to AI services outside organizational controls. Insights from these signals are integrated into Microsoft Defender XDR, providing a comprehensive view of AI-related risks alongside other insider threats.
55+
5256
### Integration with Microsoft Security Copilot
5357

5458
Microsoft Purview Insider Risk Management supports integration with Microsoft Security Copilot, through the standalone and embedded experiences.

0 commit comments

Comments
 (0)