9.1 Purview DSPM for AI and Data Overexposure

Key Takeaways

  • Microsoft Purview Data Security Posture Management (DSPM) for AI is the central Purview experience for discovering AI usage risks, SharePoint oversharing, and sensitive data flowing through Copilot and AI apps.
  • Copilot and agents ground answers on content users can already access—overexposed SharePoint sites turn ordinary permissions into AI-amplified data leakage.
  • Default weekly data risk assessments scan top-usage SharePoint sites for oversharing; custom assessments target specific sites or user sets when needed.
  • Remediation patterns include sensitivity labels that block Copilot summarization, SharePoint Restricted Content Discovery, auto-labeling, retention, DLP for Copilot interactions, and site access reviews.
  • SC-500 trap: DSPM for AI is posture and recommendation-driven—it does not replace Conditional Access, Entra Agent ID, or Defender for AI runtime threat protection.
Last updated: July 2026

9.1 Purview DSPM for AI and Data Overexposure

Quick Answer: Microsoft Purview Data Security Posture Management (DSPM) for AI is the Purview hub for AI data security. Use it to find SharePoint overexposure, review Copilot and AI app risks, and remediate with labels, DLP, Restricted Content Discovery, retention, and access reviews—because Copilot surfaces whatever users can already open.

Security for AI is the clearest differentiator of SC-500 versus classic AZ-500. Under Secure compute → Implement security for AI, Microsoft explicitly measures your ability to identify overexposure of data in SharePoint and identify risks related to Microsoft Copilot and AI apps by using Microsoft Purview DSPM. This section is the data-plane foundation for that skill area.

Why AI turns “already shared” into a security incident

Microsoft 365 Copilot and many agents ground responses on enterprise content the signed-in user is allowed to read—SharePoint libraries, OneDrive files, Teams/chat context, email, and other connected sources depending on the experience. That design is productive and dangerous:

Pre-AI worldWith Copilot / agents
User must know the file path and open itNatural language can summarize, extract, and recombine many files in seconds
Oversharing might stay undiscovered for monthsOne prompt can surface salary tables, M&A drafts, or customer PII that lived in a broadly shared site
“Anyone with the link” was a collaboration convenienceAnonymous or organization-wide links become high-velocity leakage paths
Shadow AI (ChatGPT, Gemini sites) was hard to inventoryDSPM for AI and related policies help discover visits and sensitive info sent to third-party AI

Exam principle: Copilot rarely “hacks” ACLs. It respects existing access. Your job is to fix overpermissioned content and weak labels before AI amplifies them.

What Microsoft Purview DSPM for AI is

Microsoft Purview Data Security Posture Management for AI (often shortened to DSPM for AI; formerly referred to in some materials as an AI Hub-style experience) lives in the Microsoft Purview portal. It is a central management location to help you:

  • Gain insights and analytics into AI activity (Copilot experiences, agents, enterprise AI apps, and other AI apps).
  • Activate ready-to-use / one-click policies that protect data and help prevent data loss in AI prompts.
  • Run and review data risk assessments for oversharing (especially SharePoint).
  • Track recommendations, reports, policies, Apps and agents, and Activity explorer.

Access note: You need an account with appropriate compliance management permissions—for example membership in a role such as Microsoft Entra Compliance Administrator (or equivalent Purview compliance roles). Exact role names and licensing can vary by tenant SKU; for the exam, remember the portal surface is Purview, not Azure portal Resource Manager alone.

Microsoft has also evolved the DSPM experience (classic DSPM for AI versus a newer unified DSPM experience with broader AI apps/agents coverage). For SC-500, focus on capabilities and remediation patterns, not marketing names of intermediate portal skins.

Identify overexposure of data in SharePoint

Default weekly data risk assessment

DSPM for AI automatically runs a weekly data risk assessment for the top 100 SharePoint sites based on usage in the organization. No separate “turn on scanning” step is required for that default assessment. Results help you answer:

  • How many items look potentially overshared?
  • How many items contain sensitive information types (SITs)?
  • How many items use risky sharing links (for example anyone / anonymous patterns)?
  • Which sites drive the highest risk for Microsoft 365 Copilot, agents, and Copilot Chat grounding?

Custom assessments

You can create custom data risk assessments (preview capabilities have been documented) to target different users or specific sites beyond the default top-100 set. After a custom assessment completes, results may not continuously refresh—Microsoft documentation notes waiting periods (often on the order of 48 hours to see results) and that rerunning/duplicating assessments is how you recheck after remediations. Treat exact timing as product-documented operational detail, not a trick number to invent on the exam.

Item-level oversharing signals (Microsoft 365)

Item-level scanning and remediation for potentially overshared items is focused on Microsoft 365, currently with strong emphasis on SharePoint sites. Items may be flagged when they have sharing links for external or anonymous users, and views commonly show any applied sensitivity label and the owner of each item.

Fabric workspaces

DSPM for AI also supports Fabric data risk assessments on a separate tab after a one-time Entra app / Fabric admin portal configuration. Fabric is secondary to SharePoint on most SC-500 SharePoint-overexposure questions, but know that oversharing is not only a SharePoint problem when Fabric lakehouses, warehouses, and reports feed AI scenarios.

Risks related to Microsoft Copilot and AI apps

DSPM for AI groups risk visibility across categories such as:

CategoryExamples of what you investigate
Copilot experiences and agentsMicrosoft 365 Copilot, Copilot Studio-related interactions, agent activity
Enterprise AI appsRegistered enterprise AI (for example ChatGPT Enterprise workspace patterns when connected)
Other AI appsSupported third-party generative AI sites (Gemini, consumer ChatGPT-class destinations, etc.)

Sensitive data Copilot might surface

Think in concrete business content types—not abstract “data leakage”:

  • HR and compensation files on open team sites
  • Legal / M&A drafts shared “with everyone except external users” too broadly
  • Customer PII / regulated health or financial records without labels or DLP
  • Source code, API keys, or infrastructure diagrams pasted into SharePoint wikis
  • Unlabeled sensitive SITs that auto-labeling never covered

Copilot can summarize these into chat responses, tables, or drafts. Even when a user is “allowed” by ACL, the organization may still violate need-to-know, regulatory retention, or ethical boundaries. DSPM recommendations therefore pair access hygiene with Purview Information Protection and DLP.

Apps and agents + Activity explorer

  • Apps and agents dashboards help inventory AI apps/agents, sensitive data they accessed, and which Purview policies protect them.
  • Activity explorer shows detailed events (AI interaction, sensitive info types, AI website visit, files referenced). With correct permissions, prompts and responses can appear in AI interaction events—critical for investigations and for knowing which web queries occurred.

Recommendations and one-click policies

From Overview → Recommendations (and related one-click policy activation), DSPM for AI commonly steers you toward outcomes such as:

  1. Protect data from potential oversharing using assessment results before/after Copilot rollout.
  2. Create or publish sensitivity labels if the tenant lacks a baseline label set.
  3. Protect items with sensitivity labels from Microsoft 365 Copilot and agent processing—select labels that prevent Copilot/agents from summarizing labeled content (implemented via Microsoft Purview DLP patterns for Copilot locations).
  4. Detect risky interactions in AI apps (Insider Risk Management risky AI usage style detections for risky prompts/responses).
  5. Secure interactions for additional Copilot experiences (for example capturing prompts/responses for Copilot in Fabric or Security Copilot where default audit alone may not capture full content).
  6. Extend insights for third-party AI (browser extension, device onboarding, network data security integrations where licensed).

Operational tip: Allow time (Microsoft often cites at least ~24 hours) for newly activated default policies to populate reports. Do not expect instant heatmaps after clicking Apply.

Remediation patterns (memorize the menu)

When DSPM flags oversharing, remediation is multi-tool. Match the control to the risk:

Risk patternPrimary remediationWhy it works for AI
Broad site permissions / stale membershipSharePoint site access review / data access governance reportsShrinks who Copilot can ground for
Anyone/anonymous sharing linksRemove sharing link; reset to least-privilege link type; default sharing-link via labelsStops anonymous retrieval paths
Sensitive unlabeled filesAuto-labeling policies (Information Protection)Labels enable downstream DLP and Copilot restrictions
Specific high-sensitivity content must not be summarizedDLP: restrict by label so Copilot/agents cannot process selected labelsDirect control on Copilot processing
Entire site must not be discovered by CopilotSharePoint Restricted Content Discovery (restrict all items / exempt sites from discovery)Hard exclusion when site is toxic for AI grounding
Old unused content still broadly availableRetention policies (for example delete content not accessed in years)Shrinks attack and overshare surface
User pastes secrets into promptsDLP for Copilot interactions / prompt-level protections (often start in simulation mode)Stops sensitive SITs in prompts/web reasoning paths
Risky employee AI behaviorInsider Risk Management / Communication Compliance templatesPeople risk, not just file ACLs

Scenario: pre-Copilot rollout assessment

Contoso plans Microsoft 365 Copilot. Security runs DSPM for AI default assessment and finds Finance SharePoint with hundreds of items shared via Anyone links, many matching credit card and SSN SITs, few sensitivity labels. Correct sequence:

  1. Prioritize Finance sites in DSPM details (Identify / Protect / Monitor tabs).
  2. Remove or tighten anonymous links on highest-risk libraries; notify owners carefully.
  3. Deploy auto-labeling for finance SITs.
  4. Create DLP so labels such as Highly Confidential are blocked from Copilot summarization.
  5. Consider Restricted Content Discovery for legacy dump sites until cleaned.
  6. Run site access reviews to remove departed users and “Everyone” style groups.
  7. Reassess after remediation before expanding Copilot licenses.

This is a classic SC-500 “pick the Purview path” story—not “turn on Azure Firewall.”

What DSPM for AI is not

ControlRole vs DSPM for AI
Entra Conditional AccessWho/what can sign in and under which conditions—not SharePoint SIT discovery
Microsoft Entra Agent IDIdentity for agents as non-human principals
Defender for AI Service / CWPRuntime threat detection for Azure AI / Foundry-style workloads
Foundry guardrails / Prompt ShieldsModel/agent content and injection filtering at inference
AI Gateway (APIM)Token limits, auth, logging in front of model endpoints

DSPM answers: Is our data overshared and are AI interactions creating data risk? Other SC-500 AI bullets answer identity, runtime, and platform guardrails.

SC-500 traps

  1. “Copilot bypasses SharePoint permissions” — False. Oversharing is the permission model.
  2. Fixing overshare only with Azure Storage firewalls — Wrong surface; this is Microsoft 365 content.
  3. Assuming sensitivity labels alone block Copilot — You often need label + DLP policies (and correct label settings for Copilot/agent processing) as Microsoft documents.
  4. Confusing DSPM for AI with Defender CSPM alone — Related “posture” language, different products (Purview vs Defender for Cloud).
  5. Ignoring third-party AI — SC-500 language includes AI apps, not only Microsoft 365 Copilot.

Engineer checklist

  1. Open Microsoft Purview portal → DSPM for AI (or current unified DSPM AI views).
  2. Confirm Purview Audit is on; review Get started prerequisites for third-party AI if needed.
  3. Review default weekly SharePoint oversharing assessment; create custom assessments for critical sites.
  4. Activate recommended one-click policies carefully (simulation first where available).
  5. Remediate with labels, DLP, Restricted Content Discovery, retention, access reviews.
  6. Monitor Reports, Apps and agents, and Activity explorer after Copilot/agent deployment.
  7. Feed findings into security ops: high-risk sites become backlog items, not one-time screenshots.

Bottom line: On SC-500, SharePoint overexposure + Purview DSPM for AI is how you prove you can make Copilot and AI apps safe to adopt—by fixing the data surface AI will inevitably touch.

Test Your Knowledge

Why does SharePoint oversharing become higher risk after Microsoft 365 Copilot is deployed?

A
B
C
D
Test Your Knowledge

Which Microsoft product experience is the SC-500-aligned hub for identifying Copilot/AI app data risks and SharePoint oversharing assessments?

A
B
C
D
Test Your Knowledge

A DSPM for AI assessment finds highly sensitive unlabeled contracts on a SharePoint site that must not be summarized by Copilot until ownership is cleaned up. Which remediation pairing best matches Microsoft’s guided patterns?

A
B
C
D
Test Your Knowledge

Which statement correctly limits what DSPM for AI does relative to other SC-500 AI controls?

A
B
C
D