What's new in Microsoft Purview
Whether it's adding new solutions, updating existing features based on your feedback, or rolling out fresh and updated documentation, Microsoft Purview helps you stay on top of the ever-changing data governance, data security, and risk and compliance areas. Take a look at the following information to see what's new in Microsoft Purview.
Tip
If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the Microsoft Purview compliance portal trials hub. Learn details about signing up and trial terms.
What's planned for Microsoft Purview
Microsoft Purview continues to add new solutions and features to help with data governance, data security, and risk and compliance in your organization. Check out the following roadmap sites to learn more about what's planned for Microsoft Purview:
October 2024
Microsoft Purview Data Governance
Self-service analytics and insights for data governance metadata (Public Preview)
- This feature empowers data analysts and data stewards to analyze and gain insights from Microsoft Purview Data Governance metadata in Fabric OneLake. Customers will have full flexibility in computing and tooling to leverage insights from Purview Data Governance metadata to manage and enhance their data estate health. They can link data governance metadata with other data sources to create leadership reports and generate insights that support fact-based decision-making and foster a culture of data governance across the organization.
- ADLSg2 support is currently in gated preview. Please contact your Microsoft Purview account team to have your tenant allowlisted to access Purview Data Governance metadata for your ADLSg2 storage. You need to provide the following information for allow listing: Tenant ID, Organization name, Purview Account name, Purview Account ID, Azure Region, and Azure Subscription ID. Learn more..
Azure Databricks view support is in public preview. Azure Databricks users will be able to profile and run data quality scans for data in Azure Databricks views in addition to Azure Databricks tables. Learn more
Native Synapse connector for Serverless and Synapse Data Warehouse with managed vNet support is available in gated preview for both tables and views. Customers will be able to profile and run data quality scans on their data in Synapse behind the private endpoint. You need to provide following information for allow listing: Tenant ID, Organization name, Purview Account name, Purview Account ID, Azure Region, and Azure Subscription ID. Learn more.
AI Hub
- UI changes to navigation: Although there's no change to functionality, some AI hub pages and navigation have changed. For example, the original Analytics page is replaced by Overview and Recommendations pages, and the one-click policies have moved from the Policies page to individual recommendation cards. If you need help navigating the AI hub, see How to use the AI hub.
- Event name change: The event name of "Classification stamped" in activity explorer is changed to Sensitive info types detected.
Compliance Manager
- Updated: Changes in Compliance Manager settings for automated testing of improvement actions and user access to assessments are now reflected in the audit log. Relevant schemas have also been added to Office 365 Management Activity API schema.
Purview Deployment Models
- New model: Microsoft Purview deployment models are a new content set authored by the product engineering team and are based on real-world customer experiences. They are intended to streamline and accelerate your deployment process for specific business scenarios. The first one, Secure by default with Microsoft Purview and protect against oversharing focuses on:
- Implementing a secure-by-default configuration using sensitivity labeling
- Using label publishing defaults and auto-labeling in the Office client.
- Using contextual default in SharePoint sites to increase deployment velocity.
Sensitive information types
Sensitivity labels
- Loop support: New article that lists the supported apps and scenarios for using sensitivity labels with Loop components, pages, and workspaces, Use sensitivity labels with Microsoft Loop.
- Change for label scopes: The Items scope is renamed Files & other data assets. This renamed scope now includes items that were previously in the removed Schematized data assets scope and newly includes items for Microsoft Fabric.
- In preview: Sensitivity labels that apply access control to encrypt items now support protection policies for Microsoft Fabric. For more information, see Protection policies in Microsoft Fabric.
- In preview: Now rolling out, a naming change to the encryption permissions levels that you see in the Microsoft Purview portal and Microsoft Purview compliance portal, and that users see when a sensitivity label prompts them for permissions in Word, Excel, and PowerPoint. The actual usage rights included in these permission levels haven't changed. Accompanying this change is a new dialog box for users, which displays the permission levels and additional options.
- Reviewer is renamed Restricted Editor
- Co-author is renamed Editor
- Co-owner is renamed Owner
- Improvements to default labels: Rolling out, the default sensitivity labels now include the Meetings scope if the tenant has licenses to manually apply a label for scheduled meetings. Additionally:
- The accompanying sensitivity label policy includes a default Teams meeting label.
- If the tenant has licenses to manually apply the label to Teams meetings, some of the sensitivity labels also have settings configured to protect these meetings.
- Improvements to Microsoft 365 Copilot: Copilot in Outlook (Classic) for Windows now supports encrypted items for version 2408 in Monthly Enterprise Channel.
September 2024
Microsoft Purview Data Governance GA
The Microsoft Purview Data Governance experience with Data Catalog is generally available with some new features and capabilities:
- Business concept deletes - enables data stewards to delete business concepts (governance domains, data products, glossary terms, critical data elements, and OKRs that are unpublished and don't have associations with other concepts.
- Data catalog admin settings - the admin experience including roles, permissions, and self-service analytics is now part of the Solution Settings for Data Catalog in the Microsoft Purview portal.
- Data product policies - optional access providers in data product request access workflows can record the asset level access provisioning status for assets in the data product and mark the request as Completed. See our access policies article for more information.
- Data product request access workflows -
- Data consumers can select a request from the My Data Access tab in Data Products page and see the request details, including approval details and asset level access provisioning status. Learn more.
- Access request approvers or new optional access providers who are the last step in the workflow can record asset level access provisioning status for assets in the data product and mark the request as ‘Completed’ post approval. Learn more.
- Data quality for multi-cloud data sources - Data Quality Stewards will be able to profile, add data quality rules, run data quality scans and monitor data quality scores of their data in multicloud data estate.
- Enterprise glossary (Preview) - data consumers can browse and understand all glossary terms, CDEs, and OKRs across the enterprise in this new page under Discovery.
- New navigation - New navigation and menu enhancements to navigate the 3 main categories of experiences: Discovery, Catalog management, and Health management, and separate admin experiences to Solution settings in the Microsoft Purview portal.
- Partner-built bulk import functionality - Download our partner Macula’s standalone utilities to bulk import business concepts into the new Data Catalog.
- Self-service analytics and insights for data governance metadata (Private Preview) - Empower data analysts and data stewards to analyze and derive insights from Microsoft Purview Data Governance metadata. Customers will have full flexibility in computing and tooling to analyze and utilize insights from Purview Data Governance metadata to manage and improve their data estate health. They can link data governance metadata with other data sources to create leadership reports and generate insights that drive fact-based decision-making and foster a data governance culture across the company. Learn more.
- Tree-view visualization: Hierarchy for governance domains and glossary terms can be visualized as a tree-view within the catalog management and discovery experiences.
Sensitivity labels
- Improvements to Microsoft 365 Copilot: Copilot in Outlook (Classic) for Windows is now rolling out support for encrypted items, starting with version 2408 in Current Channel.
August 2024
AI Hub
- Copilot prompts and responses reported by activity explorer: The activity explorer event AI interaction includes the prompt and response independently from eDiscovery and insider risk management.
- Improvements to permissions: You can use the Microsoft Purview Security Reader role for read-only access to the Microsoft Purview AI Hub. For more information, and a comparison breakdown of permissions by activities, see the new article, Permissions for Microsoft Purview AI Hub.
Compliance Manager
- Updated: Added and clarified information about assessment status states.
Sensitivity labels
- In preview: Dynamic watermarks are now also supported on iOS and Android, and the custom string supports a date and time variable.
July 2024
AI Hub
- Improvements to permissions: You can now also use the Microsoft Purview Compliance Administrator role to access the Microsoft Purview AI Hub.
Audit
- Updated: Clarified the CreationTime property meaning.
- Updated: Documented that SearchQueryInitiated events are now included in Audit (Standard).
Compliance Manager
- Updated: Clarified settings for automatic testing of improvement actions to specify that Compliance Manager Administrators can turn on or off automatic testing for all improvement actions, not just on a per-action basis.
Data connectors
- Retired: All Veritas data connectors in Microsoft Purview were retired in June 2024. Non-Veritas data connectors in your organization aren't affected by this change. Contact your Veritas account representative if you have questions about Veritas archiving services.
eDiscovery
- In preview: Use the new eDiscovery (preview) solution in the Microsoft Purview portal to identify, review, and manage content in Microsoft 365 services to support your investigations. The new experience supports most of the features and capabilities from the previous experience, with more features being added over the coming months.
- Updates: New scenarios added for the Invoke-ComplianceSecurityFilterAction cmdlet for compliance boundaries.
Microsoft Purview portal
- Updated: The global search feature now supports the new User category in the Microsoft Purview portal.
Sensitivity labels
- In preview: New privacy control for Office apps that prevents sending labeled content to some connected experiences for analysis. This setting impacts services such as data loss prevention, automatic and recommended labeling, and Microsoft 365 Copilot.
- In preview: Dynamic watermarks to deter leakage of labeled and encrypted documents by rendering over the document the reader's Universal Principal Name (UPN) or other identifying information. Unlike standard content markings, dynamic watermarks can't be changed or removed by the user.
- In preview: Rolling out, the condition builder to create search queries in eDiscovery from the Microsoft Purview portal supports sensitivity labels. For example, as part of your eDiscovery case, restrict content to files and emails that have a Highly Confidential sensitivity label. Or conversely, exclude content to files and emails that have a Public sensitivity label.
- Improvements to Microsoft 365 Copilot: Outlook for iOS and Outlook for Android join the platforms that support Copilot in Outlook for encrypted items.
June 2024
Communication compliance
- New article: Configure conditions for key scenarios. Use the screenshots in this article as models to quickly configure policy conditions for your own scenarios.
- Scheduled reports: If you need to recreate the same report regularly, you can now schedule report creation.
Data lifecycle management and records management
- Change for Teams meetings: Now that Microsoft Teams supports meetings that have transcripts without recordings, these transcripts are also identified with the same query that identifies recordings and accompanying transcripts.
Insider risk management
- New article: See the Best practices for managing your alert volume article to tune your alert volume if you have too many or too few alerts.
- In preview: With the new policy deletion enhancements, you have the choice to delete associated alerts and users when you delete a policy. This is useful if you have created a policy for testing purposes.
- Updated: Clarified that detection groups can be used with the Global exclusions setting as well as with variants of built-in indicators.
- Updated: Clarified that admins restricted by admin groups can't access alerts for users assigned to them through security groups or distribution groups and recommendations for adding users directly to admin groups.
Sensitivity labels
- General Availability (GA): New privacy control for Office apps that prevents sending labeled content to some connected experiences for analysis. This setting impacts services such as data loss prevention, automatic and recommended labeling, and Microsoft 365 Copilot.
- Improvements to Microsoft 365 Copilot: Copilot in Outlook now supports encrypted items for Outlook for Mac, Outlook on the web, and the New Outlook for Windows.
- Improvements to auto-labeling: The maximum number of automatically labeled files in your tenant per day is increased from 25,000 to 100,000 and the number of matched files that simulation supports is increased from 1,000,000 to 4,000,000.
- New: Additional column, "New Outlook for Windows" is now included in the capabilities table for Outlook.
Data governance private endpoints
- New: Enterprise data governance resources can now use platform private endpoints to secure access to the Microsoft Purview Data Catalog and Data Map, and secure data traffic between Microsoft Purview and your private networks.
May 2024
AI Hub
- In preview: Microsoft Purview AI Hub provides easy to use graphical tools and reports to quickly gain insights into AI use within your organization. Not just for Microsoft 365 Copilot, but also third-party LLMs. One-click policies help you protect your data and comply with regulatory requirements. For more information, see Microsoft Purview AI Hub provides insights, policies, and controls for AI apps.
Communication compliance
- General Availability (GA): Summarize a message using Microsoft Copilot for Security in Microsoft Purview.
- In preview: Use the new communication compliance indicators in insider risk management to integrate communication compliance with insider risk management.
- In preview: Use admin units to scope users to a region or department.
- In preview: Use the new condition builder to combine multiple conditions in the same policy. Create compound conditions with AND, OR, and NOT operators. See a list of scenarios that use the new condition builder.
- In preview: Use the new Cross-policy resolution setting to resolve all instances of the same policy match in any policy where it's detected.
- Updated: Clarified that policies appearing in the policy list with the "AI-hub" prefix are created in the AI Hub, not in communication compliance.
- Updated: Added Outlook Copilot and Stream Copilot to the list of Copilot apps supported by communication compliance.
- Updated: Clarified that when migrating between Microsoft 365 US Government Cloud and the commercial cloud, active cases, and alerts won't be migrated.
Compliance Manager
- Updated: There are four new AI regulatory templates to help organizations assess, implement, and strengthen their compliance against AI regulations, including the EU Artificial Intelligence Act, ISO/IEC 23894:2023, ISO/IEC 42001, and NIST AI RMF.
Data lifecycle management and records management
- In preview: Adaptive protection for content in SharePoint, OneDrive, and Exchange. An auto-labeling retention policy for these locations is automatically created when you use Adaptive Protection with insider risk management. For more information, see Dynamically mitigate the risk of accidental or malicious deletes. You might need to opt in to this new capability:
- If Adaptive Protection was turned on before this data lifecycle management preview release, you must manually enable the auto-labeling retention policy.
- If you turn on Adaptive Protection after this data lifecycle management preview release, the auto-labeling retention policy is automatically turned on for you.
Information protection scanner
- General availability (GA): A new scanner version from the Microsoft Purview Information Protection client is generally available and procedural information is updated to use the new PowerShell module. When you upgrade from the Azure Information Protection client, it's important to follow the upgrade instructions because service names and other components are renamed.
Insider risk management
- General Availability (GA): Adaptive protection in insider risk management when used with Microsoft Purview Data Loss Prevention.
- In preview: Adaptive protection in insider risk management extended to Microsoft Purview Data Lifecycle Management. The data lifecycle management policy that's automatically created detects for users that are assigned an Elevated risk level. When a risky user deletes any content from SharePoint, OneDrive, or Exchange Online, the contents are automatically preserved for 120 days.
- General Availability (GA): Summarize an alert using Microsoft Copilot for Security in Microsoft Purview.
- In preview: You can now use adaptive scopes with insider risk management policies. Learn about the advantages of adaptive scopes and how they work with admin units
- In preview: Exclude users or groups from an insider risk management policy.
- In preview: Use the new Global exclusions setting to configure exclusions for your policies. Exclusions settings (domains, email signature attachments, file paths, file types, keywords, sensitive info types, SharePoint sites, and trainable classifiers) have been moved from the Intelligent detections setting to this new setting.
- In preview: Insider risk management now uses the Free public domains domain group to automatically create email insights for exfiltration of business data to personal email and email to self.
- In preview: Use the new communication compliance indicators in insider risk management to integrate communication compliance with insider risk management.
- In preview: Use the new Microsoft Fabric indicators to detect for techniques used to figure out the environment and to gather data of interest.
- In preview: Data sharing setting now extends insider risk severity to the Microsoft Defender XDR User's page.
- Updated: Clarified that when migrating between Microsoft 365 US Government Cloud and the commercial cloud, active cases, and alerts won't be migrated.
- Updated: Clarified that when assigning an alert, if you're using a custom group, you must add the Case management role to the custom group.
- Updated: Clarified that when configuring a physical badging connector, you can't add non-english characters to the JSON file.
- Updated: Clarified that the Users exceeding daily thresholds for indicator graph appears now even if you select the Get alerts only for activity that includes priority content option in the Content to prioritize page. This was a previous limitation for the graph.
Sensitivity labels
- General availability (GA): The Microsoft Purview Information Protection client is generally available, and replaces the Azure Information Protection (AIP) unified labeling client. For more information, see the following resources:
- In preview: Double Key Encryption (DKE) is now in preview for Word, Excel, and PowerPoint on macOS and iOS.
- In preview: Rolling out, sensitivity labels for protected meetings now extend the option for who can record to who can record and transcribe.
- Improvements to Microsoft 365 Copilot: Copilot in PowerPoint can now create a presentation from a labeled and encrypted file for supported configurations.
April 2024
The Microsoft Purview portal (in preview) is being gradually updated with solutions from the compliance portal. Where relevant, the documentation now includes configuration steps for both portals.
Audit
- Updated: Clarified search tips for Exchange admin activities in the audit log.
Communication compliance
- In preview: Summarize a message by using Microsoft Copilot in Microsoft Purview (preview).
- Updated: Clarified why a generic error message might appear when summarizing a message with Copilot in Microsoft Purview.
- Updated: Clarified roles required to investigate Microsoft 365 Copilot interactions and how you can remediate policy matches for Copilot interactions in the same way that you remediate other policy matches in communication compliance.
- In preview: Create a custom tag when you need more flexibility than the standard tags provide.
- Updated: Added new table that describes possible values for the Sentiment column when prioritizing messages.
Compliance Manager
- Updated Working with connectors in Compliance Manager to reflect the availability of a new connector for Corporate Sustainability.
Copilot for Security
- New: Microsoft Copilot for Security in Microsoft Purview
- New: Microsoft Copilot in Microsoft Purview prompts and promptbooks
Data catalog
- In preview: New data catalog experience
- In preview: Governance domains
- In preview: Data products
- In preview: Glossary terms
- In preview: OKRs
- In preview: Data quality
- In preview: New data estate health controls
Data lifecycle management and records management
- Improvements to SharePoint and OneDrive retention: For these services, you can now delete a folder that's subject to retention, even if it contains files.
Data loss prevention
- In preview: Learn about DLP the toolsets you can use to investigate DLP alerts (preview) for Microsoft Copilot in Microsoft Purview.
- In preview: Get started with the DLP alert dashboard (preview)
eDiscovery
- In preview: Summarize an item by using Microsoft Copilot for Security (preview)
- Updated: Clarified steps in the recommended script to correctly output a list of OneDrive sites in targeted collections.
- Updated: Updated application and service data sources for Copilot data.
- Updated: Updated content to reflect the retirement of the Search-Mailbox cmdlet.
- Updated: Clarified non-support for purge or search for Teams Connect Chat (External access or Federation).
- Updated: Documented the Export role for downloads from review sets.
- Updated: Clarified the differences in datacenter locations used to store data in the Canada for eDiscovery (Standard) and eDiscovery (Premium).
Information protection scanner
- In preview: A new scanner version from the Microsoft Purview Information Protection client, now in preview. When you upgrade from the Azure Information Protection client, it's important to follow the upgrade instructions because service names and other components are renamed.
Insider risk management
In preview: Use the Copilot button to summarize an alert, updated for Copilot in Microsoft Purview.
In preview: Configure sharing of user risk severity levels with Microsoft Defender and DLP alerts, updated for Copilot in Microsoft Purview.
In preview: What happens when you share insider risk management user risk severity levels in DLP alerts?, updated for Copilot in Microsoft Purview.
In preview: Use the new cloud storage indicators (Google Drive, Box, and Dropbox) to detect for techniques used to determine the environment, gather and steal data, and disrupt the availability or compromise the integrity of a system.
Use the new cloud service indicators (Amazon S3 and Azure) to detect for techniques used to: avoid detection or risky activities by disabling trace logs or by updating or deleting SQL Server firewall rules; steal data, such as sensitive documents; disrupt the availability or compromise the integrity of a system; gain higher-level permissions to systems and data.
Updated: Domains to add to the firewall and proxy server allowlist to support forensic evidence capture storage.
Updated: Clarification that only Power Automate flows created within the default environment are supported for use with insider risk management.
Microsoft Priva
New: What's new in Microsoft Priva is the new destination for learning about updates to Microsoft Priva solutions, features, and documentation. Moving forward, all Priva updates will be found on What's new in Microsoft Priva instead of the What's new in Microsoft Purview article.
In preview: Four new Priva solutions are available for customers in seven regions, with more regions to come. Get details about how to get started using the new Priva solutions.
In preview: Learn about the new Microsoft Priva portal, a unified experience for using the preview and generally available Priva solutions.
Microsoft Purview portal
- In preview: A new related portal feature is now available in the Microsoft Purview portal.
- In preview: A new help and support experience is now available in the Microsoft Purview portal.
Sensitivity labels
- General availability (GA): Now rolling out, Office documents that are labeled and encrypted can be tracked and revoked by end users in their Office apps on Windows, as a parity feature for the AIP add-in.
- In preview: The Microsoft Purview Information Protection client is released in preview, and replaces the Azure Information Protection (AIP) unified labeling client. For more information, see the following resources:
- Improvements to Microsoft 365 Copilot: Microsoft 365 Copilot in Word can now generate draft content from labeled and encrypted files for supported configurations.
- Retired: Because the AIP add-in for Office apps is now retired, migration instructions and other references to the AIP add-in have been removed throughout from the documentation. If you previously used an Office Group Policy setting to enable the add-in for Office apps, see Office built-in labeling and the Azure Information Protection client.