Recognize the broader Microsoft Purview governance surface

Completed

Every capability this module covers so far answers a question Relecloud already knew to ask: what does a DLP policy need to cover, how does an alert reach you, how long does a record need to survive, and what is Copilot doing with the data it can already touch. But Microsoft Purview's governance surface extends past those four questions into three more, and this final stretch is about recognizing each one—not configuring it. Reporting and alerting, Insider Risk Management, and Purview Audit round out the picture DSPM for AI started, and knowing when each one is the right tool to reach for (or the right specialist to loop in) is the skill this unit builds.

Track policy activity over time with reporting and alerting

Unit 5 covered how a single DLP alert reaches you through Microsoft Defender XDR the moment a policy matches. That's useful in the moment, but it doesn't answer a slower, wider question Relecloud's compliance team asks on a recurring basis: how often are policies matching overall, where are those matches concentrated, and is a specific rule generating more noise than signal? That's what Purview's reporting and alerting surface is for. DLP alert dashboards show a running feed of matches as they happen, and reporting layers in match trends across locations—enough to spot a spike in Exchange or SharePoint that a single alert would never reveal on its own.

Recognize this surface as the answer to "how do I see what my policies are catching, over time?" You don't need to design a new alerting workflow to use it; the dashboards and trend reports already do that work. When Relecloud's leadership asks whether policies are actually working, this is where you look first.

Detect risky behavior patterns with Insider Risk Management

Where reporting shows what policies catch, Insider Risk Management (IRM) asks a different kind of question entirely. IRM is a distinct Purview solution that correlates signals across a user's activity—IP theft, data leakage, security violations—to surface potential malicious or inadvertent insider risk before it becomes an incident. It's built with privacy by design: users appear pseudonymized by default, and role-based access controls limit who can see identifying details at all.

IRM ships with policy templates for common scenarios, including data theft by a departing employee and data leaks from a disgruntled user. Two templates matter directly to the AI oversight you covered in the previous unit: a Risky AI usage template that detects risky prompts and responses across Microsoft 365 Copilot, Microsoft Copilot, and agents, and a template built specifically for agents hosted on Copilot Studio and Microsoft Foundry, watching for risky prompts, agents that generate sensitive responses, agents accessing sensitive SharePoint files, and agents sharing files externally.

That AI connection isn't incidental. Recall from the previous unit that DSPM for AI includes one-click policies you can turn on with no separate configuration—and some of those one-click policies, like "DSPM for AI - Detect when users visit AI sites" and "DSPM for AI - Detect risky AI usage," are themselves IRM policy templates under the surface. DSPM for AI gives you a fast path into IRM's AI-specific detection without building a policy from scratch. Authoring a custom IRM policy beyond that one-click path is still a specialist's workflow—someone trained in IRM's investigation and case-management process configures and reviews it. Your role is to recognize when a behavior pattern calls for IRM and bring in that specialist, not to build the policy yourself.

Recognition check: An unfamiliar SharePoint site starts collecting broad-audience permissions over several weeks—no single event, just a slow drift. Is that a reporting-and-alerting question, an IRM question, or an Audit question? (It's IRM: a gradual behavior pattern is exactly what correlation-based detection is built to catch, while reporting shows point-in-time policy matches and Audit tells you what already happened.)

Learn more about Insider Risk Management and its policy templates.

Prove who did what with Purview Audit

The third capability answers a question that only comes up after something already happened: who did what, and when? Purview Audit and the unified audit log are the system of record for that question. As Microsoft puts it, "your organization's unified audit log captures, records, and retains thousands of user and admin operations performed in dozens of Microsoft services and solutions"—including Copilot and other AI applications, where audit logs capture the same kind of forensic detail.

You reach for Audit when someone needs proof of what already happened: investigating a possible security breach, supporting an internal investigation, meeting a compliance obligation that requires long-term retention of activity records, or running a forensic review of something specific, like confirming when a mail item was accessed, forwarded, or replied to. Where reporting shows trends and IRM flags behavior patterns, Audit answers the question after the fact, with a retained record that holds up under scrutiny. Configuring audit retention periods and running advanced search queries is Purview specialist territory; your job is recognizing that a who-did-what-when question belongs in Audit and routing it there.

Learn more about auditing solutions in Microsoft Purview.

Capability Question it answers Your role
Reporting & alerting How often are policies matching, and where? (trends over time) Read the dashboards and trend reports
Insider Risk Management (IRM) Is a risky behavior pattern building across a user's activity? Recognize the pattern; bring in the IRM specialist
Purview Audit Who did what, and when? (a retained system of record) Route who-did-what-when questions here

The governance surface, complete

This module started with specifying DLP requirements for Copilot and agent interactions and ends here, with three more capabilities that complete the picture: reporting and alerting for ongoing visibility, Insider Risk Management for behavioral risk—including the AI-specific templates that pick up right where DSPM for AI leaves off—and Purview Audit as the record you turn to when you need proof of what already happened. None of these are configuration work for you to take on directly; they're capabilities to recognize, so that when Relecloud needs one of them, you know exactly which specialist to bring in and why.