Introduction
Organizations with sensitivity labels, data loss prevention (DLP) policies, and insider risk controls in place generate hundreds of signals daily. Alerts fire, policy matches trigger, AI agents interact with content. The challenge isn't the absence of signals. It's determining which ones represent actual risk, reconstructing what happened, and deciding whether to escalate.
Data Security Posture Management (DSPM) in Microsoft Purview provides investigation surfaces that bring these signals together. You can investigate activity, use Security Copilot to synthesize patterns, and examine AI agent behavior from a connected set of tools.
Learning objectives
After completing this module, you'll be able to:
- Analyze sensitive data activity across activity explorer, audit logs, and DSPM reports
- Investigate data security events using Security Copilot in DSPM
- Investigate risky AI agent behavior through AI observability
Prerequisites
- Familiarity with the Microsoft Purview portal and its navigation
- Working knowledge of sensitivity labels, DLP policies, and Insider Risk Management concepts