LearnMicrosoft 365 Copilot › 7 · Security & compliance

DSPM for AI: the posture instrument

Purview's Data Security Posture Management for AI is the dashboard this whole curriculum keeps citing: oversharing risk, sensitive-data-in-prompts, BYO-AI visibility. Read it like a vulnerability scanner — findings, owners, SLAs — not like a poster.

What it actually watches

  • Posture assessments: recurring checks against your Copilot estate — oversharing exposure (the SAM data joined to AI risk), label/DLP coverage gaps, risky configuration — rendered as recommendations with affected-resource lists. This is the 'assess' engine the pilot-to-scale gates run on.
  • Activity analytics: sensitive-info types appearing in PROMPTS and responses, per app — including third-party/consumer AI reached from managed endpoints (browser/endpoint DLP signals feeding it). The BYO-AI shadow inventory the alternatives concept demands lives here.
  • Policy one-clicks: pre-built policy bundles (DLP for AI locations, insider-risk detections for risky AI usage, collection policies for interaction oversight) — accelerators into the controls modules 2-3 and 7 covered properly; adopt via those concepts' design lenses, not blindly.

Operating it as a programme (the vulnerability-scanner discipline)

  1. Baseline at stage 0 (pilot-to-scale): the first assessment IS the readiness report's spine.
  2. Triage cadence: new findings weekly to named owners — 'the dashboard shows red' is only useful if red pages someone.
  3. SLA by class: oversharing findings ride the runbook's containment clock; sensitive-prompt spikes ride security review; coverage gaps ride the labeling backlog.
  4. Trend, not snapshot: the exec artifact is direction — exposure shrinking wave over wave (the before/after metric the steering committee understands).

Honest limits

It watches the MICROSOFT-visible world: unmanaged devices and network-invisible AI use escape it (endpoint coverage decides reach); findings lag reality on the assessment cadence; and it measures your DATA posture, not agent behaviour (run histories and action telemetry — modules 5-7 — are the agent instrument). The gap list is, as ever, part of the report.

What to watch (proofs)

  • The trend deck: assessment scores/finding counts over time, exported each cycle — the programme's heartbeat.
  • Finding-to-fix latency: per class, measured — the SLA made real.
  • BYO-AI census accuracy: DSPM's third-party AI list vs network telemetry — the instrument's coverage, audited against another instrument.
  • Sensitive-prompt hotspots: which apps/populations trip sensitive-info detections — the awareness-training targeting data (what-users-ask concept's training trigger, quantified).

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.