Brings together DLP, Insider Risk Management and sensitivity-label insights in Microsoft Purview to surface risks to sensitive data, and adds data risk assessments plus remediation for oversharing.
Also called DSPM, Data Security Posture Management (classic).
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Data Security Posture Management in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview Data Loss Prevention
Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
- Insider Risk Management
A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- remediation
Applying updates through vSphere Lifecycle Manager, entering maintenance mode where needed, so that every cluster and host ends up compliant with its image or baselines. Readiness can first be confirmed by a pre-check that changes nothing.
Related terms
- AI observability
A page in Data Security Posture Management listing the AI agents and apps used in the past 30 days. For each it shows whether it is high risk, any interactions involving sensitive data, and which policies apply to it.
- Content Explorer Content Viewer
Grants the ability to read what is inside items listed in the Content and Data explorers, plus AI prompts and responses shown in DSPM. List Viewer membership does not include this.
- Data risk assessment
Looks for overshared data as part of Data Security Posture Management. A built-in run checks the 100 busiest SharePoint sites weekly, while custom runs can focus on particular people, sites or Fabric workspaces, and fixes include limiting access by label.
- Data security objectives
Step-by-step goals in DSPM, for example stopping oversharing or Copilot data exposure. Each comes with its own remediation plan, Security Copilot agents and policies you can create in one click.
- Data Security Posture Agent
Lets admins ask questions in plain language across Exchange, Teams, SharePoint, OneDrive and Copilot interactions for quick checks before an investigation. It is a Security Copilot agent in preview inside the current DSPM and uses security compute units.
- DSPM for AI
Purview solution securing data used by Copilot, agents and AI apps. Its one-click recommendations generate policies, for example DLP scoped to Microsoft 365 Copilot and Copilot Chat, which you then adjust in the solution that owns them rather than in DSPM.
- One-click policies
Ready-made policies that Data Security Posture Management sets up from its recommendations, covering DLP, Insider Risk Management, Communication Compliance and collection. Any later changes happen in each policy's own solution.