Forum Discussion
I just want to secure AI. DLP vs Info Protection vs DSPM vs Governance vs...
I'm with an MSP, and I've avoided Purview like the plague, because it seems to be suffering from the same 'made by marketing teams' 'strategy' the 365 documentation is. However, it's my understanding Purview policies are needed for Data control of Copilot.
Here's my issue: all of these different 'solutions' sound like the exact same thing, but are pitched as if they are something different. i'm going to post a couple of descriptions for these 'solutions' to illustrate this.
'discover, label, and protect sensitive and business-critical info'
'make sure your organization can identify, monitor, and protect sensitive info across the expanding Microsoft 365 landscape'
'discover and secure all your sensitive data across Microsoft 365 and non-365 data sources'
'Discover, label, and protect sensitive and business-critical info across your multicloud data estate.'
I genuinely do not have time to figure out what each of these 'solutions' are, then figure out their policies, then their giant library of settings (below)... It's not even clear to me what's active NOW, considering we never licensed Purview - but somehow have been roped into it. It SEEMS like these are all variations of marketing terms, which all point to 3-4 actual technical implementations in obscure ways.
Can someone advise on the ACTUAL technical policies we want to target and enable? Or just give some clarity? I've never felt so overwhelmed or disconnected from Microsoft's environment. We just want to secure our tenant's AI usage.
9 Replies
- KnutPetterTin Contributor
Two things in your follow-up haven't been answered, and the licensing detail you added changes the second one.
First, directly: yes, the one-click policies in DSPM are real DLP policies. Not a separate mechanism. Enable one and it sits in your normal DLP policy list alongside everything else.
Second, the circle you're going round in is real, and it isn't only marketing. Information Protection is the labelling engine. DLP is the enforcement engine. DSPM is the dashboard that assesses posture and switches the other two on for you. They are different things that all touch the same data, which is why the descriptions overlap.
What makes the docs actively misleading: "DSPM for AI" and "DSPM" have been merged, and both classic solutions retire on 30 September 2026. If one guide shows them as separate and another doesn't, you're reading two generations of documentation at once. Worth knowing the merge is only cosmetic in one respect, the policies themselves are still literally named "DSPM for AI: ..." in the DLP list, which adds to the confusion rather than removing it.
On Business Premium: I looked at a Business Premium tenant with no Purview add-on. DSPM is fully there, and the DSPM for AI policies show up in the DLP policy list. More usefully, the default policy "Safeguard sensitive data in Microsoft 365 Copilot interactions" already exists in simulation mode, unenforced, with an Enforce button. So you can see what it would have caught before you commit to anything or buy anything. Given you only have a couple of Copilot seats, that's where I'd start: open it, read the simulation numbers, and let those tell you whether the add-on is worth it for that customer. Beats deciding from the product descriptions. I wrote up how these layers stack, in Norwegian:
https://knutdimmen.no/posts/pureview-1-2-3-del-3/ - KnutPetterTin Contributor
Two things in your follow-up haven't been answered, and the licensing detail you added changes the second one.
First, directly: yes, the one-click policies in DSPM are real DLP policies. Not a separate mechanism. Enable one and it sits in your normal DLP policy list alongside everything else.
Second, the circle you're going round in is real, and it isn't only marketing. Information Protection is the labelling engine. DLP is the enforcement engine. DSPM is the dashboard that assesses posture and switches the other two on for you.
They are different things that all touch the same data, which is why the descriptions overlap.What makes the docs actively misleading: "DSPM for AI" and "DSPM" have been merged, and both classic solutions retire on 30 September 2026. If one guide shows them as separate and another doesn't, you're reading two generations of documentation at once. Worth knowing the merge is only cosmetic in one respect , the policies themselves are still literally named "DSPM for AI: ..." in the DLP list, which adds to the confusion rather than removing it.
On Business Premium: I looked at a Business Premium tenant with no Purview add-on. DSPM is «fully» there, and the DSPM for AI policies show up in the DLP policy list. More usefully, the default policy "Safeguard sensitive data in Microsoft 365 Copilot interactions" already exists in simulation mode, unenforced, with an Enforce button. So you can see what it would have caught before you commit to anything or buy anything.
Given you only have a couple of Copilot seats, that's where I'd start: open it, read the simulation numbers, and let those tell you whether the add-on is worth it for that customer. Beats deciding from the product descriptions. I wrote up how these layers stack, in Norwegian: https://knutdimmen.no/posts/pureview-1-2-3-del-3/
- Dean_GrossSilver Contributor
The most straightforward place to start is with the Purview DSPM Setup tasks. work you way through those, don't worry about the endpoint DLP configuration settings initially, that is for later after you learn about what is going and you need to change the defaults. See Deploy and use Data Security Posture Management | Microsoft Learn for a great tutorial.
Sensitivity labels are your friend, many other solutions use them. Get started with them by following this Introduction to secure by default with Microsoft Purview | Microsoft Learn - underQualifriedIron Contributor
"helps you discover and classify sensitive data, apply consistent protections, and reduce the risk of data loss across Microsoft 365"
^^^ description for a solution that is NOT Data Loss Protection.Microsoft Purview can feel complex.
If you are looking at controls to minimise oversharing with Microsoft 365 Copilot and Copilot Chat then it depends on what licensing you have. Note that this applies to the enterprise versions, not the consumer Copilot.
The options are:
Available for all licences:
- Block content with sensitive data being shared with Copilot. Sensitive data is either the
out-of-the-box Sensitive Information Types Microsoft has defined, such as IT credentials, credit card data, etc., or your own custom SIT.
If you have E5 compliance or the Purview add-on for Business Premium, then you get additional functionality
- Block content labels with Purview sensitivity labels being uploaded or referenced by Copilot
- Block sensitive content based on SITs or labelled content being shared with third-party or consumer Gen AI apps in the browser
I have just written a blog on How to Deploy Microsoft Purview DLP for Copilot and Generative AI Deploy Microsoft Purview DLP for Copilot Security
Microsoft references
Learn about the default DLP policy for Microsoft 365 Copilot location | Microsoft Learn (available with all licences
https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about
Reach out if you need more information
- underQualifriedIron Contributor
nikkichapple looking thru a slideshow you made available on this subject. In one of the early slides, you recommend DSPM as a 'one-click' setup for default AI data protection. Do you still recommend this? Does this implement DLP / sensitivity policies?
- Block content with sensitive data being shared with Copilot. Sensitive data is either the