| name | purview-agent-365-security |
| description | Guidance for securing and governing AI agents (Microsoft 365 Copilot agents, Copilot Studio agents, and Security Copilot agents) with Microsoft Purview - applying DSPM for AI, DLP, sensitivity labels, Communication Compliance, and audit to agent data interactions and identities. WHEN: secure AI agents, govern Copilot agents, Purview for agents, agent data security, DLP for agents, audit agent interactions, Copilot Studio agent security, agent oversharing, agent compliance, agent identity governance. |
| license | MIT |
| metadata | {"author":"Microsoft","version":"0.1.0"} |
Securing AI Agents with Microsoft Purview
As organisations build and deploy AI agents (Microsoft 365 Copilot agents, Copilot Studio
agents, Security Copilot agents), Microsoft Purview extends data security and compliance controls
to the data those agents access and produce - and to the agent identities themselves.
When to use
Governing the data-security and compliance posture of AI agents before and during rollout,
especially when agents are granted access to enterprise data sources or autonomous actions.
Do not use this skill for end-user Copilot oversharing alone (use purview-copilot-oversharing)
or for prompt-level AI monitoring without agents in scope (use purview-dspm-ai).
Pick the right control per agent type
| Agent type | Primary controls |
|---|
| M365 Copilot agent (user-grounded) | Inherits user permissions - oversharing remediation + labels + DLP for Copilot |
| Copilot Studio agent (declarative, knowledge sources) | Restrict knowledge sources + DLP + Communication Compliance |
| Copilot Studio agent (autonomous/with actions) | All above + Entra identity governance + least-privilege actions |
| Security Copilot agent | Workspace permissions + audit + scope to specific data plug-ins |
| Third-party agent in tenant | Defender for Cloud Apps + Endpoint DLP + acceptable-use policy |
Rule of thumb: the more autonomous the agent, the more it must be treated like a privileged
identity - not just a piece of UX.
Approach
- Discover with DSPM for AI - Gain visibility into agent interactions and sensitive data
accessed or generated by agents; action one-click protection recommendations.
Verify: DSPM for AI dashboard shows agent activity volume and sensitive interaction counts.
- Control access (oversharing) - Because agents honour user permissions, remediate
oversharing and apply sensitivity labels so agents can't surface content users shouldn't see.
Verify: a test user via the agent cannot retrieve content they cannot reach directly.
- Apply DLP & labels - Extend DLP and sensitivity-label protection to agent grounding data
and outputs where supported; configure DLP for Copilot to exclude top-tier labelled content.
Verify: agent response excludes or warns on labelled-restricted content.
- Detect risky prompts - Use Communication Compliance / DLP for AI to detect sensitive data
or prompt-injection patterns in agent interactions.
Verify: a test prompt with PII generates a Communication Compliance alert.
- Audit & investigate - Use Purview Audit and Activity Explorer to log agent interactions for
investigation and compliance; align with Insider Risk where relevant.
Verify: agent interactions appear in audit search with user, agent, and prompt metadata.
- Govern identity - Treat agent identities as governed, least-privilege identities (Entra) -
apply Conditional Access, periodic access reviews, and entitlement management.
Verify: each non-user agent has an owner, a defined permission scope, and a renewal cadence.
- Lifecycle - Decommission unused agents on a cadence; orphaned agents are a permission
sprawl risk.
Verify: monthly agent inventory with owner re-attestation.
Guardrails
- Agent governance depends on classification, labelling, and oversharing remediation maturity -
agents without label-aware grounding inherit every gap in the underlying data estate.
- Address oversharing and access scope before granting agents broad data access - agents
amplify oversharing because they search more efficiently than humans do.
- Apply privacy controls and least privilege to agent identities and the data they touch -
default-allow on agent actions is a future incident.
- Communicate to users that agent interactions are logged and reviewed; legal/HR sign-off
on monitoring scope.
- Treat Copilot Studio published agents like apps - require security review before tenant-wide
publish.
Common anti-patterns
- Publishing a Copilot Studio agent with knowledge-source scope = "all SharePoint" with no DLP.
- Treating agent identities as machine accounts with permanent broad permissions.
- Skipping audit configuration for agent interactions until after an incident.
- No agent inventory - nobody knows how many are in production.
- Assuming DLP for Copilot covers Copilot Studio agents identically (capability varies).
Example prompts
Secure and govern Copilot agents with Microsoft Purview.
Apply DLP and audit to AI agent interactions.
How do I prevent agent oversharing and meet compliance for agents?
Govern Copilot Studio agent data security.
Treat agent identities as privileged identities in Entra.
Microsoft Learn