Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
Microsoft claims Purview data security posture management (DSPM) and data security posture management (DSPM) for AI help discover, secure, and apply compliance controls for AI usage across the enterprise.
discover, secure, and apply compliance controls for AI usage across your enterprise.
Related framework references (5)
Microsoft says Purview-supported AI app categories include other AI apps detected through browser activity and categorized as generative AI in the Defender for Cloud Apps catalog.
Other AI apps that are detected through browser activity and categorized as "Generative AI" in the Defender for Cloud Apps catalog.
Related framework references (5)
Microsoft claims supported AI app interactions can be monitored per user in the tenant and prompts and responses can flow into Purview activity views.
Interactions using supported AI apps can be monitored for each user in your tenant.
Related framework references (5)
Microsoft says Endpoint data loss prevention (DLP) policies can warn or block users from sharing sensitive information with third-party generative AI sites accessed through a browser.
warn or block users from sharing sensitive information with third-party generative AI sites that are accessed via a browser.
Related framework references (5)
Microsoft says Purview-supported AI apps use existing controls so tenant data is not returned or used by an large language model (LLM) when the user lacks access.
ensure that data stored in your tenant is never returned to the user or used by a large language model (LLM) if the user doesn't have access to that data.
Related framework references (5)
Microsoft says Purview Endpoint data loss prevention (DLP) can warn or block browser-based sharing of sensitive information with third-party generative AI sites.
Windows computers that are onboarded to Microsoft Purview can be configured for Endpoint data loss prevention (DLP) policies
Related framework references (5)
Microsoft says Purview Insider Risk Management has a risky AI usage policy template for prompt injection and protected-material access signals.
Use the Risky AI usage policy template to detect risky usage that includes prompt injection attacks and accessing protected materials.
Related framework references (5)
Microsoft says supported AI agents inherit the same Purview security and compliance capabilities as their parent AI app.
Where these AI apps support agents, they inherit the same security and compliance capabilities as their parent AI app.
Related framework references (5)
Microsoft Purview AI protection materials reviewed did not provide a clear Model Context Protocol (MCP), agent-to-agent (A2A), or agent-to-agent security control claim.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft Purview AI protection materials reviewed did not provide a clear non-human identity or service-account lifecycle security claim.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft Purview claims security and compliance oversight for AI-agent interactions, including inventory, data security posture management (DSPM) reporting, audit, retention, eDiscovery, communication compliance, and policy recommendations.
All the listed agents are supported by DSPM for AI and have their own dedicated Apps and agents page.
Related framework references (5)
Microsoft Purview materials reviewed did not provide a public product claim for automated adversarial testing, agent or model red teaming, repeatable attack suites, or release-gate evaluation.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft Purview materials reviewed did not provide a public product claim for model artifact scanning, provenance, signing, tamper analysis, dependency inventory, or registry release controls.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft Purview claims data loss prevention (DLP), sensitivity-label, risky-interaction, and unethical-behavior policies across prompts and responses for supported AI applications and agents.
This recommendation creates a policy to help calculate user risk by detecting risky prompts and responses.
Related framework references (5)
Microsoft Purview claims dedicated visibility and data-security or compliance coverage for supported agents, including Entra-registered and Foundry agents, while inheriting protections from the parent AI application.
AI agents have the same security and compliance protections for AI interactions as their parent AI app.
Related framework references (5)
Microsoft Purview materials reviewed did not provide a public product claim for governing coding-agent commands, developer-workstation files or networks, integrated development environment (IDE) extensions, skills, hooks, secrets, or package actions.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft Purview data security posture management (DSPM) for AI materials reviewed did not establish AI workload cost attribution, token or spend metrics, budgets, chargeback, or cost-aware model routing.
No quoted source text is recorded for this claim.
Related framework references (5)
Microsoft documents data security posture management (DSPM) access through Microsoft 365 E5 or Microsoft Purview Suite, while managing some AI-agent interactions can additionally require pay-as-you-go billing.
To access and use DSPM, you need a Microsoft 365 E5 or Microsoft Purview Suite license.
Related framework references (2)