Skip to content

Commit 43c2a6b

Browse files
committed
dspm for ai module
1 parent 3bec01b commit 43c2a6b

File tree

9 files changed

+264
-0
lines changed

9 files changed

+264
-0
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-identify-mitigate-ai-risks.configure-dspm-ai
3+
title: Configure DSPM for AI
4+
metadata:
5+
title: Configure DSPM for AI
6+
description: "Configure DSPM for AI."
7+
ms.date: 2/6/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 4
14+
content: |
15+
[!include[](includes/configure-dspm-ai.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-identify-mitigate-ai-risks.dspm-ai-overview
3+
title: Data Security Posture Management (DSPM) for AI overview
4+
metadata:
5+
title: Data Security Posture Management (DSPM) for AI overview
6+
description: "Data Security Posture Management (DSPM) for AI overview."
7+
ms.date: 2/6/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 4
14+
content: |
15+
[!include[](includes/dspm-ai-overview.md)]
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
Microsoft Purview Data Security Posture Management (DSPM) for AI helps organizations secure AI interactions, track AI-generated content, and enforce compliance policies. To use DSPM for AI effectively, organizations need to configure key settings, enable monitoring, and apply security controls.
2+
3+
## Prerequisites
4+
5+
Before configuring DSPM for AI, check that your environment meets these requirements:
6+
7+
- **[Check permissions](/purview/ai-microsoft-purview-permissions)**: Your account needs appropriate permissions in Microsoft Entra or Microsoft Purview, such as Compliance Administrator or a related role with compliance management permissions.
8+
- **[Verify Microsoft Purview Audit is enabled](/purview/audit-log-enable-disable?tabs=microsoft-purview-portal#verify-the-auditing-status-for-your-organization)**: Auditing is on by default for new tenants, but it's a good idea to verify.
9+
- **[Assign Copilot Licenses](/copilot/microsoft-365/microsoft-365-copilot-enable-users#assign-licenses)**: Users should be assigned Microsoft 365 Copilot licenses for activity tracking.
10+
- **[Onboard Devices to Microsoft Purview](/purview/device-onboarding-overview)**: Devices need to be onboarded to Microsoft Purview to track AI interactions.
11+
- **[Install the Microsoft Purview Browser Extension](/purview/insider-risk-management-browser-support#configure-browser-signal-detection-for-microsoft-edge)**: The Microsoft Purview browser extension is required to monitor third-party AI site visits.
12+
13+
## Steps to configure DSPM for AI
14+
15+
After completing the prerequisites, configure DSPM for AI in Microsoft Purview. This process includes enabling built-in policies, running data assessments, and verifying that AI-related security controls are in place.
16+
17+
1. Access DSPM for AI
18+
19+
- Sign in to the Microsoft Purview portal.
20+
- Navigate to Solutions > DSPM for AI.
21+
22+
1. Review the Get Started Section
23+
24+
- From the Overview page, review Get Started for initial actions.
25+
- Confirm that Audit Logging is enabled.
26+
- Enable Extend Insights for Data Discovery to track AI-generated content.
27+
- Activate One-Click Policies to apply built-in security controls.
28+
1. Activate Preconfigured Policies
29+
30+
- Go to Policies in the Microsoft Purview portal.
31+
- Review available AI security policies.
32+
- Enable recommended policies to detect sensitive data exposure and AI activity.
33+
- If needed, edit the policy scope before activation to apply policies only to specific users or groups instead of the entire organization.
34+
- Allow up to 24 hours for policies to take effect.
35+
36+
Once activated, policies begin tracking AI interactions based on configured rules. Results appear in DSPM reports and Activity Explorer after data processing. If a policy is deleted, it remains visible with a PendingDeletion status until fully removed.
37+
38+
1. Run Data Assessments
39+
40+
- DSPM for AI automatically runs weekly assessments on the top 100 SharePoint sites used by Copilot.
41+
- To create a custom assessment:
42+
- Go to Data Assessments (Preview) in Microsoft Purview.
43+
- Select Create Assessment and choose users and data sources to scan.
44+
- Run the assessment and allow up to 48 hours for results to appear.
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
Managing AI security risks requires tools that provide visibility, enforce policies, and prevent data exposure. **Microsoft Purview Data Security Posture Management (DSPM) for AI** helps organizations secure AI interactions, monitor AI-generated content, and ensure compliance with regulatory requirements.
2+
3+
It provides visibility into AI activity, security policies for AI interactions, and compliance controls to manage AI-related risks.
4+
5+
## Capabilities of Data Security Posture Management (DSPM) for AI
6+
7+
### AI insights and analytics
8+
9+
DSPM for AI provides visibility into how AI tools interact with organizational data. It provides:
10+
11+
- Identify which AI tools are in use, including Microsoft 365 Copilot and non-Microsoft AI services
12+
- Insights into data exposure risks in AI-generated content
13+
- Reports to help assess compliance and security posture
14+
15+
### Security policies for AI usage
16+
17+
DSPM for AI includes security policies that help prevent unauthorized data exposure in AI interactions. Policies can:
18+
19+
- Detect when users share sensitive data with AI tools
20+
- Block or warn users before sharing regulated or confidential data
21+
- Apply sensitivity labels and data loss prevention policies to AI-generated content
22+
23+
### Data assessments
24+
25+
DSPM for AI runs **weekly data assessments** for the top 100 SharePoint sites used by Copilot. These assessments help identify:
26+
27+
- Data that is frequently accessed or overshared
28+
- Files containing sensitive information that might be exposed through AI
29+
- Content missing appropriate labeling or governance controls
30+
31+
Organizations can also create custom assessments to scan specific users or sites for potential data exposure risks.
32+
33+
### Compliance controls
34+
35+
To support regulatory and security requirements, DSPM for AI integrates with other Microsoft Purview solutions, including:
36+
37+
- **[Sensitivity labels](/purview/sensitivity-labels)** to classify and protect AI-referenced data
38+
- **[Data classification](/purview/data-classification-overview)** to apply security controls based on content type
39+
- **[Customer Key](/purview/customer-key-overview)** for encryption with customer-managed keys
40+
- **[Communication compliance](/purview/communication-compliance-solution-overview)** to detect risky AI interactions
41+
- **[Auditing](/purview/audit-solutions-overview)** and **[eDiscovery](/purview/ediscovery)** for tracking AI activity and managing investigations
42+
43+
## Get started with DSPM for AI
44+
45+
To start using DSPM for AI:
46+
47+
- **Access the Microsoft Purview Portal**: Navigate to DSPM for AI from the Microsoft Purview portal or Microsoft Purview compliance portal.
48+
- **Review AI activity insights**: Identify AI usage patterns and potential data security risks.
49+
- **Activate preconfigured security policies**: Enable built-in policies to monitor and control AI interactions.
50+
- **Run data assessments**: Evaluate AI-related data exposure risks and implement remediation actions.
51+
- **Monitor compliance reports**: Use AI activity logs, security alerts, and policy reports to track AI risks over time.
52+
53+
DSPM for AI helps organizations manage AI-related security and compliance risks by applying the same security principles to AI-generated content as other enterprise data.

learn-pr/wwl-sci/purview-identify-mitigate-ai-risks/includes/introduction.md

Whitespace-only changes.
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
AI tools are changing how organizations work with data, but they also introduce security and compliance challenges. Traditional security controls weren't built to track how AI is used or what data it accesses. Without a way to see AI activity and apply security policies, organizations risk data exposure, compliance violations, and security gaps.
2+
3+
Managing AI-related security risks requires visibility into AI activity, protections for sensitive data, and policies to prevent unauthorized access or sharing. Key risks include data exposure, compliance challenges, and security vulnerabilities in AI interactions.
4+
5+
## Key AI security risks
6+
7+
AI interactions introduce security risks that require targeted protections. Visibility, data security, and compliance controls are critical to reducing these risks.
8+
9+
### Limited visibility into AI usage
10+
11+
Many organizations don't have a clear view of who is using AI tools, what data is being shared, or how AI-generated content is used. Without visibility, security teams can't:
12+
13+
- Identify which AI tools are being used (for example, Microsoft 365 Copilot, ChatGPT, Gemini)
14+
- Track what kind of data is being shared with AI models
15+
- Determine whether AI-generated content includes sensitive information
16+
17+
Without this information, it's difficult to assess security risks or apply the right protections.
18+
19+
### Data exposure in AI interactions
20+
21+
AI tools process user inputs and organizational data to generate responses. This creates risks such as:
22+
23+
- Sensitive data being entered into AI prompts without security controls
24+
- AI-generated responses containing confidential information
25+
- AI referencing or summarizing data that shouldn't be widely accessible
26+
27+
Organizations need security policies that apply to AI interactions to prevent unintentional data exposure.
28+
29+
### Compliance and regulatory risks
30+
31+
Many organizations must follow data protection laws and industry regulations, but AI interactions aren't always covered by existing security policies. Risks include:
32+
33+
- AI-generated content including regulated data
34+
- Employees sharing sensitive information with external AI tools
35+
- Lack of audit logs for AI activity, making compliance reporting difficult
36+
37+
Security teams need to ensure AI interactions follow the same compliance policies as email, file sharing, and other communication tools.
38+
39+
### AI-generated content security risks
40+
41+
AI doesn't just process data. It creates new content. That content can introduce security risks, including:
42+
43+
- Confidential information being included in AI-generated text
44+
- Inappropriate or noncompliant content being created and shared
45+
- AI-generated files being saved without tracking or security controls
46+
47+
Organizations need a way to monitor, apply policies to, and restrict AI-generated content when necessary.
48+
49+
## Addressing security gaps in AI usage
50+
51+
AI interactions introduce unique security risks that existing policies might not fully cover. Organizations need a way to:
52+
53+
- Identify when and how AI tools are used within their environment
54+
- Track and protect sensitive data in AI-generated content
55+
- Apply security policies to prevent unauthorized data exposure
56+
57+
Since AI tools process both user-provided inputs and existing organizational data, security teams need visibility into AI interactions and the ability to apply protections where needed.
58+
59+
Now that AI security risks are identified, it's important to understand how **Data Security Posture Management for AI** provides insights, policies, and controls to manage them.
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
### YamlMime:Module
2+
uid: learn.wwl.purview-identify-mitigate-ai-risks
3+
metadata:
4+
title: Identify and mitigate AI data security risks
5+
description: "Identify and mitigate AI data security risks."
6+
ms.date: 01/24/2025
7+
author: wwlpublish
8+
ms.author: riswinto
9+
ms.topic: module
10+
ms.service: purview
11+
hidden: false
12+
title: Use Microsoft Priva Tracker Scanning for web tracking complianceIdentify and mitigate AI data security risks
13+
summary: Microsoft Priva Tracker Scanning helps organizations identify, categorize, and manage web tracking technologies to ensure compliance and transparency. Learn how to configure Tracker Scanning, create and manage tracker categories, run scans to detect tracking technologies, and support responsible data practices aligned with user expectations.
14+
abstract: |
15+
After completing this module, you'll be able to:
16+
- Explain the purpose and benefits of Microsoft Priva Tracker Scanning.
17+
- Set up and configure Tracker Scanning to meet your organization's needs.
18+
- Create and manage tracker categories and assign trackers effectively.
19+
- Configure and run scans to detect tracking technologies and compliance objects.
20+
- Analyze scan results to address compliance issues and improve tracking practices.
21+
prerequisites: |
22+
- Familiarity with Microsoft 365 services.
23+
- Basic understanding of web trackers, cookies, and privacy compliance practices.
24+
iconUrl: /training/achievements/generic-badge.svg
25+
levels:
26+
- intermediate
27+
roles:
28+
- auditor
29+
- administrator
30+
- privacy-manager
31+
products:
32+
- microsoft-purview
33+
- m365
34+
subjects:
35+
- information-protection-governance
36+
- security
37+
units:
38+
- learn.wwl.purview-identify-mitigate-ai-risks.introduction
39+
- learn.wwl.purview-identify-mitigate-ai-risks.tracker-scanning-overview
40+
- learn.wwl.purview-identify-mitigate-ai-risks.configure-tracker-scanning
41+
- learn.wwl.purview-identify-mitigate-ai-risks.create-manage-trackers
42+
- learn.wwl.purview-identify-mitigate-ai-risks.run-a-scan
43+
- learn.wwl.purview-identify-mitigate-ai-risks.view-scan-results.md
44+
- learn.wwl.purview-identify-mitigate-ai-risks.knowledge-check
45+
- learn.wwl.purview-identify-mitigate-ai-risks.summary
46+
47+
badge:
48+
uid: learn.wwl.purview-identify-mitigate-ai-risks.badge
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-identify-mitigate-ai-risks.introduction
3+
title: Introduction
4+
metadata:
5+
title: Introduction
6+
description: "Introduction"
7+
ms.date: 2/6/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 1
14+
content: |
15+
[!include[](includes/introduction.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-identify-mitigate-ai-risks.understand-ai-security-risks
3+
title: Understand AI security risks
4+
metadata:
5+
title: Understand AI security risks
6+
description: "Understand AI security risks."
7+
ms.date: 2/6/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 4
14+
content: |
15+
[!include[](includes/understand-ai-security-risks.md)]

0 commit comments

Comments
 (0)