DSPM for AI: Setup & Controls
Data Security Posture Management for AI is the newest domain in SC-401. Configure prerequisites, roles, and Microsoft Purview controls that protect your organisation's data from exposure through AI services like Copilot.
Why AI needs data security controls
Think of Microsoft Copilot as a super-capable new employee who can read everything.
When you deploy AI services like Copilot, the AI can access the same data your users can — emails, documents, Teams messages, SharePoint sites. If a user has access to 50,000 files, Copilot can summarise, search, and reference all 50,000.
The problem? Oversharing + AI = amplified risk. A file shared with “Everyone” that nobody ever found manually suddenly surfaces in a Copilot response. Sensitive data that was hidden by obscurity is now one prompt away from exposure.
DSPM for AI helps you see what data AI can access, discover oversharing, fix permissions, and monitor how AI interacts with your sensitive content.
The AI data risk landscape
| Risk | What Happens | Example |
|---|---|---|
| Oversharing amplified by AI | Files shared with broad permissions surface in AI responses | A salary spreadsheet shared with “Everyone except external” appears in a Copilot summary when someone asks “what do senior managers earn?” |
| Unlabelled sensitive data | AI accesses sensitive content that has no label or protection | Patient data in an unlabelled Word doc gets included in a Copilot-generated report |
| Stale permissions | Former project members still have access, and AI uses that access | A departed employee’s SharePoint access lets Copilot surface their project data to current users |
| AI-generated content risks | AI creates new content from sensitive sources | Copilot generates a meeting summary that includes confidential project details from a labelled document |
Prerequisites for DSPM for AI
| Prerequisite | Detail |
|---|---|
| Licensing | Microsoft 365 E5, E5 Compliance, or E5 Information Protection and Governance |
| Microsoft Purview portal access | Admin must have appropriate Purview roles |
| Sensitivity labels deployed | DSPM recommendations rely on labels being in use |
| Audit logging enabled | Required to capture AI interaction events |
| Microsoft 365 Copilot deployed (for M365 AI monitoring) | Copilot must be licensed and active for AI activity monitoring |
Roles and permissions
| Role | DSPM for AI Capability |
|---|---|
| Compliance Administrator | Full access to DSPM for AI — view reports, configure policies, manage recommendations |
| Information Protection Admin | Manage sensitivity labels and DLP policies that DSPM references |
| Security Reader | View DSPM reports and recommendations (read-only) |
| Global Reader | View-only access across the portal |
Purview controls for AI environments
1. Sensitivity labels — the first line of defence
Sensitivity labels control what AI can do with labelled content:
| Label Setting | AI Impact |
|---|---|
| Encryption | Copilot respects encryption — users without access cannot get AI summaries of encrypted content |
| Content marking | Headers/footers/watermarks persist in AI-generated outputs from labelled sources |
| Label inheritance | When Copilot creates content based on labelled sources, the output should inherit the source label |
2. DLP policies — protect AI interactions
DLP can monitor and control AI interactions:
| DLP Capability | AI Application |
|---|---|
| Monitor AI-generated content | Detect when Copilot outputs contain sensitive data matching SITs |
| Block sensitive data in AI responses | Prevent Copilot from surfacing content matching specific SITs |
| Alert on AI data exposure | Generate alerts when AI accesses or references sensitive content |
3. Oversharing prevention
DSPM for AI identifies and helps remediate oversharing:
| Control | What It Does |
|---|---|
| Permission reviews | Identify files shared with “Everyone” or broad groups that contain sensitive data |
| Access clean-up recommendations | Suggest removing excessive permissions before AI amplifies the exposure |
| Label recommendations | Identify unlabelled sensitive content that AI could surface without restrictions |
Microsoft 365 workload controls
Beyond Purview-level settings, each M365 workload has controls relevant to AI:
| Workload | AI-Relevant Control |
|---|---|
| SharePoint | Restricted access control for sites — limits which sites Copilot can reference |
| OneDrive | Sensitivity labels on files determine Copilot’s access |
| Teams | Meeting sensitivity labels control whether Copilot can generate meeting summaries |
| Exchange | Sensitivity labels on emails control Copilot’s access to email content |
Scenario: Marcus prepares NovaTech for Copilot
NovaTech is deploying Microsoft 365 Copilot to all 800 employees. Marcus, the Security Architect, uses DSPM for AI to prepare:
- Assessment: DSPM scans NovaTech’s M365 environment and finds:
- 12,000 files shared with “Everyone” — 340 contain source code
- 8,500 unlabelled documents containing PII or IP
- 45 SharePoint sites with stale permissions (former employees still have access)
- Remediation: Marcus fixes permissions, auto-labels the 8,500 documents, removes stale access
- Controls: Configures DLP to monitor Copilot interactions containing source code SITs
- Go-live: Copilot deploys with clean permissions, labelled data, and active monitoring
Exam tip: DSPM for AI is about readiness, not blocking
DSPM for AI is NOT about preventing AI adoption. It is about ensuring your data security posture is ready for AI:
- Discover: What sensitive data can AI access?
- Assess: Where are the gaps in labeling, permissions, and protection?
- Remediate: Fix oversharing, apply labels, remove stale access
- Monitor: Track AI interactions with sensitive data ongoing
Exam questions focus on DSPM as a preparation and monitoring tool, not as an AI blocker.
NovaTech is deploying Microsoft 365 Copilot. DSPM for AI reveals that 12,000 files are shared with 'Everyone' and 340 of those contain source code. What should Marcus do BEFORE enabling Copilot?
Priya at Meridian Financial wants to ensure that when Copilot summarises documents labelled 'Highly Confidential', the summaries inherit the same protection. Which control achieves this?
🎬 Video coming soon
Next up: DSPM for AI: Policies & Monitoring — configure DSPM policies and monitor how AI services interact with your sensitive data.