Summer roundup, part 3: Data protection and compliance updates in Microsoft 365

In the first two installments of this summer roundup series, I focused primarily on Microsoft 365 Copilot, Teams, and productivity features. This time, I'm turning my attention to security, compliance, and data protection.

Over the summer, Microsoft announced a couple of changes that security and compliance teams should be aware of. Some of these updates expand visibility into user activity across cloud platforms, while others are designed to make policy enforcement more transparent for end users. In this post, I'll look at new insider risk monitoring capabilities in Microsoft Purview and a small but important improvement to how Microsoft 365 Copilot communicates Data Loss Prevention (DLP) policy enforcement.

Microsoft Purview expands insider risk monitoring across multi-cloud environments

Microsoft is expanding Microsoft Purview Insider Risk Management (IRM) with new data leak policy triggers that incorporate activity signals from Microsoft Fabric, cloud storage platforms such as Box, Dropbox, and Google Drive, and cloud services including Microsoft Azure and Amazon Web Services (AWS). The new triggers can be used within Insider Risk Management data leak policies to identify users for policy scope and contribute to risk evaluation, helping organizations extend insider risk monitoring beyond Microsoft 365 into multi-cloud and analytics environments. The feature is available through the existing Data Leaks policy template and must be configured by administrators before it becomes active.

The feature reached General Availability in July 2026 and is associated with Microsoft 365 Roadmap ID 560399.

More information:

Microsoft 365 Copilot will show consistent messages when DLP policies block content

Microsoft is introducing a standardized user message across Microsoft 365 Copilot experiences whenever a Microsoft Purview Data Loss Prevention (DLP) policy prevents Copilot from accessing, processing, or returning content. The change applies to several Copilot-related DLP protections, including Grounding DLP, Prompt DLP, and External Email DLP, and will appear across Microsoft 365 Copilot, Copilot Chat, and other Copilot experiences that use Microsoft 365 Chat orchestration. By providing a consistent notification that content has been restricted by an organizational policy, Microsoft aims to improve transparency and help users distinguish between policy enforcement and potential service issues.

The standardized message appears automatically when DLP policies restrict Copilot's access to content, including scenarios involving sensitive prompts, blocked web searches, protected files, or excluded email content. In some cases, users may also receive a link with additional information about the applicable policy restriction. No additional configuration is required, and existing DLP protections remain unchanged.

The feature became generally available in July 2026 across commercial, GCC, GCC High, and DoD environments.

More information:

That wraps up the third installment of this summer roundup series. Thanks for taking the time to read. If you'd like to stay up to date with Microsoft 365, Microsoft Entra, security, compliance, and Copilot-related announcements, you can follow me on LinkedIn.

Comments