Published Jan 13, 2026
The Data Security Posture Agent, available in public preview from December 24, 2025, uses LLMs to discover sensitive data and assess risks in Microsoft Purview. It offers GenAI summaries, risk insights, and requires admin setup. General availability begins late May 2026.
Updated March 23, 2026: We have updated the timeline. Thank you for your patience.
Introduction
We’re introducing the Data Security Posture Agent, available in public preview December 24, 2025. This agent helps data security admins proactively discover sensitive data across your organization’s data estate and assess associated risks. By leveraging large language models (LLMs), it goes beyond traditional keyword-based analysis to understand the purpose and context of content, enabling more accurate risk identification and actionable insights.
This message is associated with Roadmap ID 542188.
When this will happen:
How this affects your organization:
Who is affected: Admins managing data security and compliance in Microsoft Purview.
What will happen:
What you can do to prepare:
Learn more:
Compliance considerations:
| Question | Explanation |
|---|---|
| Does the change alter how existing customer data is processed, stored, or accessed? | The agent analyzes documents, emails, and messages to identify sensitive data and assess risk. |
| Does the change introduce or significantly modify AI/ML or agent capabilities that interact with or provide access to customer data? | Introduces LLM-powered discovery and risk assessment. |
| Does the change provide end users any new way of interacting with generative AI? | Admins receive GenAI-generated summaries and LLM-assisted tasks. |
| Does the change include an admin control and can it be controlled through Entra ID group membership? | Setup requires admin roles in Microsoft Purview. |