What's new in Microsoft Purview
Whether it be adding new solutions to the Microsoft Purview governance or compliance portals, updating existing features based on your feedback, or rolling out fresh and updated documentation, Microsoft Purview helps you stay on top of the ever-changing data governance and risk and compliance areas. Take a look at the following information to see what's new in Microsoft Purview.
Tip
If you're not an E5 customer, use the 90-day Microsoft Purview solutions trial to explore how additional Purview capabilities can help your organization manage data security and compliance needs. Start now at the Microsoft Purview compliance portal trials hub. Learn details about signing up and trial terms.
March 2024
The Microsoft Purview portal (in preview) is being gradually updated with solutions from the compliance portal. Where relevant, the documentation now includes configuration steps for both portals.
Communication compliance
- New: Consolidated content page shows how to configure a communication compliance policy to detect for Copilot for Microsoft 365 interactions.
- In preview: New Policy Health tab provides insights into potential issues or optimizations for your communication compliance policies.
- Updated: Period of time required to process Viva Engage chats with and without attachments.
- Updated: Clarifications for:
Insider risk management
- In preview: Adaptive protection in insider risk management now supports Microsoft Entra Conditional Access policies in addition to Microsoft Purview data loss prevention (DLP) policies. For example, by using adaptive protection together with Conditional Access, you can:
- Require Minor risk level users to acknowledge Terms of Use before using an application.
- Block Medium risk level users from accessing certain applications.
- Completely block Elevated risk level users from using any applications.
- In preview: Admin units are now supported for insider risk management. Use admin units to scope user permissions to a region or department.
- In preview: Capture forensic evidence clips related to Enhanced Phishing Protection in Microsoft Defender SmartScreen. For example, capture when a user enters the Microsoft password they used to sign into their Windows 11 device on a phishing site or application connecting to a phishing site.
- Updated: New restrictions on who can be added as a contributor to a case and what contributors have permission to do.
- Clarification: Added info related to role-based access controls and how admins can use the inline alert customization setting to allow investigators and analysts to make edits to policy indicators and thresholds.
Sensitivity labels
- General availability (GA): Sensitivity labels for groups & sites have new options to support private teams discoverability and channel sharing controls for invitations to other teams.
February 2024
Communication compliance
- Updated: Create and manage communication compliance policies to clarify that Teams message remediation is not supported if a user reports a message that was sent before they were added to a chat.
Compliance Manager
- Updated the Compliance Manager regulations list with the following recent additions:
- India Digital Personal Data Protection Act
- ISO/IEC 27001:2022
- Microsoft Cloud Security Benchmark v1
- NATO Directive AC/322-D(2021)0032
- NIS2 Directive (EU) 2022/2555 of the European Parliament and of the Council
Data lifecycle management and records management
- General availability (GA): Rolling out, you can now change the retention period of an existing retention label when the retention period is based on when items were labeled.
Insider risk management
Updated: Investigate insider risk management activities to clarify that insider risk management creates a single aggregated alert per user.
Updated: Create and management insider risk management policies to clarify that you must have the Insider Risk Management or the Insider Risk Management Admins role to access policy health.
Sensitivity labels
- General availability (GA): Teams mobile apps now support calendar items for protected meetings.
- In preview: Sensitivity labels for groups & sites have new options rolling out to support private teams discoverability and channel sharing controls for invitations to other teams.
- Rolling out: The Encryption page when you configure a sensitivity label is renamed Access control. There are no changes to the existing settings for encryption.
Service Trust Portal
- Updated reports, whitepapers, and artifacts with a new category of AI Resources.
January 2024
Communication compliance
- In preview: Test conditions when you create or edit a policy before rolling the policy out to the wider organization.
- Updates to note that mail-enabled security groups are now supported.
- Updates to clarify the implication of choosing Inbound as the communication direction for Teams channel communications.
Compliance Manager
- Updated Compliance Manager scoring to clarify how technical and nontechnical improvement actions are scored.
Data loss prevention
The name of the DLP settings control has been changed from "Settings" to "Data loss prevention settings" Configure endpoint data loss prevention settings
Updated content to cover the significant enhancements that have been made to the Advanced customization and Preview for DLP end-user email notification features for SharePoint, OneDrive and Exchange. You can now:
- Decide whether the matching email messages should be included or excluded in the end-user notification emails.
- Leverage tokens from the expanded token library.
- Customize the sender's display name, email subject and email body.
- Preview notifications before sending them to end users.
Preview: Support has been added for two new endpoint conditions:
- Document propery is
- Document name contains words or phrases
Insider risk management
- In preview: Use real-time analytics recommendations to efficiently adjust the selection of indicators and thresholds of activity occurrence so that you don't have too few or too many policy alerts. If you adjust threshold settings manually, select View impact to display a graph that provides sensitivity analysis for each policy indicator.
Sensitivity labels
- General availability (GA): iOS and Android now also support converting a labeled Office document into a PDF document, inheriting the sensitivity label with any content markings.
December 2023
Audit
- Microsoft 365 Copilot clarification for activities that are logged in the Microsoft 365 audit log.
Communication compliance
- Updated Copilot for Microsoft 365 content to include information about choosing a location and using the new Detect Copilot for Microsoft 365 interactions template.
- In preview: The New pending today column shows the number of policy matches for the current day.
- In preview: Added information on the new content safety classifiers for Teams. These four new classifiers, which are based on large language models, include Hate, Sexual, Violence, and Self-harm.
Data lifecycle management and records management
- In preview: Support for sites using Microsoft 365 Archive. For more information, see How retention works with Microsoft 365 Archive.
- Improvements to auto-apply retention label policies for sensitive information: Rolling out, you can now include or exclude specific Exchange mailboxes when you configure an auto-apply retention label policy for sensitive information. This policy update for both static and adaptive scopes provides parity with the other retention conditions for Exchange mailboxes.
Data loss prevention (DLP)
- Block the sharing of sensitive items via SharePoint and OneDrive in Microsoft 365 with external added.
- Guidance on how to aviod excessive policy-evaluation and check-complete notifications due to classification latency. Sensitive service domain groups.
- Preview [DLP alerts can include Insider Risk Management user risk]Investigate a DLP alert summary contextual information.
- In preview: Endpoint DLP support has been extended to four new conditions:
- Document size equals or is greater than
- Document name matches patterns
- Document could not be scanned
- Scanning did not complete
- Added discussion of halting and non-halting actions in Microsoft Exchange, including a table specifying the halting/non-halting behavior for each supported action.
eDiscovery
- NEAR keyword search operator example correction and clarification on how the distance between terms is defined.
- Content search preview item viewed activity removed from Microsoft 365 audit log for eDiscovery.
- Permission clarification for SAS tokens when exporting documents from a review set.
- Clarification on how to use the eDiscovery RBAC Check test tool.
- Clarification on how to use spaces and the OR operator in eDiscovery searches.
- Example update for the New-ComplianceSecurityFilter cmdlet when filtering content search results.
- Clarification that previews of Teams Video Clips aren't currently supported in eDiscovery.
- Added new information about managing custodian UPNs. If the UPN of a custodian changes after the custodian is added to a case, the custodian information (Title, Manager, Location, etc.) isn't retained and is displayed in the custodian summary pane as No data to show.
- Content retired: The User Data Search case tool has been retired and its functionality has merged with eDiscovery (Standard). You can now use content to search for content to support DSRs all locations supported by eDiscovery (Standard) searches.
- Content retired: The Migrate legacy eDiscovery searches and holds to the Microsoft Purview compliance portal topic was retired. The Get-MalboxSearch cmdlet isn't supported in eDiscovery, doesn't return all details older searches.
Exact data match (EDM) sensitive information types (SITs)
- Added support for multi-token matching, which allows you to detect exact data matches in fields that contain more than one string, for instance, when you have an
Address
field containing values such asOne Microsoft Way
or1234 Main Street
.
Insider risk management
- In preview: Added information on new Data share setting that you can use to share user risk severity levels from insider risk management with DLP alerts and Microsoft Defender.
- New triage attributes: Use the new attributes when filtering alerts on the Alert dashboard.
- Updated adaptive protection article to include info on how risk level is assigned if a user is in scope for multiple policies.
Microsoft Copilot for Microsoft 365
- Short video added to the Copilot protection with sensitivity label inheritance documentation, which demos how drafting with Word can update the default sensitivity label after referencing a file with a higher priority label.
Sensitivity labels
- General availability (GA): Outlook Mobile now supports calendar items for protected meetings.
- Improvements for Office on the web for labeled and encrypted documents: When screen captures are prevented for labeled and encrypted documents by not granting the user the Copy usage right, the previous exceptions for relabeling scenarios no longer apply for Office on the web. Now, the behavior matches the desktop apps.
November 2023
Announced at Microsoft Ignite
The following new Microsoft Purview capabilities are announced at Microsoft Ignite:
- Support for Microsoft Copilot: Microsoft Purview strengthens your data security and compliance for Microsoft Copilot for Microsoft 365.
- In preview: The Microsoft Purview portal has a new look and capabilities to help you govern and protect your data, wherever it lives.
Communication compliance
- General availability (GA): Support for Microsoft Copilot for Microsoft 365.
- Report this conversation for Viva Engage: Communication compliance now has a Report conversations option for Viva Engage.
- Conversation view: You can now load up to 20 messages before and after a message, and download a conversation.
Data lifecycle management and records management
- General availability (GA): You can programmatically apply and manage retention labels for SharePoint and OneDrive by using Microsoft Graph API to lock and unlock records, set retention labels, remove retention labels, and get metadata for retention labels.
- General availability (GA): Microsoft Copilot interactions can be retained or deleted with a retention policy for Teams chats and Copilot interactions.
- General availability (GA): The versions of files referenced in an interaction for Microsoft Copilot can be retained as a cloud attachment with an auto-apply retention label policy.
- New guidance: Learn about retention for Microsoft Copilot for Microsoft 365.
Data Loss Prevention
In preview: Simulation mode for Microsoft Purview Data Loss Prevention (DLP) policies replaces the Test and Test with policy tips policy states. When a policy is in simulation mode, it's run as if it were being enforced, without any actual enforcement.
In preview: Links to advanced hunting are available for DLP alerts in Microsoft Defender XDR.
In preview: Addition filters for data loss prevention alerts in the Defender portal.
- In preview: Enhanced customization of email notifications to end users for Microsoft 365 services. We've added multiple tokens, and enhanced editing experience and email preview.
In preview: Microsoft managed storage for DLP evidence. When saving evidence of the matches detected by your DLP policies, you can now use Azure blob storage managed by Microsoft as an alternative to creating an Azure blob that you manage yourself.
General availability (GA): Optical character recognition (OCR) scanning enables Microsoft Purview to scan content in images for sensitive information.
Information protection
- New graphic added to Consider a phased deployment to conceptually illustrate a phased deployment of sensitivity labels and DLP policies that become more integrated, and with more restrictive controls.
Insider risk management
- Updated the maximum number of policies available for any template from five to twenty.
- For custom indicators, clarified the waiting period required before uploading data after custom indicators and associated policies have been updated.
Microsoft Priva
- In preview: Identify duplicates, apply actions once to all duplicate items, and filter duplicates from view when reviewing data for a subject rights request.
Sensitivity labels
- General availability (GA): Sensitivity labels are recognized and used by Copilot for Microsoft 365 to provide an extra layer of protection for your organization's data.
October 2023
Adaptive scopes
New guidance: How adaptive scopes work with Microsoft Entra administrative units
Communication compliance
- Clarified when a user-reported messages policy is implemented for an organization.
- Clarified limitations for recurring and unscheduled meetings when reviewing Teams meetings transcripts.
Data lifecycle management and records management
- General availability (GA): Customize what happens at the end of the retention period by running a Power Automate flow.
- New guidance for migrating from older SharePoint features: Migration strategies for moving to Microsoft Purview risk and compliance solutions
Data loss prevention
In preview:
- New JSON code example for setting up Investigator data actions on Azure blob storage
- Support for ARM64 Endpoint devices
General availability (GA)
- New methods for testing exact data match (EDM) sensitive information types (SITs):
- Added instructions for assigning permissions and role groups for testing SITs
Insider risk management
- Added a new section on how events excluded from risk scoring are handled for sequences.
- Clarified how to specify multi-level subdomains for a root domain when creating a domains detection group.
Microsoft Priva
- In preview: New assisted redaction and search and redact capabilities for subject rights requests.
- In preview: Advanced filtering for data collected for subject rights requests.
- Email notifications for policy matches can now be customized as sent from an organization's email address instead of from Microsoft.
Sensitivity labels
- General availability (GA): Outlook on the web supports the sensitivity bar and label colors.
- General availability (GA): PDF support for auto-labeling policies, default sensitivity labels for SharePoint document libraries, and labeling activities in Office on the web that include manual labeling and displaying labeled documents, and encrypted PDFs that are now supported for DLP, eDiscovery, and search. You must opt-in for this PDF support.
- General availability (GA): Now in Current Channel, in Word, Excel, and PowerPoint for Windows and Mac, users can no longer select Information Rights Management (IRM) options that can override your sensitivity label encryption settings. Instead, users are prompted to apply a sensitivity label. For more information, see the updated section, Information Rights Management (IRM) options and sensitivity labels.
- Updated guidance:
- For auto-labeling policies, added a callout note that simulation results might not include expected files because they were updated after simulation ran.
- New requirement for a default sensitivity label for a SharePoint document library that files must contain content to be labeled. Empty files are labeled when they are updated with content.
- Clarification that sensitivity labels to protect meetings don't extend to related meeting items, such as recordings, transcripts, whiteboard, and tasks.
- The Label priority (order matters) section is updated to reflect the updated UI that displays Priority instead of Order for the Labels page of the Microsoft Purview compliance portal.
d06cf19419544fdbfff8ce8f7e6788f66182ab26
September 2023
Audit
- Added new Microsoft Graph Data Connect audit activities for user and admin activities.
- Clarified the audit activities for Microsoft Teams that are available in commercial versus government subscriptions.
Communication compliance
- In preview: Review Teams meetings transcripts for actionable alerts.
- Update for new feature that highlights the condition that caused a policy match when you select a message on the Pending or Resolved tab.
- Update to clarify the image sizes supported for detection.
- Update to clarify the retention limit for Filter email blasts reports.
Compliance Manager
- Improvement actions have a new design to make it easier to digest status information and record implementation and testing work.
- Improvement actions no longer support the "parent" testing type, which linked the test status to that of another action.
- The page formerly titled "Compliance score calculation" has been renamed Compliance Manager scoring, and has updates to clarify action types and scoring.
Data lifecycle management and records management
- General availability (GA): Support for administrative units—for both data lifecycle management and records management.
- In preview: Now in beta, you can programmatically apply and manage retention labels for SharePoint and OneDrive by using Microsoft Graph API to lock and unlock records, set retention labels, remove retention labels, and get metadata for retention labels.
Data loss prevention
Named entities are now supported on government clouds. The full list of supported clouds now includes:
- Microsoft Commercial Cloud
- Microsoft Government Community Cloud
- Microsoft 365 Government Community Cloud High
- Microsoft 365 Department of Defense
General availability (GA): Just-in-time protection for Endpoints is now generally available.
eDiscovery
- In preview: New Microsoft Teams support as a non-custodial data source.
- Updates to clarify the behavior of disabled user accounts in hold tracking mailbox diagnostic logs.
- Updated subscription and licensing requirements for litigation holds.
- Clarified support for SharePoint sites and historical versions in multi-geo environments.
- Updated for managing custodial and non-custodial holds and associated data sources.
- Clarification on how to select all SharePoint sites in a content search.
- Updates to clarify that anonymous users that join Microsoft Teams meetings are currently supported in search queries.
- Updates to clarify AZCopy version support for error remediation when processing data.
- Clarification about reported differences in draft collections for the number of locations with hits and the total number of Exchange mailboxes, SharePoint and OneDrive sites, or Exchange public folders searched.
- Updates for the requirement that the folder ID in the targeted collection script must be in hexadecimal (HEX) value format.
- Updates that jobs listed on the jobs report page can't be deleted or removed. Long-running jobs automatically time out after 7 days.
Information barriers
- Updated subscription and licensing references in all articles.
Information protection
- New guidance: Deployment strategies
Insider risk management
- Update on details for Date/Time fields when creating a connector that imports third-party insider risk detections.
- Update to clarify amount of time required before uploading data after creating an Insider Risk Indicators connector.
- Update to change the minimum number of vCPU processors required for Hyper-V and virtual machines.
Microsoft Priva
- Privacy Risk Management policies now allow users to select trainable classifiers as a data source to monitor when creating policies.
Sensitive information types
- Two new sensitive information types have been added:
Sensitivity labels
- General availability (GA): In SharePoint and Teams, you can see and apply sensitivity labels to documents by using the details pane.
- General availability (GA): The following new conditions are now generally available for auto-labeling policies. Just the final new condition listed requires an advanced rule, and is applicable to OneDrive and SharePoint only. All the other new conditions are available in common rules:
- Attachment or file extension is
- Attachment or document name contains words or phrases
- Attachment or document property is
- Attachment or document size equals or is greater than
- Document created by
Feedback
https://aka.ms/ContentUserFeedback.
Coming soon: Throughout 2024 we will be phasing out GitHub Issues as the feedback mechanism for content and replacing it with a new feedback system. For more information see:Submit and view feedback for