Security1 publisher2 min readPublished
Microsoft extends Purview data blocking to the network layer for employees and their AI agents
Microsoft's Purview and Entra Global Secure Access can now block sensitive uploads to unsanctioned AI tools at the network layer, for users and agents. Licensing is not in the announcement, so tenants cannot yet tell whether it is a setting or a purchase.
The Watch · Security desk

What happened
- Microsoft made network-layer data security in Purview and Entra Global Secure Access generally available for both human actions and on-behalf-of agent traffic.
- Entra enforces Purview's context-aware classification and policies at the network layer, detecting sensitive files and text in real time.
- In Microsoft's example, a policy stops an employee or agent from uploading a sensitive document to an unsanctioned AI tool before the data leaves.
- Purview auto-labeling policies can now simulate across up to 20 million items and 50,000 sites, and admins can edit a policy without re-running the simulation.
- Archived inactive SharePoint content stays under retention and legal hold but drops out of Microsoft 365 Copilot indexing until it is reactivated.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Budget owners in Microsoft shops cannot yet tell whether shadow-AI blocking needs a new purchase, so rollout plans wait on Microsoft's licensing terms.
- capability According to Microsoft, a Purview shop can govern agent uploads to unapproved AI tools with the same data-loss policies it writes for staff.
- constraint Content removed by Priority Cleanup is also gone from eDiscovery, so legal and records teams have to approve any cleanup meant to shrink what Copilot can surface.
Scope follows the enforcement point. Entra applies the Purview policy at the network layer [2], so a rollout starts with mapping which users, devices and agents send their traffic through Global Secure Access.
Licensing decides who can use it. Microsoft's post does not say which licences the network feature needs, or how a destination comes to be classed as risky [12]. The same post does state a prerequisite for a different item. Its new email detonation summary, AI-written explanations of URL and file sandboxing results, is available only to organisations running both Defender and Security Copilot [10].
Agent traffic is the part that reaches incident response. Microsoft opens the release by saying AI agents now run on employee devices, cloud platforms and developer workflows, and that security teams need to see them, govern what they can reach and contain them when something goes wrong [5]. The network control is where Microsoft applies that to data. According to the company, the same Purview policy covers a human upload and an on-behalf-of agent upload [1].
Nothing in this item needs a patch window. It is a new data-loss control, generally available as of this release [1], aimed at ordinary leakage to unapproved AI tools [4]. How well it blocks is described only in Microsoft's own post [1].
For investigations, eDiscovery can now search, hold, review and export content in user-owned SharePoint embedded containers, including Loop, Copilot Pages and Copilot Notebooks. Investigators no longer have to ask a SharePoint administrator for the container URL [9]. An optional HTML conversion produces a more readable version for downstream legal tools [9].
Microsoft also says Intune Enterprise Application Management, Cloud PKI and Remote Help are coming to GCC High, with Enterprise Application Management also offered to Department of Defense organisations [11].
What to watch
- Microsoft licensing terms for the Purview and Entra network control, to see whether existing tenants can enable it without a new purchase.
- How Microsoft defines a risky destination or unsanctioned AI tool, and whether administrators control that list.
- Any independent test of whether on-behalf-of agent uploads are caught as reliably as human ones.