Data is the most valuable asset enterprises possess, yet for most organizations, it remains ungoverned, undiscovered, and untrustworthy. Regulatory scrutiny has never been higher. GDPR fines exceeded €4.2 billion in 2023.
Microsoft Purview has evolved significantly since its launch in 2022. As of early 2026, it is no longer merely a data catalog, it is Microsoft’s unified data security, governance, and compliance platform for the era of AI. New capabilities including Data Security Posture Management (DSPM), AI Observability for agents, and the Generally Available Unified Catalog have fundamentally expanded what Purview can do for enterprise data programs.
This white paper is written for data architects, Chief Data Officers, compliance leaders, and senior engineers who need a current, production-grade reference. It reflects the state of the platform as of Q1 2026, incorporating AI governance capabilities, updated terminology (Microsoft Entra ID, not Azure Active Directory), and the latest Fabric integration innovations announced March 2026.
Key insight: Microsoft Purview is not merely a data catalog, it is an integrated governance, risk, and compliance (GRC) platform that creates a closed-loop governance operating model. As of 2026, it is also your primary control plane for AI data risk. Organizations that treat it as only a catalog leave 60% of its capability untapped.
Most governance programs fail not because of lack of intent, but because of architectural sprawl. Governance teams operate spreadsheets, data stewards work in isolation, and lineage is tracked manually if at all. The root causes are structural:
Federated data ownership without centralized metadata: Business units own data but metadata lives nowhere.
Tool fragmentation: Organizations accumulate Collibra, Informatica, Alation, Apache Atlas, and custom wikis, each partial, none authoritative.
Classification as a one-time project: Point-in-time inventories that decay immediately as new data arrives.
Compliance as reactive audit response: Evidence collection happens at audit time, not continuously.
AI data flows with no governance: Copilot prompts, agent responses, and AI-generated data traverse the estate invisibly, a new and rapidly growing gap.
Data estate inventory export, lineage documentation
Asset inventory report; consent metadata tagging
PCI-DSS v4.0
Cardholder data scoping, encryption, access logging
Sensitive info type: Credit card, DLP policies, encryption insights
Data map export; DLP incident reports
EU AI Act
AI system risk classification, data quality for AI training
DSPM AI observability, Unified Catalog data quality, agent governance
Agent risk inventory; data quality scan reports
ISO 27001:2022
Information classification, asset inventory, supplier management
Full data catalog, sensitivity labels, third-party scanner integration
Control mapping export from Compliance Manager
War story: A global bank with 47 data sources spent 11 weeks preparing for a GDPR audit. After deploying Purview with automated scanning, the same audit was prepared in 4 days, with full lineage documentation. Annual compliance preparation cost reduced from $1.8M to $340K.
Chapter 2: Microsoft Purview: Platform architecture (2026)
The Data Map’s scanning engine is the foundation of Purview governance. Understanding scan architecture is critical to building a reliable governance program. Three scan execution models are available:
Managed Virtual Network (MVNet), Recommended: Purview manages the integration runtime within a Microsoft-managed VNet. No infrastructure to deploy. Best for most Azure-native deployments.
Self-Hosted Integration Runtime (SHIR): Customer-deployed VM running the Purview runtime agent. Required for on-premises sources, private network sources, and non-Azure cloud sources.
Azure Integration Runtime (AIR): Used for public-endpoint Azure sources. Not recommended for sensitive environments.
The Microsoft Purview Unified Catalog reached General Availability in late 2025, consolidating data discovery into a single experience and replacing the previous bifurcated catalog model. Key advances over the prior catalog:
Automated access workflows replace manual approval chains for data product access requests and glossary term publishing.
Built-in data quality tools: measure, monitor, and remediate issues such as incomplete records, inconsistencies, and redundancies.
Critical Data Column table: new self-service analytics capability allowing users to report glossary terms and concepts associated with data asset columns.
Data quality error record publishing to cloud storage: generally available in all supported Azure regions, enabling dashboards and continuous improvement tracking.
Integration with external catalogs: Fabric OneLake, Databricks Unity Catalog, and Snowflake Polaris metadata can be unified into a single view.
A well-designed glossary is the semantic backbone of the catalog. Flat glossaries fail at scale, a 2,000-term flat list is unsearchable. Structure terms in a parent-child hierarchy:
Data lineage answers the questions that matter most: ‘Where does this metric come from?’, ‘What would break if we changed this table?’, ‘How was this data transformed?’
Automated lineage (preferred): Purview automatically extracts lineage from ADF, Synapse Spark, Synapse Pipelines, Fabric Dataflows, and Power BI. Zero code required.
SQL-based lineage parsing: Purview parses stored procedures, views, and CTAS statements for column-level lineage. Supports Azure SQL Database, Synapse Dedicated Pool, SQL Server.
Custom lineage via Atlas API: For dbt, custom Spark jobs, Informatica, Talend, lineage submitted programmatically via the Apache Atlas REST API.
Fabric lineage (recommended 2025+): Column-level lineage through Lakehouse, Warehouse, Dataflows, and Power BI reports in a single unbroken chain.
Lineage troubleshooting: If lineage gaps appear between lakehouse and warehouse, ensure Fabric warehouse is using shortcuts to lakehouse (not COPY INTO). COPY INTO breaks automated lineage, use lakehouse shortcuts or dataflows instead.
Chapter 5: Data Security Posture Management & AI governance
This chapter covers what is arguably the most significant expansion of Purview in 2025-2026: Data Security Posture Management (DSPM) and AI governance capabilities. These address risks that traditional data governance tools were never designed to handle.
The new DSPM experience (public preview December 2025, GA target April 2026) unifies the previous DSPM classic and DSPM for AI classic experiences into a single, outcome-based platform:
Outcome-based guided workflows: Choose a data security objective and receive step-by-step remediation guidance.
AI Observability: A dedicated inventory of all AI apps and agents, including first-party (Copilot Studio, Azure AI Foundry), third-party, and custom-built agents, with activity in the last 30 days, risk levels, and sensitive interaction counts.
Item-level remediation: Bulk disable overshared SharePoint links, apply sensitivity labels, and activate protection policies directly from DSPM.
External platform visibility: Third-party signals from Salesforce (Varonis), Databricks (BigID), Snowflake (Cyera), and Google Cloud Platform (OneTrust) surface in a unified view via Microsoft Sentinel Data Lake.
Advanced reports: Instant visibility into sensitivity label coverage, DLP policy activity, and posture trends with drill-down filters.
AI agents are now first-class entities in Purview’s governance model, not afterthoughts:
Capability
What it does
Applies to
AI observability
Inventory of all AI apps and agents; risk level assignment per agent; sensitive interaction count
Copilot Studio, Azure AI Foundry, third-party agents, agent 365
Agentic risk in IRM
Agent-specific risk indicators detect unauthorized data access and anomalous behaviors
All agents with M365 access
DLP for agents
Agents inherit DLP protections, prevented from accessing labeled files or sending sensitive data via teams
First-party and Copilot Studio agents
Communication compliance
Detects non-compliant activity in human-agent interactions; proactive policy-based governance
All agent interactions in M365
eDiscovery & audit
Agent prompt/response retention, deletion policies, and legal hold extended to agent interactions
All m365-connected agents
Risky agents policy template
IRM template detects anomalous agent behaviors including exfiltration patterns
Copilot Studio and Microsoft Foundry agents
Key architectural principle: Purview treats AI agents as data principals, they inherit the same protections as human users. A highly confidential labeled file cannot be accessed by an agent any more than by an unauthorized human. This governance-by-design approach eliminates the ‘shadow AI’ data exposure gap.
Purview’s Data Policy capability represents a fundamental shift from infrastructure-level ACLs managed by engineers to business-level policies managed by data owners and governance teams. A Purview data access policy states: ‘Users in group X can perform action Y on data assets matching classification Z.’
Data owner policies: Grant read or read/modify access to Azure Storage, ADLS Gen2, Azure SQL, and Fabric without involving the infrastructure team.
DevOps policies: Grant SQL performance monitoring access (VIEW DATABASE STATE) to DevOps engineers without granting data read permissions.
Self-service data access policies: Data consumers request access through the Unified Catalog. Automated workflow routes to data owner. Access provisioned or rejected with full audit trail.
Attribute-based access control (ABAC): Grant access based on asset classifications rather than specific named assets. New assets automatically inherit correct policies as they are classified.
DLP policy tip triggering on sensitive data upload
Near real-time
Asset-level with sensitive data detection
Architectural constraint: Purview data policies do NOT replace row-level security (RLS), column masking, or dynamic data masking (DDM) in SQL databases. Purview policies govern who can connect and query. RLS/DDM governs what data they see within an allowed connection. Both layers are required for complete access governance.
Sensitivity labels are the governance primitive that spans cloud storage, databases, Office documents, Teams messages, third-party applications, and, as of 2026, AI agent interactions. The taxonomy must balance usability with enforcement precision. More than 10 labels typically causes label fatigue.
Label
Definition
Protection actions
Auto-labelling trigger
Public
Approved for external publication. No restrictions.
None
No sensitive classifications detected
Internal
Business information for employee use. Not for public sharing.
Watermark on documents
Default label applied to all unlabelled items
Confidential
Sensitive business data. External sharing requires approval.
As of 2026, Purview DLP has been restructured (the table of contents for DLP documentation was reorganized for clarity) and now explicitly covers three scenarios: protecting enterprise data, protecting enterprise data on devices, and inline data protection.
DLP scope
Trigger condition
Action
Business justification override
Exchange email
Highly confidential label; external recipient
Block delivery; notify sender; generate incident
Yes, manager approval workflow
SharePoint/OneDrive
Confidential label; public sharing link created
Block link creation; notify user; generate incident
Yes, data owner approval
Teams messages
Credit card number, SSN pattern in message
Block send; notify user; policy tip displayed
No, hard block (financial regulatory)
Fabric warehouse (new GA)
Sensitive data detected in asset uploaded to warehouse
Policy tip trigger; restrict access for KQL/SQL DBs
Admin configurable
AI agents (new)
Agent attempts to access highly confidential labeled file
Block agent access; audit log entry; alert to admin
No, security team review required
Chapter 8: Deployment architecture & operating model
Pattern 1, Centralized Governance (Single Account): Best for organizations with <50,000 data assets, single-geography operation, or strong central governance team. Simple operations, lower cost.
Pattern 2, Federated Governance (Hub-and-Spoke): Best for large multi-geography organizations with autonomous business units. Central CDO office hub; business unit spoke accounts synchronized via Purview metadata API.
Pattern 3, Domain-Aligned (Data Mesh): Best for organizations implementing Data Mesh. Each data domain owns its own Purview account. Enterprise governance sets standards; federated computational governance via shared glossary and classification taxonomy.
Register data sources, configure scans, build custom lineage integration
20% allocation
Data source admin
AI governance analyst (new role)
Monitor AI agent risk scores in DSPM, review AI observability reports, manage agentic risk policies
20-50% FTE
Insights reader + security admin
Operating model insight: A Purview deployment without assigned data stewards is a catalog that fills with metadata but never becomes trusted. For a 50,000 asset estate, plan for 2-3 full-time stewards in year one. Automation can increase effective capacity to 1 FTE per 100,000 assets at maturity. For organizations deploying Copilot or AI agents, an AI governance analyst role is now essential, this is not optional in the AI era.
Purview pricing is based on Data Map capacity units (CUs), scan compute, and Microsoft 365 Compliance licensing. A new pay-as-you-go pricing model (available alongside the Suite license) covers data estates, analytics, and AI apps, use the DSPM Usage Center to track consumption per investigation and avoid over-provisioning.
Cost component
Billing model
Optimization strategy
Data Map capacity units
$0.496/CU/hour (1 CU = 1GB metadata storage + processing capacity)
Incremental scans reduce CU consumption by 60-75%
Scan compute
Billed per vCore-hour for SHIR; managed vNet included in CUs
Right-size SHIR VMs; schedule to minimize runtime; use mVNet where possible
M365 compliance (DLP, labels)
Included in M365 E5 or E5 compliance add-on
Audit license assignments; unused compliance seats are common waste
DSPM & AI governance (new)
Pay-as-you-go; data security investigation compute units (DSICUs) replaced SCUs
Use the usage center dashboard to track per-investigation consumption
Pan-European retail bank, 12,000 employees, 85 data sources
Challenge
GDPR audit failed in 2022 due to inability to demonstrate PII data inventory. €2.3M fine issued. Compliance team spent 14 weeks per audit cycle manually documenting data assets.
Purview scope
Data Map (85 sources), full estate classification, GDPR & PCI assessments in Compliance Manager, sensitivity labels across M365 and Azure Storage, DLP policies for credit card and IBAN patterns
Timeline
16 weeks to full production deployment across all 85 sources
US regional hospital network, 22 hospitals, 6,500 clinical staff, 140TB of health data across Azure and on-premises
Challenge
Inability to demonstrate minimum-necessary access principle for PHI (HIPAA §164.514). Multiple breaches of PHI to non-clinical staff through misconfigured Power BI reports.
Purview scope
Healthcare-specific classification rules (34 custom PHI types), Data Map across epic EHR integration layer + Azure SQL + ADLS Gen2, Purview policy for PHI access restriction, DLP to block PHI in teams/email, Compliance Manager HIPAA assessment
Key result
Classification accuracy validated at 96.3% against 10,000 manually labelled records. First external HIPAA audit post-deployment: no significant findings.
A FTSE 100 retailer with 8 data domains implemented a Data Mesh on Microsoft Fabric. The governance challenge evolved in 2025: beyond interoperability and trust, they needed to govern Copilot-powered analytics agents accessing domain-owned data products.
Deployed DSPM AI Observability to inventory 47 AI agents accessing the Fabric estate, 12 were flagged as high-risk due to oversharing patterns.
Applied DLP policies to Fabric Warehouse and KQL DBs (newly GA) to prevent sensitive data leakage through Copilot agent responses.
Insider Risk Management extended to Fabric lakehouses with built-in risk indicators for potential data exfiltration by agents.
KPI
Target
Achieved (month 12)
Data products certified
80% of published products
84%
Cross-domain data access time
< 3 business days
1.2 days average
AI agent data risk incidents resolved
< 5/month
2.1/month average
Time to identify root cause of cross-domain data issue
< 4 hours
47 minutes average
Chapter 11: 90-Day implementation roadmap
Based on 20+ Purview deployments, the following 90-day roadmap represents the optimal sequencing for enterprise governance programs in 2026, incorporating AI governance activation alongside traditional catalog and classification work.
Glossary completion: approve tier 1 glossary terms; link to classified assets via bulk assignment
Data steward
>80% of tier 1 assets linked to at least one approved glossary term
12
Program review: measure governance maturity score vs. week 1 baseline; document lessons; plan 90-180 day roadmap
CDO + data governance lead
Governance score improvement documented; 90-180 day roadmap approved; operating model confirmed
Critical success factor: Governance programs that fail typically do so in days 31-60, the ‘activation phase.’ quick wins must be demonstrated by day 45 to maintain organizational momentum. The Power BI governance maturity score dashboard is designed as this early value demonstration. In 2026, demonstrating AI agent governance to leadership is an equally powerful motivator for program continuation.
Appendix: Governance maturity model & quick reference
Open-source metadata management framework; the foundational metadata model underlying Purview’s Data Map
Business glossary
Curated vocabulary of business terms linked to data assets; provides semantic context and shared language
Collection
Hierarchical container in Purview that scopes metadata, access control, and policy enforcement
Data lineage
Documentation of data origin, movement, and transformation, tracing how data flows from source to consumption
DSPM
Data Security Posture Management, Purview’s unified plane for discovering, protecting, and investigating data risks across traditional and AI workloads
AI observability
DSPM capability providing an inventory of all AI apps and agents, their risk levels, and sensitive data interactions
Microsoft Entra ID
The current name for Azure Active Directory (rebranded October 2023). all Purview documentation and configurations should use this term.
Unified Catalog
GA feature (2025) consolidating data discovery, data quality, automated access workflows, and glossary management into a single experience
OpenLineage
Open standard for data lineage metadata; used by Purview Spark connector to emit lineage from Spark jobs
Sensitivity label
Classification tag applied to data assets and documents that drives downstream protection actions across the entire Microsoft ecosystem
Data governance, classification and compliance.
Microsoft Sentinel, identity and audit-ready controls.
ERP-aligned models that keep the estate coherent.
Talk to the team behind these articles. Start with a no-obligation discovery call with a senior Veratas architect.
Governance work of this kind is also what decides whether a Copilot rollout produces anything measurable. Why 74% of enterprises cannot show a return on Copilot covers what the organisations getting a return fixed first.
Senior Business Intelligence Architect with 22 years of experience designing enterprise analytics and data platforms. Focus areas include Power BI, real-time analytics, and large-scale BI architecture across the Microsoft data stack.