Microsoft named a leader in the Frost Radar for cloud and application runtime security
July 2, 2026Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5
July 2, 2026Protection that keeps up with how data moves in the AI era
Enterprise data used to be easier to contain.
It lived in files, in apps you managed, within boundaries you controlled. Security teams could focus on endpoints and known systems, and that was often enough. That’s no longer the case.
Today, data travels constantly between trusted endpoints and unmanaged web apps, SaaS apps, and most critically, generative AI tools over the network. Employees type and paste sensitive information into prompts, upload work-related files to external services or personal cloud storage, and interact with systems that sit entirely outside the traditional enterprise perimeter. AI has expanded the risk surface for potential enterprise data loss.
Traditional data loss prevention (DLP) approaches lack real-time visibility and enforcement, flagging incidents after data has already left the organization. In other cases, vendors rely heavily on physical network appliances that are complex and expensive to deploy, or compute resources that can add significant latency. In the era of AI, that model breaks down quickly.
Real-time data protection for how work happens today
To adapt to how enterprise data moves in the AI era, we’re announcing the extension of data security to the network layer, powered by Microsoft Purview and Microsoft Entra, now in public preview.
This integration brings together data context and identity-aware enforcement to help protect sensitive data in transit, in real time:
- Detect how sensitive data is shared to shadow AI tools, unmanaged SaaS apps, and personal cloud repositories
- Help block the sharing of sensitive data in real time based on identity, user activity, and data context, before data leakage occurs
- Unify investigation workflows by correlating identity, data, and insider risk signals across Purview, Entra, and Defender
By combining Purview data classification, DLP policies, and insider risk detection with identity-aware enforcement at the network layer through Entra, organizations can dynamically apply protections based on:
- The sensitivity of the data
- Who the user is
- How that user has interacted with sensitive data over time
Together, Purview and Entra enable a modern approach to data protection that follows the data to prevent leakage instead of relying on at-rest controls alone. Not only that, but the same Purview classification and policies that you already leverage for the rest of your enterprise data can now be applied consistently across data in motion, at rest, and in use.
- Learn more in the detailed blog.
- See the capabilities in action here.
- Start your free trial of Purview Suite here.