News to Know – Volume 3, Edition 7, July 2026
July 2, 2026Bring business logic into PIM role activation workflows
July 2, 2026Once, securing data meant protecting them within the confines of endpoints and managed apps. It lived inside boundaries you controlled. Today, those boundaries have disappeared—and with them, the old playbook for data security.
Data security must keep up with how data moves in the AI-era
Organizational data now travels constantly between trusted endpoints and unmanaged web apps, SaaS apps, and most critically, generative AI tools over the network. Employees type and paste sensitive information into prompts, upload work-related files to external services or personal cloud storage, and interact with systems that sit entirely outside the traditional enterprise perimeter. AI has expanded the risk surface for potential enterprise data loss.
Traditional data loss prevention (DLP) approaches lack real-time visibility and enforcement, often flagging incidents after data has already left the organization. In other cases, vendors rely heavily on physical network appliances that are complex and expensive to deploy, or compute-intensive resources that can add latency. In the era of AI, that model breaks down quickly.
Enabling real-time data protection for how work happens
To address this shift, we’re announcing the extension of data security to the network layer, powered by Microsoft Purview and Microsoft Entra, now in public preview.
This integration brings together data context and identity-aware enforcement to help protect sensitive data in transit, in real-time:
- Detect how sensitive data is shared to shadow AI tools, unmanaged SaaS apps, and personal cloud repositories.
- Help block or limit data exposure in real-time based on identity, user activity, and data context.
- Unify investigation workflows by correlating identity, data, and insider risk signals across Microsoft Purview, Microsoft Entra, and Microsoft Defender.
By combining Microsoft Purview data classification, DLP policies, and insider risk detection with identity-aware enforcement at the network layer through Microsoft Entra, organizations can dynamically apply protections based on:
- The sensitivity of the data
- Who the user is
- How that user has interacted with sensitive data over time
Together, these capabilities help protect data in motion across browser sessions, SaaS usage, and AI interactions (including prompts and responses), all at the speed and scale that today’s work demands. The result is a more complete, consistent approach to data protection that follows the data instead of relying on fixed, at-rest controls.
What this changes in practice
With network-level visibility and enforcement, security teams can finally understand how sensitive data is moving across unmanaged SaaS and AI apps, not just within Microsoft applications or endpoint devices.
Prevent employees from sharing proprietary or sensitive organizational data to potentially risky locations such as consumer AI apps.
That includes scenarios that have historically been difficult to see and protect, including:
- Text that’s inputted directly into unmanaged apps and email services, such as prompts and responses
- Files that are uploaded to personal cloud storage repositories
- Files and text that could be scanned and processed by unsanctioned plugins or add-ins
- Files and text that are shared outside of a managed browser session
Most importantly, protection preempts data leakage. Instead of relying on downstream detection, organizations can detect and block sensitive data in transit before it’s exposed. Because enforcement is tied to identity and user context, policies can adapt based on risk without introducing unnecessary friction for end users.
Underneath, this is powered by a unified policy model, where the classification and protection policies defined in Microsoft Purview for the rest of your data estate are also enforced consistently at the network layer through Microsoft Entra. This reduces the need to juggle multiple point solutions to secure data holistically across your environment.
A shift to real-time data protection
This shift reflects a broader transformation in how data and network security teams must operate.
Traditional approaches rely on static boundaries and after-the-fact controls. That model breaks down when data is continuously exchanged across SaaS apps and AI systems.
Data protection now needs to operate in real-time and in the flow of user activity.
Network data security – now available in Microsoft 365 E7* – plays a critical role in enabling this shift by extending enforcement beyond endpoints and applications to the network itself, helping protect data wherever it moves.
Learn more
As organizations adopt AI at scale, securing data and access during AI and agent use becomes mission-critical.
Join our three-part webinar series, Securing Data and Access in the Era of AI, to see how Microsoft Entra and Microsoft Microsoft Purview help protect data, govern access, and reduce risk across your AI journey.
Register for the webinar series: Securing data and access in the era of AI with Microsoft Entra and Microsoft Purview
Sule Tatar, Senior Product Marketing Manager, SCI Identity
-Vivian Ma, Senior Product Marketing Manager, Microsoft Purview Data Security
*Network data security capabilities are also available to customers with both a Purview ME5 (or equivalent) and Entra Internet Access (or equivalent) license.
Learn more about Microsoft Microsoft Purview
Dynamically secure your data with an integrated approach across your multi-structured data estate, devices, and generative AI apps and agents.
- Microsoft Purview news and insights | Microsoft Microsoft Security Blog
- Microsoft Purview community blog | Tech Community
- Microsoft Purview documentation | Microsoft Learn
Learn more about Microsoft Entra
Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.
- Microsoft Entra news and insights | Microsoft Microsoft Security Blog
- Microsoft Entra blog | Tech Community
- Microsoft Entra documentation | Microsoft Learn
- Microsoft Entra discussions | Microsoft Community