Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365…

MITAuto-check passedDocuments & Office

Install Purview Dspm AI

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill purview-dspm-ai -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills purview-dspm-ai --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/purview-dspm-ai .claude/skills/purview-dspm-ai && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
purview-dspm-ai
GitHub stars
175
Token cost
~1.5k tokens
SKILL.md length
630 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365…

  • Works in 6 steps: Onboard DSPM for AI - Activate from the… → Run the data assessments - Execute the… → Action one-click recommendations - Apply… → …
  • The goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing)
  • SKILL.md covers When to use, Pick the right starting lens, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Purview Dspm AI is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party AI (ChatGPT, Gemini). Covers AI usage visibility, one-click recommendations, oversharing risk surfaced to AI, and DLP for AI. WHEN: DSPM for AI, AI data security posture, Copilot data risk, monitor AI prompts, sensitive data in AI, generative AI data…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites and Privacy and GDPR. It works with OpenAI, Microsoft Copilot Studio, Microsoft 365 and Microsoft SharePoint. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • The goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing)
  • Building IRM policies for departing users (use insider-risk-baseline)

Example prompts

  • “/purview-dspm-ai”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Onboard DSPM for AI - Activate from the Purview portal; consent to the analytics it needs
  2. Run the data assessments - Execute the oversharing assessment and **Copilot interactions
  3. Action one-click recommendations - Apply the recommended policies: detect risky AI
  4. Govern third-party AI - Pair with Defender for Cloud Apps to discover ChatGPT/Gemini/Claude
  5. Apply DLP for AI - Use DLP policies for Microsoft 365 Copilot to exclude labelled
  6. Operate - Review Activity Explorer weekly, tune false positives, and report metrics

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Purview Dspm AI loads about 1.5k tokens when it runs. Until then it costs about 239 tokens; SKILL.md has 630 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~239
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 630 words, ~1,498 tokens.

Download SKILL.mdSave it as .claude/skills/purview-dspm-ai/SKILL.md (or your agent's skills folder).
name
purview-dspm-ai
description
Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party AI (ChatGPT, Gemini). Covers AI usage visibility, one-click recommendations, oversharing risk surfaced to AI, and DLP for AI. WHEN: DSPM for AI, AI data security posture, Copilot data risk, monitor AI prompts, sensitive data in AI, generative AI data protection, third-party AI usage visibility, secure Copilot data, what sensitive data is being sent to AI, monitor what users are putting into Copilot prompts, detect sensitive data in AI responses, ChatGPT data leakage risk. DO NOT USE when the goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing) or building IRM policies for departing users (use insider-risk-baseline).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Purview DSPM for AI

DSPM for AI gives visibility and control over how sensitive data is used in generative AI - Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party/consumer AI apps (ChatGPT, Gemini, Claude) - and recommends protections you can apply in one click.

When to use

Securing and governing data interactions with AI as Copilot and genAI adoption grows in the tenant, especially before broad rollout.

Do not use this skill when the goal is to clean up SharePoint permissions ahead of Copilot (use purview-copilot-oversharing) or to investigate insider activity (use insider-risk-baseline).

Pick the right starting lens

ConcernStart here
Are users pasting sensitive data into ChatGPT?DSPM for AI - Activity Explorer + Edge browser extension / Defender for Cloud Apps signals
What sensitive data is Copilot retrieving?DSPM for AI - Data assessments + interaction reports
Are prompts/responses violating policy?Communication Compliance for Copilot + DLP for AI
Files Copilot can reach but shouldn'tDSPM for AI - unlabelled sensitive files report (then purview-copilot-oversharing)

Rule of thumb: turn on DSPM for AI first to see the risk surface, then action the one-click recommendations rather than building bespoke policies from scratch.

Approach

  1. Onboard DSPM for AI - Activate from the Purview portal; consent to the analytics it needs and confirm Audit is enabled tenant-wide. Verify: the DSPM for AI overview shows interaction counts within 24-48 hours.
  2. Run the data assessments - Execute the oversharing assessment and Copilot interactions assessment to scope risk before enforcement. Verify: assessment results identify top sites/users by sensitive interaction volume.
  3. Action one-click recommendations - Apply the recommended policies: detect risky AI interactions, extend sensitivity labels to AI, and protect data referenced by Copilot. Verify: each accepted recommendation creates a corresponding Purview policy in audit mode.
  4. Govern third-party AI - Pair with Defender for Cloud Apps to discover ChatGPT/Gemini/Claude use; apply Endpoint DLP rules to block paste of labelled content into unsanctioned AI apps. Verify: Cloud App Catalog shows AI app risk scores and DLP blocks appear in Activity Explorer.
  5. Apply DLP for AI - Use DLP policies for Microsoft 365 Copilot to exclude labelled content from Copilot processing or restrict by group; use Communication Compliance for prompt review. Verify: a test prompt referencing a labelled document is excluded or flagged.
  6. Operate - Review Activity Explorer weekly, tune false positives, and report metrics (interactions classified, recommendations accepted, blocks) to leadership.
Show full SKILL.md (241 more words)Show less

Guardrails

  • DSPM for AI surfaces risk but depends on classification and label maturity to act on it - if nothing is labelled, recommendations have nothing to enforce.
  • Address oversharing before broad Copilot rollout, not after - users will notice when Copilot starts returning HR files.
  • Apply privacy controls when monitoring user prompts; pseudonymise where works councils require it and publish an AI acceptable-use policy.
  • Audit must be on tenant-wide before DSPM for AI can show interactions - confirm in the Purview portal first.
  • Endpoint DLP for third-party AI requires onboarded Windows/Mac devices and Edge for Business.

Common anti-patterns

  • Enabling Copilot for all users before running the oversharing assessment.
  • Treating DSPM for AI as a one-off audit instead of an ongoing program.
  • Blocking ChatGPT outright with no sanctioned alternative - users move to mobile/personal devices.
  • Skipping DLP for Copilot and assuming sensitivity labels alone will stop oversharing.
  • Ignoring third-party AI because "we only allow Copilot" - Edge telemetry usually proves otherwise.

Example prompts

  • Use DSPM for AI to monitor what sensitive data users send to Copilot.
  • How do I detect sensitive data in AI prompts and responses?
  • Gain visibility into third-party AI usage like ChatGPT.
  • Run the Copilot oversharing assessment and action the recommendations.
  • Block paste of Highly Confidential content into ChatGPT on managed endpoints.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/purview-dspm-ai of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Purview Dspm AI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Purview Dspm AI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Purview Dspm AI this skillvinayaklatthe/microsoft-security-skills175—~1.5kAutomated safety check: PassMIT
CLI Microsoft365pnp/cli-microsoft365-mcp-server132—~3.5kAutomated safety check: PassMIT
Spfx Releasepnp/docker-spfx134—~572Automated safety check: NotesMIT
CLI Microsoft365 Scriptpnp/cli-microsoft365-mcp-server132—~3.3kAutomated safety check: PassMIT
AI Agent PostureSCStelz/security-investigator249—~21kAutomated safety check: PassMIT
M365 Agents Pymicrosoft/skills3.1k5 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • CLI Microsoft365

    pnp/cli-microsoft365-mcp-server

    Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

    132 GitHub stars~3.5k tokensUpdated 5 days ago
    Documents & OfficeAuto-check passed
  • Spfx Release

    pnp/docker-spfx

    Automate SPFx version releases - branch, update files, commit, open PR, then tag after merge

    134 GitHub stars~572 tokensUpdated 3 mo ago
    Documents & OfficeAuto-check: notes
  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    132 GitHub stars~3.3k tokensUpdated 5 days ago
    Documents & OfficeAuto-check passed
  • AI Agent Posture

    SCStelz/security-investigator

    Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.

    249 GitHub stars~21k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • M365 Agents Py

    microsoft/skills

    Official

    Microsoft 365 Agents SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.5k tokens
    Documents & OfficeAuto-check: notes
  • M365 Agents Dotnet

    microsoft/skills

    Official

    Microsoft 365 Agents SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.5k tokens
    Documents & OfficeAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Purview Dspm AI

What does Purview Dspm AI do?

Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365…. Purview Dspm AI is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party AI (ChatGPT, Gemini).

When should I use Purview Dspm AI?

Purview Dspm AI fits situations like: the goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing); building IRM policies for departing users (use insider-risk-baseline).

How do I install Purview Dspm AI in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-dspm-ai -a claude-code`. Or copy the skill folder (skills/purview-dspm-ai in vinayaklatthe/microsoft-security-skills) into .claude/skills/purview-dspm-ai in your project. Claude Code loads it when a task matches its description.

How do I install Purview Dspm AI in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-dspm-ai -a codex`. Or copy the skill folder (skills/purview-dspm-ai in vinayaklatthe/microsoft-security-skills) into .agents/skills/purview-dspm-ai in your project. Codex loads it when a task matches its description.

Can I use Purview Dspm AI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-dspm-ai -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/purview-dspm-ai, .gemini/skills/purview-dspm-ai, .github/skills/purview-dspm-ai and .opencode/skills/purview-dspm-ai in your project.

What does Purview Dspm AI need to run?

SKILL.md names no scripts, command-line tools or credentials: Purview Dspm AI is instructions for the agent only.

Does Purview Dspm AI access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Purview Dspm AI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Purview Dspm AI use?

Purview Dspm AI is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Purview Dspm AI use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Purview Dspm AI?

Skills that share tags, products or a category with Purview Dspm AI: CLI Microsoft365 (pnp/cli-microsoft365-mcp-server, 132 stars), Spfx Release (pnp/docker-spfx, 134 stars), CLI Microsoft365 Script (pnp/cli-microsoft365-mcp-server, 132 stars) and AI Agent Posture (SCStelz/security-investigator, 249 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Purview Dspm AI?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.