New Agents in Microsoft Purview
Security teams often face alert overload and hidden data risks. This video shows how Microsoft Purview agents, powered by Security Copilot, help you focus on what matters most. Watch how the Data Security Triage Agent prioritizes incidents and how the Data Security Posture Agent surfaces risks through natural language queries.
What are the new agents in Microsoft Purview?
The new agents in Microsoft Purview are AI-powered helpers designed to streamline your daily data security work so you can focus on real risks instead of chasing noise.
There are two main agents:
1. **Data Security Triage Agent**
- Helps you work through alert overload from Insider Risk Management and Data Loss Prevention (DLP).
- Filters out likely false positives so you can quickly see which incidents actually need attention.
- Provides clear, contextual reasoning for each alert, so you understand *why* something is risky.
- Can automate user outreach, helping you follow up with employees directly from the workflow.
2. **Data Security Posture Agent**
- Lets you uncover hidden risks using natural-language queries (you can ask questions in plain English instead of building complex queries).
- When it finds issues, you can apply sensitivity labels and trigger security policies right from the insight, helping you proactively prevent data loss.
Both agents are powered by Security Copilot and are built to give security and compliance teams a faster, more efficient way to manage data security inside Microsoft Purview.
How does the Data Security Triage Agent reduce alert overload?
The Data Security Triage Agent is designed to help your team rethink how you handle Insider Risk and DLP alerts by reducing noise and surfacing what truly needs action.
Here’s how it helps:
- **Cuts through alert overload**: Instead of manually reviewing a long list of alerts, the agent analyzes them for you and highlights the ones that are most likely to represent real risk.
- **Eliminates many false positives**: By using context around user behavior and data activity, it can deprioritize alerts that are unlikely to be problematic, so your analysts spend less time on non-issues.
- **Explains the “why” behind alerts**: Each prioritized alert comes with clear, contextual reasoning, so your team can quickly understand what happened and why it matters.
- **Supports automated user outreach**: You can stay in control of the process while using the agent to automate parts of user communication, such as asking for clarification or reminding users of policies.
The result is a more focused triage process where your team spends time on the incidents that are most likely to impact your organization, instead of getting stuck in a backlog of low-value alerts.
What does the Data Security Posture Agent do for proactive protection?
The Data Security Posture Agent helps you reimagine how you discover and address data risks by making it easier to ask questions about your environment and act on the answers.
Key capabilities include:
- **Natural-language risk discovery**: You can use plain-language queries (for example, “Show me data at risk in our finance department”) to uncover risks that might be hard to find with traditional, rule-based searches.
- **Context-aware insights**: The agent looks at the context around data—such as where it’s stored, how it’s accessed, and by whom—to surface issues that might otherwise stay hidden.
- **Inline remediation**: When the agent identifies a risk, you can immediately apply sensitivity labels or trigger security policies directly from the insight, without switching tools or building new rules from scratch.
- **Proactive data loss prevention**: By continuously uncovering and addressing posture issues, you move from reacting to incidents to proactively reducing the chances of data loss.
Because it’s powered by Security Copilot and integrated into Microsoft Purview, the Data Security Posture Agent helps your security and compliance teams work more efficiently while tightening your overall data protection posture.
New Agents in Microsoft Purview
published by Definitive Solutions
Definitive Solutions was founded in 1999 by Peter Meade who has over 30 years in the IT industry. We deliver IT managed services, cloud and security solutions to our SMB and Enterprise clients throughout Ireland and Internationally.
We are not just another MSP; our technical skill is given, but our success has been built on the ethos of trust and our focus is always on building strong relationships. Our approach is to really understand our clients’ business challenges and goals, and implement bespoke technology products and services which meet their unique business requirements.
As an independent private company, you can trust us to give impartial advice. We stand over every product and service we recommend and will only offer the right solutions for our clients. There is no such thing as ‘one size fits all’.
Our focus on professional trust and relationships does not just apply to our long-established clients; it continues within our dedicated team, evidenced by one of the strongest retention rates in the industry, and with our partners.
All of the growth and success our business has enjoyed is a result of our outstanding team of people and we all share a passion for providing the best customer experience.
Our clients range across all industry verticals including financial services, public sector, distribution, pharma and charities. Many of our clients operate within highly regulated industries, and adhere to strict compliance and regulation standards and we work closely with them to ensure their technology strategy is aligned with their compliance responsibilities.