AI engineering

Set Up Microsoft Purview DSPM for AI to Audit and Govern Copilot Interactions

Turn on auditing, activate the DSPM for AI one-click policies, run data risk assessments and read Copilot prompts and responses in activity explorer and the unified audit log.

11 min read
On this page

To see and govern what users ask Microsoft 365 Copilot and agents, confirm that Microsoft Purview auditing is on, open DSPM for AI (classic) (or the new DSPM) in the Microsoft Purview portal, and activate the one-click policies from Recommendations. After a day, prompts and responses appear as AI interaction events in activity explorer for users with a content viewer role, and every interaction is searchable in the unified audit log as a CopilotInteraction record.

Who this is for and what you will have at the end

This guide is for compliance and security administrators who are rolling out Microsoft 365 Copilot or Copilot Studio agents and need visibility before, or soon after, licenses are assigned.

At the end you will have:

  • Auditing confirmed and the right Purview roles assigned.
  • The DSPM for AI one-click policies created for Copilot.
  • The default data risk assessment reviewed and a custom one running.
  • A repeatable way to read prompts and responses, and to query raw audit records with PowerShell.
  • Retention and eDiscovery set up for Copilot interactions.

DSPM for AI (classic) and the new DSPM

Microsoft has converged DSPM for AI and DSPM into a single Data Security Posture Management solution. The classic version remains available under Solutions > DSPM for AI (classic), and most of its one-click policies are offered in the new version as remediation actions. New features are only added to the current version. The steps below use the classic navigation because it maps one-to-one to the documentation, and the table shows where each task lives in the new DSPM.

Task in DSPM for AI (classic)Location in the new DSPM
Get started (auditing, browser extension, device onboarding)DSPM > Getting Started, then Actions > Setup tasks
Recommendations and one-click policiesDSPM > Actions > Remediation actions
Microsoft 365 Copilot overviewDSPM > Reports > Microsoft 365 Copilot
Policies pageDSPM > Reports > Policies with AI workloads
Apps and agentsDSPM > Discover > Apps and agents, plus AI observability
Activity explorerDSPM > Discover > Activity explorer > AI activities tab
Data risk assessmentsDSPM > Discover > Data risk assessments

The new DSPM also adds Objectives, such as Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions, which bundle the same policies into a guided workflow.

Prerequisites

Roles

NeedRole or role group
View, create and edit in DSPM for AIMicrosoft Entra Compliance Administrator, Microsoft Entra Global Administrator, or the Microsoft Purview Compliance Administrator role group
View onlyMicrosoft Purview Security Reader role group, Purview Data Security AI Viewer, or Entra AI Administrator
Read prompt and response textContent Explorer Content Viewer or Microsoft Purview Data Security AI Content Viewer
See file details in data risk assessmentsContent Explorer Content Viewer or Content Explorer List Viewer
Turn auditing on or offThe Exchange Online Audit Logs role (in Compliance Management and Organization Management by default)

Use the least privileged role that works. If you use administrative units, only an unrestricted administrator can create the one-click policies that apply to all users.

Licensing and data sources

  • Users must have Microsoft 365 Copilot licenses for their Copilot and agent interactions to be monitored.
  • Copilot in Fabric and Security Copilot need the enterprise version of Microsoft Purview data governance and a collection policy.
  • Third-party AI sites need devices onboarded to Purview and the Purview browser extension; AI apps other than Microsoft 365 Copilot and Microsoft Facilitator need pay-as-you-go billing.

Step 1: Confirm that auditing is on

Run this in Exchange Online PowerShell. Don't use Security & Compliance PowerShell for this check, because there the property always returns False.

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
 
# Only if the value is False
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true

Turning it on can take up to 60 minutes to take effect, and events can take several hours to become searchable. You can also select the Audit solution in the Purview portal and choose the Start recording user and admin activity banner if it appears.

Step 2: Open DSPM for AI and complete Get started

  1. Sign in to the Microsoft Purview portal and go to Solutions > DSPM for AI (classic).
  2. On Overview, keep the All AI apps view and review the Get started section. The actions are Turn on Microsoft Purview Audit, Install Microsoft Purview browser extension, Onboard devices to Microsoft Purview and Extend your insights for data discovery.
  3. Complete the audit action at minimum. The browser extension and device onboarding only matter if you also want visibility into third-party AI sites.
  4. Switch the view from All AI apps to Microsoft 365 Copilot and work through Assess and prevent oversharing of sensitive data, Secure your data in Microsoft 365 Copilot and Discover Microsoft 365 Copilot activity.

Step 3: Activate the one-click policies for Copilot

Select Recommendations and open these Copilot-specific items. Each creates a policy in the owning Purview solution, which you can edit or scope later.

RecommendationPolicy createdWhat it does
Protect your data with sensitivity labelsDefault sensitivity labels and label policiesSkipped if you already have labels
Detect risky interactions in AI appsInsider Risk Management: DSPM for AI - Detect risky AI usageCalculates user risk from risky prompts and responses
Detect unethical behavior in AI appsCommunication Compliance: DSPM for AI - Unethical behavior in AI appsDetects sensitive information in prompts and responses for all users
Protect items with sensitivity labels from Microsoft 365 Copilot and agent processingDLP: DSPM for AI - Protect sensitive data from Copilot processingBlocks Copilot and agents from processing items with the labels you select

For Copilot in Fabric and Security Copilot, Secure interactions for Microsoft Copilot experiences creates the collection policy DSPM for AI - Capture interactions for Copilot experiences, which captures prompts and responses that would otherwise only produce audit events.

The label-based DLP policy is the same control described in excluding labeled files from Copilot with sensitivity labels; choose the labels carefully, because Copilot won't use the content of matching items.

Policies that use Adaptive Protection turn that capability on with default risk levels if it isn't already enabled. If you delete a one-click policy, it shows PendingDeletion on the Policies page until removal completes.

Step 4: Review data risk assessments

A default data risk assessment runs weekly, without activation, for the top 100 SharePoint sites by usage. The first time, results take four days to appear.

  1. Select Data risk assessments, then View details on the default assessment.
  2. Select a site to open its flyout with Overview, Identify, Protect and Monitor tabs.
  3. On Protect, choose a remediation: Restrict access by label (a Copilot DLP policy), Restrict all items (SharePoint Restricted Content Discovery), Create an auto-labeling policy, or Create retention policies for content not accessed in at least three years.
  4. On Monitor, review sharing counts and use Start a SharePoint site access review for owners.

To scan specific sites or users, select Create custom assessment. Results take at least 48 hours and don't refresh; duplicate the assessment to rerun it, including after the 30-day expiration. Limits for Microsoft 365: up to 200,000 items per location, and counts might be inaccurate above 100,000 files per location. Item-level scanning, which needs an Entra app registration with Microsoft Graph application permissions, supports up to 10 SharePoint sites and doesn't support OneDrive.

Step 5: Read prompts and responses in activity explorer

After at least a day, open Reports and select Copilot experiences & agents to see total interactions, sensitive interactions per app and the top sensitivity labels referenced. Then select Activity explorer and filter AI app category to Copilot experiences & agents.

EventMeaning
AI interactionA user interacted with Copilot, an agent or another AI app. Includes prompt and response text for users with a content viewer role.
Sensitive info typesSensitive information types were found in the interaction. For Copilot this needs auditing but no active policy.
DLP rule matchA DLP rule matched, including DLP for Microsoft 365 Copilot.
AI website visitA user browsed to a generative AI site (needs the browser extension).

Use the Web queries filter to find interactions where Copilot used web search. Select Apps and agents to see which agents are in use and what sensitive data they accessed.

Step 6: Query Copilot audit records with PowerShell

The audit log captures each interaction under the record type CopilotInteraction, without prompt or response text. Each record includes properties such as AppHost (for example BizChat, Word or Teams), AppIdentity, AgentId and AgentName for agents, and AccessedResources, which lists the files, emails and sites Copilot read along with each item's SensitivityLabelId and any PolicyDetails when a policy restricted access.

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
$records = Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) -EndDate (Get-Date) `
  -RecordType CopilotInteraction -ResultSize 5000
 
$records | Select-Object CreationDate, UserIds, Operations | Format-Table
 
# Inspect the full JSON of one record
$records | Select-Object -First 1 -ExpandProperty AuditData

-ResultSize has a maximum of 5,000. For larger exports, use -SessionCommand ReturnLargeSet with a -SessionId, which can return up to 50,000 unsorted results. In the portal, use Audit and the Activities - operation names field. To check whether Copilot used the public web, look for BingWebSearch in the AISystemPlugin details. Interactions with Copilot Studio agents also appear as CopilotInteraction, with an AppIdentity that begins with Copilot.Studio..

Treat audit data as a security and compliance source, not as usage reporting. For adoption metrics, use the Microsoft 365 Copilot usage report or the Copilot Dashboard in Viva Insights.

Step 7: Retain and search interactions

  • Retention: In Data Lifecycle Management, create a retention policy and select Microsoft Copilot Experiences. To keep the exact version of files referenced in Copilot, auto-apply a retention label with Apply label to cloud attachments and links shared in Exchange, Teams, Viva Engage, and Copilot.
  • eDiscovery: Prompts and responses are stored in the user's mailbox. In a case, search with Add condition > Type > Contains any of > Copilot activity, or use the ItemClass property with the value IPM.SkypeTeams.Message.Copilot.*.

Verify the setup

  1. In Policies, confirm each one-click policy shows as created and is in the expected mode.
  2. Ask a pilot user to run a few Copilot prompts, including one that references a labeled file.
  3. The next day, confirm an AI interaction event appears in activity explorer and that a content viewer can read the text.
  4. Run the PowerShell search and confirm CopilotInteraction records exist for the pilot user, with AccessedResources populated.
  5. Check Reports for the label in Top sensitivity labels references in Microsoft 365 Copilot and agents.

Troubleshooting

SymptomCause and fix
UnifiedAuditLogIngestionEnabled shows False although auditing is onYou ran the command in Security & Compliance PowerShell. Use Exchange Online PowerShell.
Search-UnifiedAuditLog returns nothingAuditing is off, or events aren't searchable yet. Wait several hours after enabling.
AI interaction events show no prompt textMissing Content Explorer Content Viewer or Data Security AI Content Viewer role; or the user has no Exchange Online mailbox; or the text spans consecutive entries.
A one-click policy can't be createdYour account is restricted by administrative units. Use an unrestricted administrator.
Reports are emptyWait at least 24 hours after creating policies; confirm users have Copilot licenses.
Default risk assessment shows nothingThe first run has a four-day delay.
Copilot in Teams meetings has no audit or retention dataAuditing, eDiscovery and retention aren't supported when transcripts are turned off.

Closing checklist

  • Auditing verified in Exchange Online PowerShell.
  • DSPM roles assigned with least privilege, including a separate content viewer role for the few people who should read prompts.
  • One-click Copilot policies created and reviewed in their owning solutions.
  • Default and custom data risk assessments reviewed, with remediation assigned to site owners.
  • Weekly review of activity explorer, plus a saved PowerShell audit query.
  • Retention policy for Microsoft Copilot Experiences in place.
  • External content brought into Copilot through Copilot connectors and agents built in Copilot Studio governed with data policies and an environment strategy.

References

Questions people ask

Do I need to turn on anything extra to audit Microsoft 365 Copilot?

No extra configuration is needed beyond Microsoft Purview auditing. Copilot interactions are logged as part of Audit (Standard) under the CopilotInteraction record type. Auditing is on by default for most enterprise tenants, but not for Business Basic, Business Standard, Business Premium or unmanaged trial tenants, where you must turn it on.

Does the audit log contain the text of Copilot prompts and responses?

No. Audit records show who interacted with Copilot, when, where and which resources were accessed, but not the prompt and response text. Use the AI interaction events in DSPM for AI activity explorer, with the right content viewer role, or eDiscovery to see the text.

What is the difference between DSPM for AI (classic) and the new DSPM?

DSPM for AI (classic) is the original AI-focused solution. Microsoft has replaced it with a unified Data Security Posture Management solution that adds data security objectives, AI observability and broader data sources. The classic version still works but won't get new features.

How long until DSPM for AI shows data?

Allow at least 24 hours after creating the one-click policies before reports show results. The first default data risk assessment has a four-day delay before results appear, and custom assessments take at least 48 hours.

Microsoft PurviewDSPM for AIMicrosoft 365 CopilotAudit
  1. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  2. Control Web Search in Microsoft 365 Copilot and Copilot Chat: Admin Guide

    Allow, restrict or disable Bing web grounding for Copilot and Copilot Chat with the Cloud Policy setting, and understand exactly what leaves the tenant.

    AI engineering11 min read
  3. Prepare a Tenant for Microsoft 365 Copilot by Fixing Oversharing First

    Find overshared SharePoint and OneDrive content with Data access governance reports and DSPM, contain it with RCD and RAC, then hand cleanup to site owners before Copilot rollout.

    AI engineering14 min read