To see and govern what users ask Microsoft 365 Copilot and agents, confirm that Microsoft Purview auditing is on, open DSPM for AI (classic) (or the new DSPM) in the Microsoft Purview portal, and activate the one-click policies from Recommendations. After a day, prompts and responses appear as AI interaction events in activity explorer for users with a content viewer role, and every interaction is searchable in the unified audit log as a CopilotInteraction record.
Who this is for and what you will have at the end
This guide is for compliance and security administrators who are rolling out Microsoft 365 Copilot or Copilot Studio agents and need visibility before, or soon after, licenses are assigned.
At the end you will have:
- Auditing confirmed and the right Purview roles assigned.
- The DSPM for AI one-click policies created for Copilot.
- The default data risk assessment reviewed and a custom one running.
- A repeatable way to read prompts and responses, and to query raw audit records with PowerShell.
- Retention and eDiscovery set up for Copilot interactions.
DSPM for AI (classic) and the new DSPM
Microsoft has converged DSPM for AI and DSPM into a single Data Security Posture Management solution. The classic version remains available under Solutions > DSPM for AI (classic), and most of its one-click policies are offered in the new version as remediation actions. New features are only added to the current version. The steps below use the classic navigation because it maps one-to-one to the documentation, and the table shows where each task lives in the new DSPM.
| Task in DSPM for AI (classic) | Location in the new DSPM |
|---|---|
| Get started (auditing, browser extension, device onboarding) | DSPM > Getting Started, then Actions > Setup tasks |
| Recommendations and one-click policies | DSPM > Actions > Remediation actions |
| Microsoft 365 Copilot overview | DSPM > Reports > Microsoft 365 Copilot |
| Policies page | DSPM > Reports > Policies with AI workloads |
| Apps and agents | DSPM > Discover > Apps and agents, plus AI observability |
| Activity explorer | DSPM > Discover > Activity explorer > AI activities tab |
| Data risk assessments | DSPM > Discover > Data risk assessments |
The new DSPM also adds Objectives, such as Prevent data exposure in Microsoft 365 Copilot and Microsoft Copilot interactions, which bundle the same policies into a guided workflow.
Prerequisites
Roles
| Need | Role or role group |
|---|---|
| View, create and edit in DSPM for AI | Microsoft Entra Compliance Administrator, Microsoft Entra Global Administrator, or the Microsoft Purview Compliance Administrator role group |
| View only | Microsoft Purview Security Reader role group, Purview Data Security AI Viewer, or Entra AI Administrator |
| Read prompt and response text | Content Explorer Content Viewer or Microsoft Purview Data Security AI Content Viewer |
| See file details in data risk assessments | Content Explorer Content Viewer or Content Explorer List Viewer |
| Turn auditing on or off | The Exchange Online Audit Logs role (in Compliance Management and Organization Management by default) |
Use the least privileged role that works. If you use administrative units, only an unrestricted administrator can create the one-click policies that apply to all users.
Licensing and data sources
- Users must have Microsoft 365 Copilot licenses for their Copilot and agent interactions to be monitored.
- Copilot in Fabric and Security Copilot need the enterprise version of Microsoft Purview data governance and a collection policy.
- Third-party AI sites need devices onboarded to Purview and the Purview browser extension; AI apps other than Microsoft 365 Copilot and Microsoft Facilitator need pay-as-you-go billing.
Step 1: Confirm that auditing is on
Run this in Exchange Online PowerShell. Don't use Security & Compliance PowerShell for this check, because there the property always returns False.
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled
# Only if the value is False
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $trueTurning it on can take up to 60 minutes to take effect, and events can take several hours to become searchable. You can also select the Audit solution in the Purview portal and choose the Start recording user and admin activity banner if it appears.
Step 2: Open DSPM for AI and complete Get started
- Sign in to the Microsoft Purview portal and go to Solutions > DSPM for AI (classic).
- On Overview, keep the All AI apps view and review the Get started section. The actions are Turn on Microsoft Purview Audit, Install Microsoft Purview browser extension, Onboard devices to Microsoft Purview and Extend your insights for data discovery.
- Complete the audit action at minimum. The browser extension and device onboarding only matter if you also want visibility into third-party AI sites.
- Switch the view from All AI apps to Microsoft 365 Copilot and work through Assess and prevent oversharing of sensitive data, Secure your data in Microsoft 365 Copilot and Discover Microsoft 365 Copilot activity.
Step 3: Activate the one-click policies for Copilot
Select Recommendations and open these Copilot-specific items. Each creates a policy in the owning Purview solution, which you can edit or scope later.
| Recommendation | Policy created | What it does |
|---|---|---|
| Protect your data with sensitivity labels | Default sensitivity labels and label policies | Skipped if you already have labels |
| Detect risky interactions in AI apps | Insider Risk Management: DSPM for AI - Detect risky AI usage | Calculates user risk from risky prompts and responses |
| Detect unethical behavior in AI apps | Communication Compliance: DSPM for AI - Unethical behavior in AI apps | Detects sensitive information in prompts and responses for all users |
| Protect items with sensitivity labels from Microsoft 365 Copilot and agent processing | DLP: DSPM for AI - Protect sensitive data from Copilot processing | Blocks Copilot and agents from processing items with the labels you select |
For Copilot in Fabric and Security Copilot, Secure interactions for Microsoft Copilot experiences creates the collection policy DSPM for AI - Capture interactions for Copilot experiences, which captures prompts and responses that would otherwise only produce audit events.
The label-based DLP policy is the same control described in excluding labeled files from Copilot with sensitivity labels; choose the labels carefully, because Copilot won't use the content of matching items.
Policies that use Adaptive Protection turn that capability on with default risk levels if it isn't already enabled. If you delete a one-click policy, it shows PendingDeletion on the Policies page until removal completes.
Step 4: Review data risk assessments
A default data risk assessment runs weekly, without activation, for the top 100 SharePoint sites by usage. The first time, results take four days to appear.
- Select Data risk assessments, then View details on the default assessment.
- Select a site to open its flyout with Overview, Identify, Protect and Monitor tabs.
- On Protect, choose a remediation: Restrict access by label (a Copilot DLP policy), Restrict all items (SharePoint Restricted Content Discovery), Create an auto-labeling policy, or Create retention policies for content not accessed in at least three years.
- On Monitor, review sharing counts and use Start a SharePoint site access review for owners.
To scan specific sites or users, select Create custom assessment. Results take at least 48 hours and don't refresh; duplicate the assessment to rerun it, including after the 30-day expiration. Limits for Microsoft 365: up to 200,000 items per location, and counts might be inaccurate above 100,000 files per location. Item-level scanning, which needs an Entra app registration with Microsoft Graph application permissions, supports up to 10 SharePoint sites and doesn't support OneDrive.
Step 5: Read prompts and responses in activity explorer
After at least a day, open Reports and select Copilot experiences & agents to see total interactions, sensitive interactions per app and the top sensitivity labels referenced. Then select Activity explorer and filter AI app category to Copilot experiences & agents.
| Event | Meaning |
|---|---|
| AI interaction | A user interacted with Copilot, an agent or another AI app. Includes prompt and response text for users with a content viewer role. |
| Sensitive info types | Sensitive information types were found in the interaction. For Copilot this needs auditing but no active policy. |
| DLP rule match | A DLP rule matched, including DLP for Microsoft 365 Copilot. |
| AI website visit | A user browsed to a generative AI site (needs the browser extension). |
Use the Web queries filter to find interactions where Copilot used web search. Select Apps and agents to see which agents are in use and what sensitive data they accessed.
Step 6: Query Copilot audit records with PowerShell
The audit log captures each interaction under the record type CopilotInteraction, without prompt or response text. Each record includes properties such as AppHost (for example BizChat, Word or Teams), AppIdentity, AgentId and AgentName for agents, and AccessedResources, which lists the files, emails and sites Copilot read along with each item's SensitivityLabelId and any PolicyDetails when a policy restricted access.
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
$records = Search-UnifiedAuditLog -StartDate (Get-Date).AddDays(-7) -EndDate (Get-Date) `
-RecordType CopilotInteraction -ResultSize 5000
$records | Select-Object CreationDate, UserIds, Operations | Format-Table
# Inspect the full JSON of one record
$records | Select-Object -First 1 -ExpandProperty AuditData-ResultSize has a maximum of 5,000. For larger exports, use -SessionCommand ReturnLargeSet with a -SessionId, which can return up to 50,000 unsorted results. In the portal, use Audit and the Activities - operation names field. To check whether Copilot used the public web, look for BingWebSearch in the AISystemPlugin details. Interactions with Copilot Studio agents also appear as CopilotInteraction, with an AppIdentity that begins with Copilot.Studio..
Treat audit data as a security and compliance source, not as usage reporting. For adoption metrics, use the Microsoft 365 Copilot usage report or the Copilot Dashboard in Viva Insights.
Step 7: Retain and search interactions
- Retention: In Data Lifecycle Management, create a retention policy and select Microsoft Copilot Experiences. To keep the exact version of files referenced in Copilot, auto-apply a retention label with Apply label to cloud attachments and links shared in Exchange, Teams, Viva Engage, and Copilot.
- eDiscovery: Prompts and responses are stored in the user's mailbox. In a case, search with Add condition > Type > Contains any of > Copilot activity, or use the
ItemClassproperty with the valueIPM.SkypeTeams.Message.Copilot.*.
Verify the setup
- In Policies, confirm each one-click policy shows as created and is in the expected mode.
- Ask a pilot user to run a few Copilot prompts, including one that references a labeled file.
- The next day, confirm an AI interaction event appears in activity explorer and that a content viewer can read the text.
- Run the PowerShell search and confirm
CopilotInteractionrecords exist for the pilot user, withAccessedResourcespopulated. - Check Reports for the label in Top sensitivity labels references in Microsoft 365 Copilot and agents.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
UnifiedAuditLogIngestionEnabled shows False although auditing is on | You ran the command in Security & Compliance PowerShell. Use Exchange Online PowerShell. |
Search-UnifiedAuditLog returns nothing | Auditing is off, or events aren't searchable yet. Wait several hours after enabling. |
| AI interaction events show no prompt text | Missing Content Explorer Content Viewer or Data Security AI Content Viewer role; or the user has no Exchange Online mailbox; or the text spans consecutive entries. |
| A one-click policy can't be created | Your account is restricted by administrative units. Use an unrestricted administrator. |
| Reports are empty | Wait at least 24 hours after creating policies; confirm users have Copilot licenses. |
| Default risk assessment shows nothing | The first run has a four-day delay. |
| Copilot in Teams meetings has no audit or retention data | Auditing, eDiscovery and retention aren't supported when transcripts are turned off. |
Closing checklist
- Auditing verified in Exchange Online PowerShell.
- DSPM roles assigned with least privilege, including a separate content viewer role for the few people who should read prompts.
- One-click Copilot policies created and reviewed in their owning solutions.
- Default and custom data risk assessments reviewed, with remediation assigned to site owners.
- Weekly review of activity explorer, plus a saved PowerShell audit query.
- Retention policy for Microsoft Copilot Experiences in place.
- External content brought into Copilot through Copilot connectors and agents built in Copilot Studio governed with data policies and an environment strategy.
References
- https://learn.microsoft.com/en-us/purview/dspm-for-ai
- https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations
- https://learn.microsoft.com/en-us/purview/ai-microsoft-purview-permissions
- https://learn.microsoft.com/en-us/purview/data-security-posture-management-learn-about
- https://learn.microsoft.com/en-us/purview/dspm-task-mapping
- https://learn.microsoft.com/en-us/purview/ai-m365-copilot
- https://learn.microsoft.com/en-us/purview/ai-m365-copilot-considerations
- https://learn.microsoft.com/en-us/purview/audit-copilot
- https://learn.microsoft.com/en-us/purview/audit-log-enable-disable
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/search-unifiedauditlog