www.microsoft.com 24 Sept 2026, 16:00 UTC

Microsoft Tightens Controls Over AI Agents and Sensitive Data

Microsoft Tightens Controls Over AI Agents and Sensitive Data
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT’S September 2026 security updates focus on governing artificial-intelligence agents operating on employee devices, cloud platforms and developer workflows. For organisations using Microsoft Defender and Security Copilot, a new email detonation summary provides AI-generated explanations of URL and file sandboxing results, helping security operations teams correlate evidence and investigate suspicious messages more quickly.

Microsoft also says Purview and Entra Global Secure Access are now generally available for enforcing data-security policies at the network layer, covering both human activity and on-behalf-of agent traffic. Organisations can identify sensitive files and text in real time and block transfers to risky destinations. This could, for example, prevent an employee or agent from uploading a sensitive document to an unsanctioned consumer AI service before the data leaves the organisation.

Other Purview changes include auto-labelling simulations supporting up to 20 million items and 50,000 sites through adaptive scopes, with policy edits possible without repeating a simulation. Purview eDiscovery can search, place holds on, review and export content in user-owned SharePoint embedded containers, including material from Loop, Copilot Pages and Copilot Notebooks.

Administrators can also archive inactive SharePoint content while retaining it for legal and retention purposes, removing it from Microsoft 365 Copilot indexing, or permanently delete approved stale content through Priority Cleanup. Microsoft further announced that selected Intune capabilities are coming to GCC High, with Enterprise Application Management also offered to DoD organisations.

View full article

Article by CyberSIXT