Microsoft Purview

What it is

Microsoft’s family of data governance, data security and compliance services. Two halves matter for AI rollouts: data governance (Data Map scans sources and captures metadata; Unified Catalog is the curated, searchable catalog on top) and data security / compliance (information protection, DLP, audit, insider risk, eDiscovery, retention, Compliance Manager, and Data Security Posture Management (DSPM) for AI). All data in Data Map and Unified Catalog is metadata, not the underlying data; catalog roles do not grant access to the data itself (Microsoft Learn).

Maker, ownership, history

Product of Microsoft. Unified Catalog is the newer governance experience on top of the earlier Purview Data Map; docs note it is rolling out region by region and needs the enterprise version of the new Purview experience (Learn, updated 2026-03-16). Exact launch dates not verified (see Open items).

Editions and deployment

SaaS, single-tenant model for Unified Catalog. Billing is covered on Microsoft’s billing page (data governance billing and pay-as-you-go models); no amounts here. Managing Foundry and Copilot-in-Fabric interactions with Purview requires pay-as-you-go billing to be enabled (Learn, 2026). Closed source.

Core architecture

  • Data Map: scanners over multicloud sources; metadata and lineage graph.
  • Unified Catalog: governance domains (business-aligned containers), data products (bundles of tables, files, Power BI reports), glossary terms (can carry policies), critical data elements, OKRs, health controls and actions, self-service access requests and access policies.
  • Data quality: rules set top-down per domain, data product or asset; scores at asset, data product and domain level.
  • Purview Analytics in OneLake: export Unified Catalog data into OneLake for analysis in Fabric.

Role in an enterprise AI rollout

AI-ready data needs, and what Purview offers (vendor documentation):

  • Quality: built-in data quality rules and scores per data product.
  • Lineage: lineage between data products and assets to find root causes of quality issues.
  • Access policy: self-service access requests and policies on data products; RBAC for catalog roles. Copilot and agents honour existing permissions: data a user cannot access is not returned.
  • PII / sensitivity handling: classification (sensitive information types, trainable classifiers) and sensitivity labels; with encrypted labels the AI app needs both VIEW and EXTRACT usage rights. Endpoint DLP can warn or block pasting sensitive data into third-party generative AI sites.
  • Semantics: glossary terms, governance domains, critical data elements and data products carry business meaning.

AI features as of October 2026

  • DSPM for AI (and the newer DSPM, with “DSPM for AI (classic)” still documented): front door for discovering AI use, recommendations and one-click policies, reports and activity explorer on prompts and responses. Supported app groups per Learn (page updated 2026-06-25): Copilot experiences and agents (Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio), enterprise AI apps (Microsoft Foundry, Entra-registered apps, Claude Enterprise, ChatGPT Enterprise), and other AI apps seen via browser activity (ChatGPT, Gemini, DeepSeek, consumer Copilot). Microsoft Agent 365 has its own page.
  • Foundry: enable Purview Data Security in the Foundry Control Plane or via Defender for Cloud. Supports DSPM, audit, classification, sensitivity labels, DLP (only prompt-blocking by sensitive information type, scoped to an Entra-registered app), insider risk, communication compliance, eDiscovery, retention, Compliance Manager. RAG apps on Azure AI Search can enforce sensitivity labels at query time (Learn, 2026-05-01). Policies apply to calls with Entra ID user-context tokens.
  • Copilot in Fabric: support first covers Copilot for Power BI (prompts and text responses); other Fabric Copilot experiences and Fabric Data Agent are in preview (Learn, 2026-06). Sensitivity labels and DLP not supported there. Tenant setting “Allow Microsoft Purview to secure AI interactions” (default enabled). Needs enterprise Purview data governance.
  • Unified Catalog: AI-powered copilot search and AI-enabled curation recommendations (Learn). An MCP server for Purview: not verified (the doc URL I tried returned 404).
  • Compliance Manager templates for AI regulations.

Integrations

OneLake and Fabric, Microsoft Fabric, Power BI reports as data products, Entra, Defender for Cloud, Azure AI Search; scanners cover multicloud sources. Compared in data-catalogs-compared.

Strengths and weaknesses (opinion)

  • Strong where the estate is Microsoft 365 / Azure / Fabric and where AI interaction compliance (audit, retention, eDiscovery) matters; one vendor for catalog and security.
  • Weaker as a neutral, deep catalog outside Microsoft (opinion; open-source and independent catalogs lead on openness). Feature support varies by AI app (see tables above), regions and billing mode.

Self-learning

Sources

Open items

  • Launch dates of Unified Catalog and DSPM for AI; any Purview MCP server; named Purview certifications; analyst rankings.