Skip to Content
PurviewCopilot Interaction Compliance Audit

Copilot Interaction Compliance Audit

TL;DR: This skill inspects Microsoft 365 Copilot audit logs and Purview DSPM for AI signals to find where prompts and responses touched sensitive data, then produces a prioritised risk register so you can act on the highest-exposure interactions first.

What does the Microsoft Purview DSPM for AI dashboard reveal about Copilot interactions?

Microsoft Purview Data Security Posture Management (DSPM) for AI shows where Microsoft 365 Copilot and other AI apps interacted with your data. Its activity explorer displays interaction type, user, AI app, sensitive information types and referenced files, drawing on prompts and responses captured in the unified audit log, so you can see where sensitive content was involved.

Copilot audit records list the resources Copilot accessed, including each resource’s sensitivity label ID and any policy that blocked or restricted access. Microsoft describes the original DSPM for AI as a classic version, now replaced by Data Security Posture Management; check which one your tenant shows. This skill treats your tenant as a modern, cloud-only estate governed by Microsoft Entra and Microsoft Purview.

When should you run this skill?

Run this skill when you need evidence of how Microsoft 365 Copilot interacted with labelled or sensitive content, such as before widening a rollout or during a compliance review. It reads audit records and DSPM for AI signals, then ranks interactions by exposure.

  • “Show me which Copilot interactions referenced files labelled Highly Confidential.”
  • “Audit whether Copilot exposed any data subject to DLP policies last month.”
  • “Which users are generating the highest-risk Copilot prompts in our tenant?”
  • “Prepare a compliance evidence pack for our Copilot rollout review.”
  • “Did any Copilot response include personally identifiable or financial information?”
  • “Assess our DSPM for AI posture before we widen Copilot licensing.”
  • “Flag Copilot interactions that touched content lacking a sensitivity label.”

How this skill works, step by step

  1. Confirm read-only access to the Microsoft Purview portal and the unified audit log via an appropriately scoped Microsoft Entra identity.
  2. Query Microsoft 365 Copilot audit events for the requested period, capturing prompt and response message references, accessed resources, and the acting user.
  3. Pull DSPM for AI signals to enrich each interaction with sensitive information types and referenced files, and use the policy details in the audit record to see where a policy blocked or restricted access.
  4. Correlate each interaction with Microsoft Entra user and group context to establish role and access scope.
  5. Classify interactions by the highest sensitivity label or information type referenced and whether a control (label, DLP) was present.
  6. Derive a risk score per interaction from data sensitivity, control coverage, and user exposure breadth.
  7. Aggregate scores into a prioritised register, grouping recurring patterns by user, label, and data type.
  8. Summarise tenant-level posture, highlighting unlabelled content reached by Copilot and gaps in DLP coverage.

Output format

The skill returns a prioritised risk register followed by a posture summary. The rows below are illustrative, not real data, and the risk score is this skill’s own rating rather than a Microsoft field.

Interaction IDUserSensitive Data ReferencedControl PresentRisk Score
CP-10482finance.lead@contoso.comHighly Confidential label, sensitive information type ADLP policy restricted accessHigh
CP-10519hr.coord@contoso.comUnlabelled document, sensitive information type BNoneCritical
  • Total Copilot interactions analysed and the number flagged at High or Critical risk.
  • Top users and sensitivity labels driving exposure.
  • Count of interactions touching unlabelled or uncontrolled sensitive content.
  • Recommended remediation priorities, such as extending DLP scope or applying default labels.

Scope and safety

This skill is read-only by default and makes no changes to your tenant, policies, or data.

This skill does NOT:

  • Modify, delete, or quarantine any Copilot interaction, file, or audit record.
  • Create, edit, or disable sensitivity labels, DLP policies, or Conditional Access rules.
  • Change user licensing, permissions, or Microsoft Entra group membership.
  • Disable or restrict Microsoft 365 Copilot for any user or organisation unit.

Licensing and permissions

Audit prerequisites

  • Copilot and AI application audit logs are generated automatically as part of Audit (Standard); Microsoft says no extra configuration is needed if auditing is enabled.
  • Audit (Standard) retains records for 180 days. Audit (Premium) adds audit log retention policies and up to one year of retention (up to 10 years with an add-on licence). Under Audit (Premium), Microsoft Entra ID, Exchange, OneDrive and SharePoint records are kept for one year by default, and Microsoft states that records for all other activities are kept for 180 days by default unless a retention policy extends them.
  • Microsoft documents licence requirements for Audit and DSPM for AI on its subscription and service description pages. Confirm your tenant’s entitlement there, because this page does not state a minimum licence.

Least-privilege roles

  • Audit search: the Audit Logs or View-Only Audit Logs role in the Microsoft Purview portal.
  • DSPM for AI: an account with compliance-management permissions, such as membership of the Microsoft Entra Compliance Administrator group role. Microsoft notes that administrative-unit restricted admins cannot create the one-click policies for all users.
  • Reading prompt and response text in activity explorer depends on holding the right permissions; check the Purview permissions guidance before promising it.

Sources

Reviewed 2026-09-30: removed unsourced licence tiers (E3/E5), Global Reader and Compliance Data Administrator roles, Microsoft Graph permission names, the Security and Compliance PowerShell claim, and the Essential Eight and ISM alignment statement; added sourced audit retention, roles and record properties.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-02

Last updated on