Skip to Content
PurviewDSPM for AI Remediation

DSPM for AI Remediation

TL;DR: Reads a Microsoft Purview DSPM for AI data risk assessment export and produces an owner-assigned remediation checklist covering sensitivity labels, DLP policies and SharePoint sharing clean-up. It is read-only: it plans changes and applies none.

How does the DSPM for AI Remediation skill turn oversharing telemetry into action?

The DSPM for AI Remediation skill reads a Microsoft Purview data risk assessment export and turns each oversharing finding into an owner-assigned action, such as applying a sensitivity label, creating a DLP policy, or removing a sharing link. It produces a plan only and changes nothing in Microsoft 365.

For each finding it names the owner, the SharePoint site, the recommended sensitivity label, the DLP or discovery control to apply, and how to verify the fix. It frames the work for a Microsoft 365 Copilot rollout, where Agentic AI can surface overshared content.

When should you run this skill?

Run this skill when a Microsoft 365 Copilot or agent rollout is planned, or after a Microsoft Purview data risk assessment flags overshared SharePoint content, and you need a prioritised, owner-assigned plan. Microsoft states generative AI amplifies oversharing because it can surface obsolete, over-permissioned or ungoverned content quickly.

  • “Build a DSPM for AI remediation plan”
  • “Turn DSPM findings into actions”
  • “Plan oversharing cleanup for Copilot rollout”

How this skill works, step by step

  1. Ingest the data risk assessment export (Microsoft documents CSV, Excel, JSON and TSV export formats)
  2. Group findings by site, then by sensitivity tier of the exposed content
  3. For each group, pick from the remediation options Microsoft documents (see the table below)
  4. Assign an owner (site owner where present, otherwise the data steward)
  5. Set a target date using the suggested defaults: Critical 7 days, High 30 days, Medium 90 days
  6. Record an evidence pointer for each remediation, such as the assessment name and the Microsoft Learn page that supports the control
  7. Produce the remediation checklist below

The 7, 30 and 90 day targets are this skill’s own suggested defaults. Microsoft does not define them, so adjust them to your risk appetite and change control.

Remediation options Microsoft documents

WhereOptionWhat it does
Default assessment, Protect tabRestrict access by labelUses Microsoft Purview DLP to stop Microsoft 365 Copilot and agents summarising items with selected sensitivity labels
Default assessment, Protect tabRestrict all itemsUses SharePoint Restricted Content Discovery to exempt listed sites from Microsoft 365 Copilot
Default assessment, Protect tabCreate an auto-labelling policyApplies a sensitivity label to unlabelled files where sensitive information is found
Default assessment, Protect tabCreate retention policiesDeletes content not accessed for at least 3 years, using Data Lifecycle Management
Custom assessment, item-levelResolveCloses the item when you decide it is not at risk
Custom assessment, item-levelApply sensitivity labelLabels an unlabelled item or changes its label
Custom assessment, item-levelNotifyEmails the site owner (the email is not customisable)
Custom assessment, item-levelRemove sharing linkRemoves the link so it can no longer be used. Use sparingly, as it can block legitimate access

Output format

FindingSiteSensitivityActionOwnerDueEvidence

Followed by:

  • Total findings: N
  • Critical: N (suggested 7-day target)
  • High: N (suggested 30-day target)
  • Estimated effort by team

Scope and safety

Read-only by default. This skill produces the plan only. It does NOT:

  • Apply labels or modify DLP (read-only, produces the plan only)
  • Remove sharing links or notify site owners
  • Reassign site ownership
  • Replace formal change control

Note that the item-level scanning in Microsoft Purview itself is different. Its Entra application needs Microsoft Graph application permissions that include Files.ReadWrite.All and Sites.ReadWrite.All. This skill does not use that application.

What limits and prerequisites apply to data risk assessments?

Microsoft documents these limits for Microsoft 365 data risk assessments, so check them before you rely on a plan built from an export.

  • A default assessment runs weekly for the top 100 SharePoint sites by usage, and the first run has a 4-day delay before results appear
  • A maximum of 200,000 items per location, and the reported file count may be inaccurate above 100,000 files per location
  • Item-level scanning is limited to SharePoint sites, currently a maximum of 10 sites, and OneDrive is not supported
  • Custom assessment results expire after 30 days, so duplicate the assessment to rerun it
  • Item-level scanning needs a registered Microsoft Entra application with admin consent, created by a Cloud Application Administrator, Application Administrator or Privileged Role Administrator
  • For DSPM for AI (classic), monitoring Microsoft 365 Copilot interactions needs Microsoft Purview auditing enabled and users assigned a Microsoft 365 Copilot licence

This page does not state a minimum Microsoft 365 licence. Confirm licensing against Microsoft’s current Purview service description before you scope work.

Which roles do you need to read DSPM for AI findings?

In DSPM for AI (classic), the Microsoft Purview Security Reader role group, the Purview Data Security AI Viewer role and the Entra AI Administrator role are view-only. They can view data risk assessments but not create them. Creating assessments needs Compliance Administrator or Global Administrator.

AccessRoles Microsoft documents
View, create and editMicrosoft Entra Compliance Administrator, Microsoft Entra Global Administrator, Microsoft Purview Compliance Administrator role group
View onlyMicrosoft Purview Security Reader role group, Purview Data Security AI Viewer role, Entra AI Administrator role
File details in assessmentsContent Explorer Content Viewer or Content Explorer List Viewer, in addition to the above

Microsoft recommends using the roles with the fewest permissions and minimising Global Administrator use. These roles come from the classic permissions page. Microsoft’s current DSPM data risk assessment page cited here does not list roles, so confirm them in your tenant.

Frequently asked questions

What is the difference between a default and a custom data risk assessment?

A default data risk assessment runs automatically each week for the top 100 SharePoint sites by usage. A custom assessment lets you choose users and data sources, and can add item-level scanning for SharePoint. Custom results expire after 30 days, so duplicate the assessment to rerun it.

What remediation actions can Microsoft Purview take on overshared items?

Item-level scanning of SharePoint sites offers four actions on potentially overshared items: Resolve, Apply sensitivity label, Notify the site owner by email, and Remove sharing link. Microsoft advises using link removal sparingly because it can block legitimate access. Items count as potentially overshared when they carry an external or anonymous sharing link.

Are there limits on item-level scanning?

Yes. For Microsoft 365, assessments cover a maximum of 200,000 items per location, and item-level scanning is limited to 10 SharePoint sites at present. OneDrive is not supported for item-level scanning. Item-level scanning also needs a registered Microsoft Entra application with admin-consented Microsoft Graph application permissions, so plan that access request early.

Which roles can view DSPM for AI results?

In DSPM for AI (classic), the Microsoft Purview Security Reader role group, the Purview Data Security AI Viewer role and the Entra AI Administrator role are view-only. They can view data risk assessments but not create them. Creating assessments needs Compliance Administrator or Global Administrator.

Sources

Reviewed 2026-09-30 against the four Microsoft Learn pages below: removed unsourced claims (GA date, Essential Eight and ISM mappings, licence table, unlisted roles, AuditLog.Read.All scope).


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-02

Last updated on