---
name: DSPM for AI Remediation
description: Turn Microsoft Purview DSPM for AI oversharing findings into an owner-assigned remediation plan mapped to labels, DLP and SharePoint sharing clean-up.
lastReviewed: 2026-09-30
---

# DSPM for AI Remediation

> **TL;DR:** Reads a Microsoft Purview DSPM for AI data risk assessment export and produces an owner-assigned remediation checklist covering sensitivity labels, DLP policies and SharePoint sharing clean-up. It is read-only: it plans changes and applies none.

## How does the DSPM for AI Remediation skill turn oversharing telemetry into action?

The DSPM for AI Remediation skill reads a Microsoft Purview data risk assessment export and turns each oversharing finding into an owner-assigned action, such as applying a sensitivity label, creating a DLP policy, or removing a sharing link. It produces a plan only and changes nothing in Microsoft 365.

For each finding it names the owner, the SharePoint site, the recommended sensitivity label, the DLP or discovery control to apply, and how to verify the fix. It frames the work for a Microsoft 365 Copilot rollout, where Agentic AI can surface overshared content.

## When should you run this skill?

Run this skill when a Microsoft 365 Copilot or agent rollout is planned, or after a Microsoft Purview data risk assessment flags overshared SharePoint content, and you need a prioritised, owner-assigned plan. Microsoft states generative AI amplifies oversharing because it can surface obsolete, over-permissioned or ungoverned content quickly.

- "Build a DSPM for AI remediation plan"
- "Turn DSPM findings into actions"
- "Plan oversharing cleanup for Copilot rollout"

## How this skill works, step by step

1. Ingest the data risk assessment export (Microsoft documents CSV, Excel, JSON and TSV export formats)
2. Group findings by site, then by sensitivity tier of the exposed content
3. For each group, pick from the remediation options Microsoft documents (see the table below)
4. Assign an owner (site owner where present, otherwise the data steward)
5. Set a target date using the suggested defaults: Critical 7 days, High 30 days, Medium 90 days
6. Record an evidence pointer for each remediation, such as the assessment name and the Microsoft Learn page that supports the control
7. Produce the remediation checklist below

The 7, 30 and 90 day targets are this skill's own suggested defaults. Microsoft does not define them, so adjust them to your risk appetite and change control.

### Remediation options Microsoft documents

| Where | Option | What it does |
| --- | --- | --- |
| Default assessment, Protect tab | Restrict access by label | Uses Microsoft Purview DLP to stop Microsoft 365 Copilot and agents summarising items with selected sensitivity labels |
| Default assessment, Protect tab | Restrict all items | Uses SharePoint Restricted Content Discovery to exempt listed sites from Microsoft 365 Copilot |
| Default assessment, Protect tab | Create an auto-labelling policy | Applies a sensitivity label to unlabelled files where sensitive information is found |
| Default assessment, Protect tab | Create retention policies | Deletes content not accessed for at least 3 years, using Data Lifecycle Management |
| Custom assessment, item-level | Resolve | Closes the item when you decide it is not at risk |
| Custom assessment, item-level | Apply sensitivity label | Labels an unlabelled item or changes its label |
| Custom assessment, item-level | Notify | Emails the site owner (the email is not customisable) |
| Custom assessment, item-level | Remove sharing link | Removes the link so it can no longer be used. Use sparingly, as it can block legitimate access |

## Output format

| Finding | Site | Sensitivity | Action | Owner | Due | Evidence |
| --- | --- | --- | --- | --- | --- | --- |

Followed by:

- Total findings: N
- Critical: N (suggested 7-day target)
- High: N (suggested 30-day target)
- Estimated effort by team

## Scope and safety

Read-only by default. This skill produces the plan only. It does NOT:

- Apply labels or modify DLP (read-only, produces the plan only)
- Remove sharing links or notify site owners
- Reassign site ownership
- Replace formal change control

Note that the item-level scanning in Microsoft Purview itself is different. Its Entra application needs Microsoft Graph application permissions that include `Files.ReadWrite.All` and `Sites.ReadWrite.All`. This skill does not use that application.

## What limits and prerequisites apply to data risk assessments?

Microsoft documents these limits for Microsoft 365 data risk assessments, so check them before you rely on a plan built from an export.

- A default assessment runs weekly for the top 100 SharePoint sites by usage, and the first run has a 4-day delay before results appear
- A maximum of 200,000 items per location, and the reported file count may be inaccurate above 100,000 files per location
- Item-level scanning is limited to SharePoint sites, currently a maximum of 10 sites, and OneDrive is not supported
- Custom assessment results expire after 30 days, so duplicate the assessment to rerun it
- Item-level scanning needs a registered Microsoft Entra application with admin consent, created by a Cloud Application Administrator, Application Administrator or Privileged Role Administrator
- For DSPM for AI (classic), monitoring Microsoft 365 Copilot interactions needs Microsoft Purview auditing enabled and users assigned a Microsoft 365 Copilot licence

This page does not state a minimum Microsoft 365 licence. Confirm licensing against Microsoft's current Purview service description before you scope work.

## Which roles do you need to read DSPM for AI findings?

In DSPM for AI (classic), the Microsoft Purview Security Reader role group, the Purview Data Security AI Viewer role and the Entra AI Administrator role are view-only. They can view data risk assessments but not create them. Creating assessments needs Compliance Administrator or Global Administrator.

| Access | Roles Microsoft documents |
| --- | --- |
| View, create and edit | Microsoft Entra Compliance Administrator, Microsoft Entra Global Administrator, Microsoft Purview Compliance Administrator role group |
| View only | Microsoft Purview Security Reader role group, Purview Data Security AI Viewer role, Entra AI Administrator role |
| File details in assessments | Content Explorer Content Viewer or Content Explorer List Viewer, in addition to the above |

Microsoft recommends using the roles with the fewest permissions and minimising Global Administrator use. These roles come from the classic permissions page. Microsoft's current DSPM data risk assessment page cited here does not list roles, so confirm them in your tenant.

## Frequently asked questions

### What is the difference between a default and a custom data risk assessment?

A default data risk assessment runs automatically each week for the top 100 SharePoint sites by usage. A custom assessment lets you choose users and data sources, and can add item-level scanning for SharePoint. Custom results expire after 30 days, so duplicate the assessment to rerun it.

### What remediation actions can Microsoft Purview take on overshared items?

Item-level scanning of SharePoint sites offers four actions on potentially overshared items: Resolve, Apply sensitivity label, Notify the site owner by email, and Remove sharing link. Microsoft advises using link removal sparingly because it can block legitimate access. Items count as potentially overshared when they carry an external or anonymous sharing link.

### Are there limits on item-level scanning?

Yes. For Microsoft 365, assessments cover a maximum of 200,000 items per location, and item-level scanning is limited to 10 SharePoint sites at present. OneDrive is not supported for item-level scanning. Item-level scanning also needs a registered Microsoft Entra application with admin-consented Microsoft Graph application permissions, so plan that access request early.

### Which roles can view DSPM for AI results?

In DSPM for AI (classic), the Microsoft Purview Security Reader role group, the Purview Data Security AI Viewer role and the Entra AI Administrator role are view-only. They can view data risk assessments but not create them. Creating assessments needs Compliance Administrator or Global Administrator.

## Related skills

- [Copilot Interaction Compliance Audit](/purview/copilot-interaction-compliance-audit): run before this to surface sensitive-data exposure in Copilot interactions
- [Data Access Governance Report Review](/sharepoint/data-access-governance-report-review): run before this to interpret oversharing and sharing-link signals
- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): run before this to find risky sharing links and site permissions
- [Purview Label Coverage](/purview/purview-label-coverage): run after this to check sensitivity label coverage
- [Governing Microsoft 365 Copilot with Microsoft Purview](/purview/copilot-governance-guide): start here for the Purview controls documented for Microsoft 365 Copilot

## Sources

Reviewed 2026-09-30 against the four Microsoft Learn pages below: removed unsourced claims (GA date, Essential Eight and ISM mappings, licence table, unlisted roles, AuditLog.Read.All scope).

- [Microsoft Purview data security and compliance protections for generative AI apps](https://learn.microsoft.com/en-us/purview/ai-microsoft-purview)
- [Prevent oversharing with data risk assessments from Data Security Posture Management](https://learn.microsoft.com/en-us/purview/data-security-posture-management-oversharing)
- [Considerations for DSPM for AI (classic)](https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations)
- [Permissions for DSPM for AI (classic)](https://learn.microsoft.com/en-us/purview/ai-microsoft-purview-permissions)
- Pair with SharePoint Oversharing Audit for ongoing baselining
