Microsoft IQ: The Missing Link Between AI and Business Context

Artificial Intelligence is everywhere today. Organizations are deploying agents, copilots, and generative AI solutions at an unprecedented pace. Yet many AI projects still struggle with a fundamental problem: AI may be intelligent, but it often lacks a true understanding of the business it serves.  This is exactly where Microsoft IQ comes in. Announced as Microsoft’s unified enterprise intelligence layer, Microsoft IQ is designed to help AI agents and Microsoft 365 Copilot understand not just data, but also people, processes, knowledge, and business relationships across the organization. Instead of AI working with isolated information sources, Microsoft IQ creates a shared understanding of the enterprise.

 

Why AI Needs More Than Data

Many organizations assume that giving an AI model access to documents and databases is enough. In reality, AI often struggles because it lacks context.

Consider these questions:

  • Who is the right person to approve a request?
  • Which policy takes precedence?
  • Who was involved in a customer decision?
  • What business rules govern a specific process?

Traditional AI systems can search for information, but they rarely understand how information connects across the organization.

Microsoft IQ addresses this challenge by bringing together how people work, how the business operates, and how organizational knowledge is structured into a single intelligence layer.

 

What Is Microsoft IQ?

Microsoft describes Microsoft IQ as a “unified intelligence layer for enterprise AI.” It provides a continuously updated understanding of the organization that can be used by Microsoft 365 Copilot, custom AI agents, and business applications.

Instead of building separate integrations for every AI project, organizations can leverage a shared intelligence foundation that connects:

  • Work activities
  • Business data
  • Enterprise knowledge
  • Web intelligence

This helps AI agents deliver more relevant, accurate, and context-aware responses.

 

The Four Pillars of Microsoft IQ

Work IQ

Work IQ focuses on understanding how people work.

It continuously analyzes signals from:

  • Email
  • Meetings
  • Calendar
  • Chats
  • Files
  • Collaboration patterns
  • Business systems

The goal is not simply to retrieve content. Work IQ builds a semantic understanding of how work happens across the organization. This enables AI agents to understand relationships, responsibilities, priorities, and workflows.

Imagine asking:

“Who should be involved in this customer escalation?”

Instead of returning random documents, an agent powered by Work IQ can identify the most relevant stakeholders based on organizational context and collaboration patterns.

 

Fabric IQ

Fabric IQ brings business intelligence into the AI experience.

It provides agents with an understanding of:

  • Business entities
  • Metrics
  • Relationships
  • Processes
  • Semantic models

By leveraging existing Microsoft Fabric and Power BI investments, organizations can reuse trusted business definitions and data models rather than rebuilding them for AI. This means an AI agent can understand not only that a metric exists, but also what it means to the business.

 

Foundry IQ

Knowledge is often scattered across thousands of documents, policies, and repositories.

Foundry IQ helps consolidate institutional knowledge into a trusted foundation for AI.

It enables agents to access:

  • Policies
  • Compliance requirements
  • Internal documentation
  • Knowledge bases
  • Authoritative business content

This reduces the risk of agents providing incomplete or inconsistent answers by grounding them in approved knowledge sources.

 

Web IQ

Businesses operate in a world that changes every day.

Web IQ extends enterprise knowledge with external intelligence from the web, helping AI systems stay aware of current events, market developments, and external information when appropriate. Combined with internal enterprise knowledge, this creates a richer, more complete view of the world.

 

Security and Governance Built-In

One of the biggest concerns I hear from organizations exploring AI is data oversharing.

The good news is that Microsoft IQ was designed with enterprise governance in mind.

Microsoft states that IQ respects existing permissions, Microsoft Entra-based access controls, and Microsoft Purview sensitivity labels. This means agents can only access information users are already authorized to see. For organizations already investing in Microsoft Purview and Microsoft Entra, this approach helps extend existing governance controls into the AI era rather than creating a separate security model.

 

A Practical Example

Let’s imagine a sales executive preparing for a customer meeting.

Without Microsoft IQ, the executive might need to:

  • Search emails
  • Review Teams chats
  • Check CRM records
  • Read project updates
  • Review Power BI reports

With Microsoft IQ, an AI agent can bring everything together automatically and answer questions such as:

  • What is the current status of the customer account?
  • What open issues exist?
  • Which stakeholders are involved?
  • What revenue opportunities exist?
  • What actions were agreed during recent meetings?

Instead of searching multiple systems, the executive receives a contextual business briefing within seconds.

 

Why Microsoft IQ Matters

The future of AI is not just about having better models.

It is about giving those models a deeper understanding of your business.

Microsoft IQ represents a significant shift from AI that simply retrieves information to AI that understands context, relationships, processes, and organizational knowledge. By combining Work IQ, Fabric IQ, Foundry IQ, and Web IQ, Microsoft is building a foundation that allows agents to operate with greater intelligence, accuracy, and business awareness.  As organizations move beyond AI experimentation and toward enterprise-scale adoption, contextual intelligence may become the most important differentiator between helpful AI and truly transformative AI. And that is exactly the promise of Microsoft IQ.

 

What excites you most about Microsoft IQ?

Is it the ability to connect business knowledge, improve Copilot responses, strengthen governance, or build smarter AI agents? Share your thoughts in the comments.

 

 

🎧 Tune in for all the details!
🎥 Watch the episode: Microsoft IQ – The Missing Intelligence Layer for Enterprise AI

Microsoft Purview DLP Expands to Microsoft Cowork

As organizations continue to embrace AI-powered productivity tools, maintaining strong data protection and compliance controls remains a top priority. To support the secure adoption of Microsoft Cowork, Microsoft is extending Microsoft Purview Data Loss Prevention (DLP) capabilities to this new AI experience, ensuring organizations can apply consistent data protection policies across both Microsoft 365 Copilot and Microsoft Cowork. This update helps organizations reduce the risk of sensitive information exposure while enabling employees to take advantage of AI-driven productivity tools with confidence.

 

What’s New?

With this enhancement, existing and future DLP policies configured for Microsoft 365 Copilot will automatically extend to Microsoft Cowork. This means administrators can manage AI-related data protection through a single set of policies and controls without additional configuration.

 

The following DLP capabilities will be supported:


1. Sensitivity Label-Based Grounding Protection

Organizations can prevent Microsoft Copilot and Microsoft Cowork from using specific content as grounding data when generating responses.

For example, documents or emails labeled Highly Confidential can be excluded from AI processing, helping ensure protected information is not used to generate responses.

2. Prompt DLP Protection

Administrators can block prompts that contain sensitive information by leveraging Sensitive Information Types (SITs).

Examples include:

  • Credit card numbers
  • National identification numbers
  • Financial account details
  • Custom Sensitive Information Types created by the organization

If a prompt contains protected content, users can be prevented from submitting it to Copilot or Cowork.

3. Web Search DLP Controls

Organizations can allow AI prompts to be processed while restricting sensitive information from being sent to Bing Search for web-based results.

This provides an additional layer of protection when users leverage AI experiences that combine organizational data with web content.

Important: Prompt DLP and Web Search DLP currently apply only to text entered in prompts and do not cover uploaded files.

 

What This Means for Organizations

The update simplifies AI governance by automatically extending protection to Microsoft Cowork.

Key changes include:

  • Existing DLP policies targeting Microsoft Copilot will automatically apply to Microsoft Cowork.
  • New DLP policies created for Microsoft Copilot will include Microsoft Cowork by default.
  • Sensitivity labels can be used to prevent protected content from being used as grounding data.
  • Sensitive Information Types can be used to block prompts or restrict sensitive information from being sent for web searches.
  • No separate setup or configuration is required.

For organizations already using Microsoft Purview DLP, this significantly reduces the effort required to secure emerging AI workloads.

 


Rollout Timeline

Public Preview

  • Begins in late September 2026
  • Expected to complete by early October 2026


General Availability

  • Begins in mid-October 2026
  • Expected to complete by late October 2026

 

What Should Administrators Do?

While no action is required to receive the update, Microsoft recommends that administrators:

  • Review current DLP policies targeting Microsoft 365 Copilot.
  • Assess whether additional sensitivity labels should be protected.
  • Evaluate existing and custom Sensitive Information Types.
  • Inform compliance, security, and AI governance teams about the expanded coverage.

Why This Matters

As AI becomes increasingly integrated into daily business operations, organizations need confidence that their existing compliance and security investments extend to new AI services. By bringing Microsoft Cowork under the protection of Microsoft Purview DLP, Microsoft is delivering a more unified approach to AI governance, helping organizations maintain control over sensitive data while accelerating AI adoption across the enterprise.

The result is a consistent security and compliance experience across Microsoft’s AI ecosystem, allowing businesses to innovate without compromising on data protection.

 

🎧 Tune in for all the details!
🎥 Watch now and discover how to secure AI without slowing innovation.

 

🚨 “We’ve Got a Breach!”

Probably not the words anyone wants to hear during a normal workday.

But when you’re learning cybersecurity, it’s exactly the kind of situation you should be prepared for.

The reality is that cyberattacks don’t wait until security teams have finished their training. Threats evolve constantly, and responding effectively requires more than theory. It requires practice.

That’s why I’m excited to share Cyber Genius | Inside the Breach, a free cybersecurity learning experience from Microsoft and Founderz that places you in the middle of a realistic security incident. From the first alert to full resolution, you’ll step through the same types of challenges security professionals face every day.

What you’ll do

🔍 Investigate suspicious alerts and indicators of compromise

🕵️ Hunt down threats across the environment

🛡️ Respond using real-world security workflows and methodologies

☕ Keep your cool while everything is (fictionally) on fire

Why it’s different

This isn’t another course filled with endless slides and passive learning. Instead, you’ll gain hands-on experience by working through a simulated breach scenario at your own pace, developing practical skills as you go.

Once you’ve completed the experience, you’ll have the opportunity to join Microsoft security experts live on 30 September 2026 for additional insights and discussion.

Event Details

✅ Free and online

✅ Self-paced learning experience

✅ Live expert session

 

📅 30 September 2026

🔗 Register: aka.ms/CyberGenius-ITB

 

Cybersecurity skills are built through practice. The best time to prepare for a breach is before one happens.

Because attackers rarely send a calendar invite first.

 

Removing pay-as-you-go requirements for Edge for Business DLP unmanaged app protections

Good news for Microsoft Purview administrators. Microsoft is removing the pay-as-you-go (PAYG) billing requirement for Data Loss Prevention (DLP) and collection policies that protect unmanaged cloud app interactions in Microsoft Edge for Business. This change, rolling out starting in mid-October 2026, simplifies deployment and management by eliminating the need to connect an Azure subscription specifically for this Edge for Business protection scenario.

 

What’s Changing?

Until now, organizations that wanted to use Microsoft Purview’s inline protection capabilities for unmanaged cloud apps in Edge for Business needed to configure pay-as-you-go billing. Microsoft previously announced this requirement, but it has now decided to remove it.

Once the rollout is complete, administrators will no longer need:

  • An Azure subscription for this specific protection scenario
  • Pay-as-you-go billing configuration
  • Billing prerequisite validation checks when creating or editing applicable policies

The actual protection capabilities are not changing. This is purely a licensing and billing simplification.

 

What Stays the Same?

If you’re already using Purview DLP or collection policies in Edge for Business, there’s nothing you need to change.

Microsoft has confirmed that:

  • Existing policies will continue to work as they do today
  • No migration or policy recreation is required
  • Enforcement behavior remains unchanged
  • Supported inline browser protection activities will continue to be protected

In other words, the protection experience remains exactly the same while the administrative overhead is reduced.

 

Billing Impact

One of the biggest benefits of this update is the removal of charges associated with these protected interactions.

After rollout:

  • Requests related to supported unmanaged cloud app interactions in Edge for Business will no longer generate charges through the In Transit Protection meter.
  • Billing checks and related guidance will disappear from the Purview portal and policy cmdlets for this scenario.

For organizations that hesitated to deploy browser-based DLP because of PAYG requirements, this change removes a significant barrier.

 

Important: This Doesn’t Apply to Everything

It’s worth noting that this update is limited to Edge for Business unmanaged app protections.

Microsoft is not expanding:

  • Supported applications
  • Browsers
  • Activities
  • Licensing requirements
  • Devices
  • Cloud environments

Additionally, other Microsoft Purview capabilities that rely on pay-as-you-go billing, such as Microsoft Purview Network Data Security, are not affected by this announcement. If your organization uses other PAYG-enabled Purview services, those Azure billing configurations may still be required.

 

Rollout Timeline

The update is scheduled to roll out worldwide:

  • Start: Mid-October 2026
  • Expected completion: Late October 2026

Because the deployment is gradual, some tenants may continue to see PAYG requirements in the Purview portal until the update reaches their environment.

 

What Should Administrators Do?

The short answer: nothing.

Microsoft has stated that no action is required.

However, I recommend administrators:

  1. Continue using existing DLP and collection policies as configured.
  2. Avoid removing Azure billing configurations that support other PAYG-based Purview workloads.
  3. Monitor Microsoft documentation during the rollout for updated guidance.

 

This is a welcome change that makes Microsoft Purview easier to adopt and manage. Security teams can continue protecting sensitive data flowing to unmanaged cloud applications through Edge for Business without having to worry about additional billing configuration or consumption-based charges for this use case.

While the underlying DLP capabilities remain unchanged, reducing administrative complexity is always a step in the right direction. For organizations looking to strengthen browser-based data protection, this removes one more obstacle and makes deployment a little more straightforward.

 

Microsoft Purview Autolabeling Gets a Major Scale Upgrade: From 4 Million to 20 Million Items

Microsoft is expanding the capabilities of Microsoft Purview Information Protection, making it easier for organizations to deploy and validate autolabeling policies across significantly larger data environments.  The headline enhancement is a substantial increase in autolabeling simulation capacity, growing from 4 million to 20 million items. For organizations managing large volumes of content across Microsoft 365, this change removes a major limitation when testing and validating labeling strategies before production deployment.

What’s Changing?

With this update, administrators will be able to simulate autolabeling policies against much larger datasets, helping them better understand potential policy impact and identify issues before enabling automatic labeling.

Microsoft is also introducing several improvements aimed at simplifying policy management and providing deeper visibility into how labeling policies perform.

Key Enhancements

Autolabeling simulations now support up to 20 million items

The previous simulation limit of 4 million items has been increased fivefold, allowing organizations to assess policy effectiveness across significantly larger data estates.

Expanded SharePoint targeting

Administrators will now be able to:

  • Select up to 1,000 individual SharePoint sites when configuring an autolabeling policy.
  • Use adaptive scopes that support up to 50,000 SharePoint sites per policy.
  • Filter SharePoint sites using the SiteTemplate property during policy creation, providing more granular control over policy targeting.

Improved reporting and visibility

Microsoft is enhancing the audit and reporting experience with new insights, including:

  • Summaries of the Sensitive Information Types (SITs) detected when labels are applied.
  • A new 30-day processing chart that shows the number of files processed each day, helping administrators track policy throughput and identify trends over time.

These reporting enhancements should make it much easier to understand why labels are being applied and monitor the effectiveness of information protection policies.

Rollout Timeline

Microsoft plans to release these capabilities according to the following schedule:

  • Public Preview: Early September 2026 through mid-September 2026
  • General Availability: Beginning in late October 2026

The features will be enabled automatically as they become available in each tenant.

What Does This Mean for Organizations?

For most organizations, no action is required. Existing autolabeling policies will continue to function exactly as they do today.

However, security and compliance teams may want to revisit policies that were previously constrained by simulation limits or SharePoint scope restrictions. The increased scale opens opportunities to include additional repositories and validate policies against much larger datasets before deployment. Organizations should also consider updating their operational and reporting processes to take advantage of the new SIT visibility and processing metrics.

Compliance Impact

The update does not change how labels work, how Sensitive Information Types are defined, or how customer data is handled.

Instead, Microsoft is increasing the scale at which policies can be evaluated while improving monitoring and reporting capabilities. The added visibility into detected Sensitive Information Types and policy processing activity should help compliance teams better demonstrate and validate their information protection efforts.

Final Thoughts

This is a welcome enhancement for enterprises managing large-scale Microsoft 365 environments. The jump from 4 million to 20 million simulated items, combined with expanded SharePoint coverage and richer reporting, makes Microsoft Purview’s autolabeling capabilities more practical for organizations with complex compliance requirements and large volumes of content. For many Purview administrators, the real value will come from being able to test policies more thoroughly, target more content locations, and gain better insight into exactly how their information protection strategy is performing.

Main Improvements Made

  • Converted formal release-note language into a conversational blog style.
  • Added clear section headings and narrative flow.
  • Focused on business value and real-world impact rather than feature descriptions alone.
  • Reduced repetitive compliance wording while preserving all key technical details.
  • Added a concise conclusion with practical takeaways for administrators and compliance teams.

MS-102 vs. AB-650: More Than a New Certification. A New Era for Microsoft 365 Administrators

When I first saw that Microsoft plans to retire MS-102: Microsoft 365 Administrator and introduce AB-650: Administering Microsoft 365 and AI Services, my immediate reaction wasn’t, “Oh, another certification update.”

Instead, I found myself thinking:  “This is a reflection of how our roles are changing.”

For years, Microsoft 365 administrators have focused on identities, security, compliance, endpoints, licensing, and tenant management. Those responsibilities aren’t going away. But something new is being added to the mix: AI administration.

And that’s exactly what makes the transition from MS-102 to AB-650 so interesting.


The Certification Many of Us Know: MS-102

MS-102 has long been considered the benchmark certification for Microsoft 365 administrators.

The exam validates skills across core areas including:

  • Microsoft 365 tenant management
  • Microsoft Entra ID
  • Identity and access administration
  • Microsoft Defender XDR
  • Microsoft Purview
  • Security and compliance operations

If you’ve spent time administering Microsoft 365 environments, chances are you’ve worked with most of these technologies already.

MS-102 is focused on keeping an organization secure, compliant, productive, and operational.

In many ways, it represents the traditional Microsoft 365 administrator role.

Why Microsoft Is Moving On

Technology never stands still.

Over the last two years, we’ve witnessed something that has fundamentally changed the workplace: the rapid adoption of AI.

Organizations are no longer asking whether they will use AI.

They’re asking:

  • How do we deploy it?
  • How do we govern it?
  • How do we secure it?
  • How do we control access to organizational data?
  • How do we manage AI agents?

These questions weren’t part of a traditional Microsoft 365 administrator’s responsibilities a few years ago.

Today, they are becoming part of everyday conversations.

Enter AB-650

AB-650 isn’t simply a rebranded MS-102.

It’s Microsoft’s acknowledgment that administrators now need a broader skill set.

While the certification still includes core Microsoft 365 administration concepts, it significantly expands into areas such as:

  • Microsoft 365 Copilot administration
  • AI governance
  • AI security
  • AI compliance
  • Agent management
  • Copilot deployment and adoption
  • Organizational AI readiness

In other words, the administrator role is evolving beyond users, devices, and workloads.

We’re now expected to understand and manage intelligent systems as well.


The Biggest Difference

If I had to summarize the difference between the two certifications in a single sentence, it would be this:

MS-102 focuses on managing Microsoft 365. AB-650 focuses on managing Microsoft 365 and AI.

That may sound like a small distinction, but it’s actually a major shift.

The modern workplace increasingly includes:

  • AI assistants
  • Copilot experiences
  • Automation agents
  • Intelligent workflows

Someone needs to govern those capabilities.

Someone needs to secure them.

Someone needs to make sure they are implemented responsibly.

Microsoft clearly sees administrators playing a key role in that future.

Should You Still Take MS-102?

Honestly, I think the answer depends on where you are in your journey.

If you’ve already invested time studying MS-102, I would absolutely consider completing it before retirement.

It’s still a respected certification, and the skills it validates remain highly relevant.

Identity, security, compliance, and administration aren’t becoming less important because AI arrived.

In fact, they’re becoming even more important.

AI simply adds another layer on top.

Who Should Consider AB-650?

If you’re starting fresh today, AB-650 is difficult to ignore.

It’s particularly relevant if you work with:

  • Microsoft 365 Copilot
  • Adoption and change management
  • Security and governance
  • Digital workplace transformation
  • Architecture and consulting roles

The certification aligns closely with the conversations many organizations are having right now around AI readiness and governance.

As someone who has spent much of her career in the Microsoft ecosystem, I see this transition as something bigger than an exam retirement.

I see it as a signal.

A signal that the industry is moving toward a future where administration, security, compliance, user experience, and AI are no longer separate disciplines.

They’re becoming interconnected.

A few years ago, administrators managed users.

Today, we’re beginning to manage users and AI assistants.

Tomorrow, we’ll likely be managing entire ecosystems of human and AI collaboration.

And that’s why I believe the move from MS-102 to AB-650 matters.

It’s not just about earning your next certification.

It’s about understanding where our profession is heading.

What do you think? Would you still pursue MS-102 before it retires, or would you jump directly into AB-650 and the AI-first future?

Microsoft Purview Expands DLP and AutoLabeling to Third-Party Apps

Microsoft is taking another major step toward unified data protection by extending Microsoft Purview Data Loss Prevention (DLP) and autolabeling capabilities beyond the Microsoft ecosystem. Organisations will soon be able to protect and classify data stored in popular third-party applications such as Google Workspace, Box, Salesforce, Dropbox, ServiceNow, AWS, and Cisco Webex, all from within Microsoft Purview.

A Single Compliance Hub for More Applications

Traditionally, organisations managing data across multiple cloud platforms had to rely on separate security and compliance controls for each application. With this update, Microsoft Purview becomes a more centralised compliance solution by allowing administrators to create and manage DLP and autolabeling policies for supported non-Microsoft applications directly from the Purview portal.

The integration is made possible through Microsoft Defender for Cloud Apps connectors, which securely connect these third-party services to Microsoft Purview.

Once the feature is rolled out, dedicated application locations for supported non-Microsoft services will appear in Microsoft Purview. Administrators will be able to:

  • Create and manage Data Loss Prevention (DLP) policies for supported applications.
  • Create and manage Information Protection autolabeling policies.
  • Apply compliance controls from a single management interface.
  • Extend sensitivity labels and data protection policies beyond Microsoft 365 workloads.

Supported Applications

DLP Support

Microsoft Purview DLP will support the following applications:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex

AutoLabeling Support

Autolabeling will initially be available for:

  • Google Workspace
  • Box

Available policy actions and conditions will vary depending on the application and may include content inspection, sensitivity labelling, notifications, quarantine actions, and access controls.

Rollout Timeline

Microsoft plans to release the feature according to the following schedule:

  • Public Preview: Mid-August 2026 to early September 2026
  • General Availability: Early September 2026 through late October 2026

Important Considerations

Organisations currently using Microsoft Defender for Cloud Apps file policies for the same third-party locations should take note: Microsoft recommends disabling or removing those existing file policies before creating equivalent policies in Microsoft Purview. Running both simultaneously could result in unexpected policy enforcement behaviour.

Licensing and Pricing

To use these new capabilities, organisations will need:

  • An eligible Microsoft Purview Enterprise license
  • Connected applications via Microsoft Defender for Cloud Apps

Additionally, customers should review the pricing implications associated with Microsoft Purview At Rest Protection. Usage is billed on a pay-as-you-go basis, with 1,000 files counted as one data asset for billing purposes.

Why This Matters

As organisations continue adopting multi-cloud and multi-platform environments, data often resides well beyond Microsoft 365. This update allows security and compliance teams to apply consistent protection, classification, and governance policies across a broader range of business-critical applications without requiring separate management tools.

By bringing DLP and autolabeling capabilities to leading third-party services, Microsoft is helping organisation simplify compliance operations while strengthening data security wherever sensitive information resides.

This enhancement significantly expands Microsoft Purview’s reach, making it a stronger centralised platform for information protection and compliance. For organisations using a mix of Microsoft and non-Microsoft cloud services, the ability to manage DLP and labeling policies from a single console could reduce complexity, improve governance consistency, and strengthen overall data protection strategies.

🎧 Tune in for all the details!
🎥 Watch the full episode ➡️ here

Microsoft 365 Copilot Gets Clearer DLP Notifications

Have you ever wondered why Copilot couldn’t access, process, or return certain content?
Microsoft is making that experience much easier to understand. Previously, users could see different messages depending on how a Microsoft Purview Data Loss Prevention (DLP) policy was triggered, which sometimes made it unclear why content wasn’t available.

With this update, Microsoft 365 Copilot will now display a consistent notification whenever organisational DLP policies prevent access to content. The goal is simple: improve transparency, reduce confusion, and help users understand that Copilot is respecting their organisation’s data protection policies.

What’s Covered?

The new standardized message applies to Microsoft Purview DLP protections across Microsoft 365 Copilot and Copilot Chat, including:

  • Grounding DLP
  • Prompt DLP
  • External Email DLP

Where Will Users See It?

The unified notification can appear across Microsoft 365 Copilot experiences powered by Microsoft 365 Chat orchestration, including:

  • Microsoft 365 Copilot
  • Microsoft 365 Copilot Chat
  • Microsoft Teams Copilot experiences
  • Outlook on the web Copilot experiences
  • Microsoft Edge Copilot experiences
  • Other Microsoft 365 Copilot chat experiences that rely on Microsoft 365 Chat orchestration

Whenever a DLP policy restricts Copilot from using specific content, users will see the same clear message indicating that access to some content has been restricted by an organisational policy.

Rollout Timeline

The feature is now rolling out across all environments:

  • Worldwide: Available from July 15, 2026
  • GCC: Available from July 20, 2026
  • GCC High and DoD: Available from July 23, 2026

What This Means for Your Organisation

Organizations already using Microsoft Purview DLP with Microsoft 365 Copilot or Copilot Chat don’t need to take any action. The update does not change how DLP policies work. Instead, it improves the user experience by providing a clearer and more consistent explanation when content is blocked.

For IT administrators, this is a good opportunity to review existing training materials, user documentation, and support resources to ensure they reflect the new messaging experience.

Bottom line: the protection remains the same, but the explanation gets better. Users gain more clarity on why content is unavailable, while organisations continue to benefit from the same trusted data protection controls.

🚀Microsoft 365 Copilot Adds Custom Guidance Links for Users Blocked from Copilot Chat

Starting in July 2026, Microsoft 365 Copilot will introduce a new optional feature that allows administrators to add a custom policy or guidance link for users who are blocked from accessing Copilot Chat. When restricted users attempt to open Copilot Chat, they’ll be directed to organisation-specific information that can explain access requirements and provide next steps. The feature can be configured through the Microsoft 365 admin centre and does not affect existing access controls or policies. No administrative action is required unless organisations choose to enable and customise this experience.

What’s changing?

Organisations will now have the option to add a custom policy or support link for users who are blocked from Copilot Chat through administrative policies. Instead of only seeing a standard Microsoft message, affected users can be directed to organization-specific guidance that explains why access is restricted and outlines the appropriate next steps.

This enhancement is designed to reduce confusion, improve communication, and make it easier for users to find the information they need when access is unavailable.

Rollout timeline

  • General Availability (Worldwide): Starting in July 2026
  • Expected completion: August 2026

Who is affected?

This update may be relevant for:

  • Organizations using the Microsoft 365 Copilot app
  • Administrators managing Copilot access through Integrated Apps policies
  • Users whose access to Copilot Chat has been restricted by policy

What admins should know

This feature is optional and disabled by default. Organisations that want to provide customised guidance can configure a support URL in the Microsoft 365 admin centre under Copilot settings.

Potential uses include:

  • Explaining why access is restricted
  • Sharing internal Copilot adoption policies
  • Providing licensing information
  • Directing users to support resources or help-desk contacts
  • Outlining the process for requesting access

Recommended actions

No action is required.

However, organizations that want to take advantage of this feature should consider:

  • Reviewing their current Copilot access policies
  • Identifying relevant internal guidance or support resources
  • Configuring a custom URL in the Microsoft 365 admin center
  • Preparing helpdesk teams for the updated experience
  • Monitoring Microsoft Learn documentation for additional setup guidance

Microsoft Purview DLP: Instances Policy Location Retiring in January 2027

Microsoft has announced the retirement of the Instances policy location in Microsoft Purview Data Loss Prevention (DLP), with the change taking effect on January 6, 2027.

Today, organizations using the Instances location rely on the Microsoft Defender for Cloud Apps file policy infrastructure to enforce DLP and auto-labeling policies across supported third-party applications. To simplify policy management and provide a more consistent compliance experience, Microsoft is moving away from this approach and introducing dedicated application-specific policy locations directly within Microsoft Purview.

Supported applications include:

  • Google Workspace
  • Box
  • Dropbox
  • Salesforce
  • ServiceNow
  • AWS
  • Cisco Webex
What’s Changing?

Instead of creating policies under a generic Instances location, administrators will use dedicated locations for each supported application.

For example:

Current LocationNew Location
Instances (Google Workspace)Google Workspace
Instances (Box)Box
Instances (Dropbox)Dropbox
Instances (Salesforce)Salesforce
Instances (ServiceNow)ServiceNow
Instances (AWS)AWS
Instances (Cisco Webex)Cisco Webex

This change aligns non-Microsoft application protection more closely with the broader Microsoft Purview compliance framework.

Microsoft is introducing these new application locations ahead of the retirement date to allow organizations time to migrate.

Key dates:

  • Dedicated application locations will be rolled out before retirement.
  • January 6, 2027: Instances policy location officially retires.
  • Retirement rollout begins in early January 2027 and is expected to complete by mid-January 2027.
What Happens After January 6, 2027?

Once the retirement takes place:

  • New policies can no longer be created using the Instances location.
  • Existing policies configured with the Instances location will no longer be supported.
  • Organizations should use the new dedicated application locations for all future DLP and auto-labeling policies.
  • Policies that continue to rely on the retired Instances location may no longer be enforced as expected.

If your organization currently uses the Instances location, Microsoft strongly recommends recreating those policies in the new application-specific locations before the retirement deadline.

Recommended Next Steps

To avoid any disruption to DLP enforcement, organizations should begin preparing well before the 2027 deadline.

1. Review Existing Policies

Identify any DLP or auto-labeling policies currently configured through the Instances location.

2. Identify Affected Applications

Determine which non-Microsoft platforms are involved and map them to their new dedicated policy locations.

3. Recreate Policies

Build equivalent policies using the new application-specific locations within Microsoft Purview.

4. Test and Validate

Before retiring legacy policies, verify that policy enforcement, labeling, and user experiences behave as expected.

5. Update Documentation

Review operational procedures, internal documentation, and administrator guidance to reflect the new management model.

6. Notify Stakeholders

Make sure compliance, security, and support teams are aware of the upcoming change and migration timeline.

While the retirement is still several months away, organizations using third-party cloud platforms for collaboration and data storage should start planning their migration strategy now. Moving to dedicated application locations will ensure continued DLP and auto-labeling protection while providing a more streamlined and unified compliance experience within Microsoft Purview.

The bottom line: If you’re using the Instances location today, plan your migration before January 6, 2027. If you’re not, you can safely continue using Microsoft Purview as normal and take advantage of the new dedicated application locations as they become available.