
Microsoft is bringing new Copilot readiness and Data Explorer experiences into Purview DSPM, and this could change how we think about AI readiness.
If you’ve been following Microsoft Purview over the last couple of years, you’ll probably have noticed something. The conversation has changed.
We used to ask:
“Have we classified our data?”
Then:
“Have we protected our sensitive information?”
Then:
“Are we ready for Copilot?”
Now we’re moving towards something much more useful:
“Can we actually see the risks that determine whether we’re ready for AI?”
That’s where Microsoft Roadmap 571157 gets interesting.
Microsoft is introducing new Readiness for Microsoft Copilot and Data Explorer experiences within Purview Data Security Posture Management (DSPM), currently targeted for January 2027.
And I think this is much more significant than simply adding another dashboard.
π Copilot readiness shouldn’t just mean “Can we deploy Copilot?”
There is a tendency to think of Copilot readiness as a technical exercise.
Do we have the licences?
Are the apps supported?
Are the devices ready?
Are users trained?
Can Copilot technically be deployed?
Those are important questions.
But they’re not the questions that keep information governance people awake at night.
The bigger question is:
What will Copilot discover when we give it access to our organisational data?
Because Copilot doesn’t need to break your security model to expose a governance problem.
It can simply use the permissions you’ve already given people.
Imagine someone has access to 20,000 SharePoint documents.
Perhaps nobody has looked at most of them for years.
Perhaps some contain sensitive information.
Perhaps some are shared much more widely than they should be.
Perhaps the site owner left the organisation three years ago.
Perhaps nobody remembers why the permissions were configured that way.
And then you introduce AI.
Suddenly, all that old information becomes much easier to find, correlate and summarise.
The problem wasn’t created by Copilot.
Copilot simply makes the problem much more visible.
π This is where DSPM becomes important
Microsoft describes DSPM as a way to discover, assess and remediate data security risks across the organisation, including risks involving AI apps and agents.
That’s an important shift.
We’re moving away from:
“Here’s a collection of security controls.”
Towards:
“Here’s the security posture of our data.”
And Roadmap 571157 appears to push that idea further.
The new Readiness for Microsoft Copilot experience is intended to bring together insights around:
- Sensitive data exposure
- Oversharing
- Protection coverage
- Data readiness
- Progress towards a more secure Copilot deployment
In other words, instead of simply asking whether Copilot is technically deployable, organisations can start asking whether their data estate is actually ready for Copilot.
That’s a much better question.
π And then there’s Data Explorer
The second part of the roadmap item is equally interesting.
Microsoft is introducing a new Data Explorer experience within DSPM.
The roadmap describes this as a centralised investigation experience that helps security teams understand where sensitive data exists, review site-level access and explore relevant data through preset views.
This matters because identifying a risk is only half the job.
Imagine DSPM tells you: “You have sensitive information exposed in these areas.”
Great.
Now what?
You need to investigate.
Where is the data?
Which sites contain it?
Who has access?
What type of sensitive information is involved?
Is the access intentional?
Is the content still required?
Is it protected?
Does the site have a legitimate business owner?
That’s where an explorer becomes much more useful than a high-level score.
π Data discovery β investigation β remediation
This is the pattern I want to see more of in data governance.
Think about the lifecycle:
DISCOVER
Where is the sensitive information?
β
UNDERSTAND
What is it?
Who can access it?
β
ASSESS
Is that access appropriate?
β
PROTECT
Should we apply a sensitivity label, DLP control or other protection?
β
REMEDIATE
Should we change permissions, move the data, label it, archive it or delete it?
β
MONITOR
Has the risk actually gone away?
That’s governance, not just another dashboard.
π Data Explorer isn’t just another Content Explorer
This distinction is important.
Microsoft’s current Purview Data Explorer already provides visibility into items that have been labelled, retained or classified with sensitive information types. It can drill into locations such as SharePoint and OneDrive and provides detailed investigation capabilities.
The new roadmap experience is positioned within DSPM, with a specific focus on investigating data-security posture and Copilot readiness.
That’s significant because it connects the data itself with the security posture around that data.
And that’s exactly where I think Purview is heading.
π The real question: “Ready for what?”
Here’s the part I find most interesting.
I don’t think organisations should define Copilot readiness as:
“We’ve turned on Copilot.”
Readiness should mean something closer to:
“We understand what data Copilot could reach, why it can reach it, whether that access is appropriate, and what controls are protecting it.”
That’s a much higher bar.
And it isn’t just about Copilot.
The same thinking applies to:
- AI agents
- Copilot Studio
- Microsoft 365 Copilot
- Enterprise AI applications
- Autonomous agents
- AI-powered workflows
The more AI becomes capable of finding and acting on organisational information, the more important the underlying data governance becomes.
π Your SharePoint permissions suddenly matter a lot more
This is one of the biggest lessons from the AI era. For years, an organisation could have:
- Old SharePoint sites
- Overshared folders
- “Everyone except external users”
- Inherited permissions
- Stale documents
- Orphaned sites
- Unlabelled sensitive information
- Poorly managed Teams
- Forgotten project sites
And nothing appeared to happen. The data just sat there. But AI changes the equation.
A human might never find that document. An AI assistant potentially can.
That’s why I keep coming back to this:
AI governance is becoming information governance.
If the information isn’t governed properly, giving AI better access to it doesn’t solve the problem. It amplifies it.
π What should organisations do now?
Don’t wait for January 2027.
Roadmap dates can move, and this capability is currently listed as In development, so the exact delivery timeline should be treated as Microsoft’s current estimate rather than a guaranteed date.
But the underlying preparation makes sense today. I’d start with five things:
1. Understand your sensitive data
Know where your sensitive information actually lives.
Purview Data Explorer already provides visibility into classified and labelled content across supported locations.
2. Investigate SharePoint oversharing
Don’t just count sites.
Understand:
Who can access what?
And more importantly:
Why?
3. Review protection coverage
Ask:
- Which sensitive data is labelled?
- Which isn’t?
- Where is DLP protecting it?
- Where are protection gaps?
- Are retention and lifecycle controls appropriate?
4. Review stale information
Old information isn’t automatically harmless.
If it’s still accessible, it may still be relevant to AI.
Ask:
Should this information still be available to AI?
That’s a very different question from:
Should we retain this information?
Retention and AI relevance aren’t the same thing.
5. Treat AI readiness as an ongoing process
Don’t run one assessment, fix 20 sites and declare victory.
Data changes.
Permissions change.
Sites change.
Agents change.
AI capabilities change.
Therefore:
AI readiness needs to become continuous data governance.
π The bigger picture
Roadmap 571157 is interesting because it represents something bigger than two new Purview screens.
Microsoft is moving towards a model where data security posture becomes part of AI readiness.
And I think that’s exactly where we need to go.
Because the question shouldn’t simply be:
“Can we deploy Copilot?”
It should be:
“Is our data ready for Copilot?”
And then:
“Can we prove it?”
That’s the really interesting bit. Because when AI can search, correlate, summarise and reason across our information estate, data governance stops being something happening quietly in the background. It becomes part of the AI security boundary.
π‘ The Jim Talks takeaway
We’ve spent years building permissions around people.
We’ve spent years classifying information.
We’ve spent years building retention and DLP policies.
Now we’re giving AI the ability to navigate across all of it.
So perhaps the next generation of information governance isn’t just about asking:
Who can access this data?
It’s about asking:
What can AI discover, understand and do with the data they’re allowed to access?
That’s why I’ll be watching Roadmap 571157 closely.
Because Copilot readiness isn’t really about Copilot.
It’s about whether your data estate is ready to be intelligent.
Leave a Reply