By

Published on

🚨 Microsoft Purview Is Retiring DSPM Classic – Here’s What You Need to Do

If your organisation is still using the classic Microsoft Purview Data Security Posture Management experiences, there is a change coming that you should put on the radar now.

Microsoft Message Center update MC1481315 confirms that Microsoft is retiring:

  • Microsoft Purview Data Security Posture Management (DSPM) classic
  • Microsoft Purview DSPM for AI classic

The retirement begins 30 November 2026, with the classic experiences expected to be fully retired by 31 December 2026.

This isn’t simply a navigation change.

Microsoft is moving customers towards a single, unified DSPM experience that brings together data security posture management across traditional data sources, AI applications and AI agents and in my view, that tells us something quite important about where Microsoft sees data security heading.

πŸ‘‰ DSPM for AI is becoming part of DSPM

The original DSPM experiences had a fairly obvious separation. You had traditional DSPM looking at your broader data security posture, then you had DSPM for AI, focused specifically on AI applications, Copilot experiences, agents and the risks associated with AI interactions.

That separation is now going away.

Microsoft has converged DSPM and DSPM for AI into a single experience.

The current Microsoft Learn documentation describes the new DSPM as a unified solution designed to help organisations discover, protect and investigate data risks, while bringing AI applications and agents into the same experience.

That’s an important change in mindset. AI isn’t being treated as a completely separate data security problem anymore.

It’s becoming part of the overall data security posture, and I think that’s the right direction.


πŸ‘‰ So what actually changes?

From 30 November 2026, Microsoft will begin retiring the classic experiences.

By 31 December 2026, they will no longer be available.

Microsoft’s current guidance is that organisations should use the new:

Microsoft Purview portal β†’ Solutions β†’ DSPM

instead.

The new experience brings together capabilities including:

  • Posture
  • Reports
  • Remediation actions
  • Data security objectives
  • Activity Explorer
  • Data risk assessments
  • Apps and agents
  • AI activity visibility
  • Investigation workflows

Microsoft has also published a task-mapping guide showing where familiar DSPM and DSPM for AI activities have moved in the new experience.

So this isn’t a case of Microsoft simply turning off an old portal page. The functionality has been reorganised around the new DSPM model.


πŸ‘‰ What happens to the things you already use?

This is probably the most important question for administrators.

Microsoft’s task mapping gives us a useful indication of how the transition works.

For example:

What you used in classic DSPMWhere to find it now
RecommendationsDSPM β†’ Actions β†’ Remediation actions
Reports and trendsDSPM β†’ Reports
AI app recommendationsDSPM β†’ Actions β†’ Remediation actions
Microsoft 365 Copilot overviewDSPM β†’ Reports β†’ Microsoft 365 Copilot
Apps and agentsDSPM β†’ Discover β†’ Apps and agents
AI Activity ExplorerDSPM β†’ Discover β†’ Activity Explorer β†’ AI activities
Data risk assessmentsDSPM β†’ Discover β†’ Data risk assessments
Security Copilot promptbooksDSPM β†’ Posture

Microsoft describes many of these activities as now being embedded into data security objectives, which are designed to connect a desired business outcome with the Purview capabilities and actions needed to achieve it.

That is an interesting evolution.

We’re moving from:

β€œHere are lots of security capabilities.” towards β€œWhat security outcome are you trying to achieve?”


πŸ‘‰ Why I think this change matters

For me, the really interesting part isn’t the retirement date. It’s the convergence.

We’ve spent a lot of time talking about AI governance as though it were a completely separate discipline.

AI governance.

Data governance.

Information protection.

DLP.

Insider Risk.

Compliance.

Security.

But increasingly, those things overlap. Consider a simple example. An employee uses Copilot or an AI agent.

The AI can access information that the employee already has permission to access.

Some of that information might be:

  • sensitive
  • poorly governed
  • overshared
  • stale
  • incorrectly labelled
  • sitting in an old SharePoint site
  • subject to inappropriate permissions
  • no longer required by the organisation

The AI hasn’t necessarily broken a rule, it may simply be operating within the permissions and controls it has been given. That means the question isn’t only:

β€œIs our AI secure?”

We also need to ask:

β€œIs the data that our AI can reach secure?”

That is where the convergence of DSPM and DSPM for AI becomes particularly interesting.


πŸ‘‰ AI governance is becoming data governance

I’ve written about this quite a bit recently, but I think this Microsoft change reinforces the point. AI governance increasingly starts with the data underneath the AI.

You need to understand:

DATA β†’ IDENTITY β†’ AI β†’ AGENT β†’ ACTION β†’ OUTCOME

What data can be accessed?

Who can access it?

What AI application or agent can process it?

What can that agent do?

What actions can it take?

And ultimately, what happens as a result?

That’s not just an AI governance problem.

That’s data governance.

That’s information governance.

That’s security governance.

And that’s exactly why I think bringing these capabilities together makes sense.


πŸ‘‰ Don’t wait until December

If you’re currently using DSPM classic or DSPM for AI classic, I wouldn’t wait for the retirement window to start thinking about this.

Microsoft’s message is clear: organisations using the classic experiences need to transition their remaining workflows to the current DSPM experience.

I’d approach this as a small governance exercise rather than simply a UI migration.

  1. Find out who is using the classic experiences

Identify your:

  • Purview administrators
  • Security administrators
  • Compliance administrators
  • AI governance teams
  • Data governance teams

Then establish whether anyone still relies on the classic experiences. Don’t assume nobody is using them just because the new DSPM experience is already available.


πŸ‘‰ 2. Document the existing workflows

Don’t just document β€œwe use DSPM”. Document what people actually do.

For example:

  • Review AI activity
  • Investigate data risk assessments
  • Review recommendations
  • Monitor Copilot activity
  • Investigate sensitive information
  • Review AI applications
  • Monitor policies
  • Produce management reports
  • Review posture
  • Use Security Copilot promptbooks

Then map those activities to the new DSPM experience. Microsoft has already provided a task-mapping guide specifically for this purpose.


πŸ‘‰ 3. Check permissions

Make sure your administrators can actually access the new experience.

Microsoft currently documents access through roles including the Microsoft Entra Compliance Administrator role, Global Administrator, and Microsoft Purview Compliance Administrator role group, with some activities requiring additional permissions.

Don’t discover a permissions problem on the day the old experience disappears.


πŸ‘‰ 4. Update your operational procedures

If your SOC, compliance team or data governance team has procedures that say:

Purview β†’ DSPM for AI β†’ Reports

those procedures are going to need updating.

The same applies to:

  • Runbooks
  • Training material
  • Internal documentation
  • Help desk guidance
  • Screenshots
  • Governance procedures
  • Operational checklists

Small change? Yes. But these are exactly the things that get forgotten during platform transitions.


πŸ‘‰ And here’s the bigger governance opportunity

I wouldn’t treat this purely as a retirement exercise.

Use it as an opportunity to ask:

What does our data security posture actually look like today?

The new DSPM experience gives organisations a more unified place to look at posture, investigations, reports, recommendations and objectives.

So rather than simply moving an existing process from:

Classic DSPM β†’ New DSPM

ask whether the process itself needs improving.

For example:

DISCOVER

What sensitive data do we have?

UNDERSTAND

Who can access it and where is it exposed?

ASSESS

What risks does that create for Copilot, AI applications and agents?

PROTECT

Which controls do we need?

REMEDIATE

What needs fixing?

MONITOR

Has our posture actually improved?

That is a much more useful governance lifecycle than simply checking whether a dashboard is available.


πŸ‘‰ One more thing: don’t confuse retirement with loss of capability

This is worth making clear.

Microsoft isn’t saying:

β€œDSPM is going away.”

Quite the opposite.

Microsoft is retiring the classic experiences and directing customers towards the newer unified DSPM experience.

Microsoft’s current documentation explicitly says the classic versions have been replaced by the new version, which has broader reach, AI application and agent support, and simplified management.

Microsoft also stated when the new DSPM experience became generally available that it was designed to unify DSPM across scenarios from discovery through protection and remediation, with expanded reporting and third-party visibility.

So the direction of travel is pretty clear.

Less separation. More convergence.


πŸ’‘ The Jim Talks takeaway

If you’re still using DSPM classic or DSPM for AI classic, I’d put a small migration task on your roadmap now, not because December is particularly scary.

Because this is an opportunity to move your organisation towards a more joined-up approach to data security.

Review the classic workflows.

Map them to the new DSPM experience.

Check permissions.

Test the new workflows.

Update your documentation.

Then use the move as an opportunity to reassess your wider data security posture, because ultimately, this isn’t really about a retiring Purview experience. It’s about Microsoft bringing data security, AI security and governance closer together.

And that makes sense.

The more AI applications and agents we deploy, the less useful it becomes to treat AI governance as something that sits beside data governance.

AI governance is becoming data governance.

And Microsoft Purview’s new DSPM experience is starting to reflect that.

Microsoft Learn

Learn about Microsoft Purview Data Security Posture Management (DSPM)

Map tasks from DSPM classic and DSPM for AI classic to the new DSPM

Motivational quote:

β€œTo each there comes in their lifetime a special moment when they are figuratively tapped on the shoulder and offered the chance to do a very special thing, unique to them and fitted to their talents. What a tragedy if that moment finds them unprepared or unqualified for that which could have been their finest hour.” – Sir Winston Churchill

Leave a Reply

Discover more from Welcome to JimTalks

Subscribe now to keep reading and get access to the full archive.

Continue reading