Posted by: kurtsh | March 13, 2026

INFO: Differences in “Purview Data Security Posture Management for AI” – for Microsoft 365 E3/G3 vs E5/G5

If you’ve got Microsoft 365 E3, the good news is that you do have access to “Purview Data Security Posture Management for AI” – the tool that allows IT to monitor the use of all AI solutions, including 3rd parties like Anthropic Claude, Perplexity.ai, Google Gemini, OpenAI ChatGPT, etc., however it is designed to provide foundational functions, and limited capabilities for more advanced functions.

Microsoft 365 G5 provides the FULL compliment of capabilities for “Purview DSPM for AI”. See below for a comparison of what is available in “Purview DSPM for AI”, depending on the Microsoft 365 suite that you own.

DSPM for AI CapabilityMicrosoft 365 E3Microsoft 365 E5
DSPM for AI availability✅ Available (AI Hub / DSPM for AI experience)✅ Available (full experience) [m365admin….sontek.net]
Visibility into Copilot & AI interactions✅ View AI activity and sensitive data signals✅ Same visibility, plus deeper investigation support [learn.microsoft.com]
Insights into sensitive data used in AI prompts✅ Insights based on existing labeling and classification✅ Same insights, enriched with advanced labeling and risk signals [learn.microsoft.com]
Ready‑to‑use AI protection policies (one‑click)✅ Available (uses baseline Purview policies)✅ Available with broader enforcement scope [learn.microsoft.com]
Data risk assessments for AI (oversharing detection)✅ Included (limited by E3 classification & labeling)✅ Included with higher fidelity due to automatic labeling and analytics [learn.microsoft.com]
Sensitivity labeling used by DSPM for AIManual labeling onlyManual + automatic labeling, default labels, container labels [syskit.com]
DLP enforcement for AI promptsExchange, SharePoint, OneDriveAll E3 locations plus Teams and Endpoint DLP (devices, browsers) [learn.microsoft.com], [syskit.com]
Protection for third‑party AI (e.g., ChatGPT via Edge)Limited (no Endpoint DLP)✅ Supported via Endpoint DLP and browser enforcement [learn.microsoft.com]
Adaptive Protection (risk‑based controls for AI use)❌ Not available✅ Available – adjusts controls based on user risk level [learn.microsoft.com]
Activity Explorer for AI investigations❌ Not available✅ Available – detailed AI‑related activity analysis [learn.microsoft.com]
End‑to‑end AI investigation workflowsBasic visibility only✅ Advanced workflows using eDiscovery, Insider Risk, Investigations [linkedin.com]
Overall DSPM for AI maturityFoundational visibility and controlsAdvanced, automated, risk‑driven AI governance [learn.microsoft.com], [linkedin.com]

Categories