New “View-only Role Management” role in Microsoft Purview
Microsoft Purview introduces a new View-only Role Management role, providing users read-only visibility into role group membership and assignments in the Purview admin portal.
Microsoft Purview introduces a new View-only Role Management role, providing users read-only visibility into role group membership and assignments in the Purview admin portal.
Retention policies for Teams call logs can now be created, modified, and deleted directly in the Microsoft Purview admin portal. Previously, a Purview compliance administrator had to manage these retention policies with PowerShell.
Microsoft Purview now supports time-limited role group assignments, with expiration dates ranging from one day to two years to reducing the risk of unnecessary long-term privileged access.
Microsoft Purview Data Loss Prevention now supports blocking or allowing external access to sensitive SharePoint and OneDrive for Business files by domain or specific email address, moving from Public Preview to general availability.
Microsoft has published a new promotional offer for the Defender for Cloud Apps standalone license, allowing eligible customers to order a free Microsoft 365 E5 Information Protection and Governance upgrade for up to three years.
Microsoft is rolling out a new Purview role groups page with roles, members, and permissions, making it easier for Compliance administrators to see who has access to what.
Microsoft Forms now supports Purview Sensitivity Labels, enabling authors and co-authors to classify forms and maintain consistent data protection across exported content.
Microsoft is introducing sensitivity label support for video files stored in SharePoint and OneDrive or edited via Clipchamp. The feature is in public preview and disabled by default.
Microsoft is updating how access controls are enforced in Purview Data Explorer and Content Explorer. Administrators should verify that users hold the appropriate role or role group before the change rolls out in May 2026.
Microsoft has started assigning the new Purview workload admin roles in Microsoft Entra, triggering PIM assignment notifications for administrators.
Microsoft has released Extended SharePoint Permissions (ESP) to general availability, keeping SharePoint access controls attached to files even after they leave the library.
Office for the web now supports applying sensitivity labels with user-defined permissions in Word, Excel, and PowerPoint, closing a gap for previously required desktop clients.
Microsoft is enabling Always-on diagnostics for Endpoint DLP by default. This post explains what the feature does, how diagnostic logs are collected, and where to manage the setting.
Microsoft is expanding DLP policy enforcement for Microsoft 365 Copilot to cover Word, Excel, and PowerPoint files regardless of storage location.
Microsoft Purview Data Security Posture Management now supports item-level investigation and remediation for SharePoint and OneDrive files, providing insights into sensitivity label status and sharing link details. Administrators can take direct remediation actions on flagged items, including applying sensitivity labels and removing sharing links.
Microsoft is simplifying access management for Data Security Investigations (DSI) in Purview by automatically adding the DSI Admin and DSI Contributor roles to additional role groups, reducing manual role assignments for teams working across DSPM, IRM, and Microsoft Defender XDR.
Viva Engage communities now support Microsoft Purview sensitivity labels assigned to Microsoft 365 groups and their connected SharePoint sites, bringing consistent privacy and access controls across Viva Engage, Microsoft 365 groups, and SharePoint.
SharePoint admins can now disable site branding for individual site collections via PowerShell. Organizations with a Multi-Geo setup must move theme creation to the primary geo, and branding changes are recorded in Purview Audit Logs.
Microsoft is adding the new Purview RBAC role Purview Agent Deployment, also added to several built-in role groups. Together with the existing Purview Agent roles, organizations can now enforce a clear separation of duties across agent administration, analysis, and deployment.
Admin activities related to Copilot agent management are now recorded in Purview Audit Logs, improving visibility for security and compliance teams. Current logging is limited to Copilot Studio agents only.