Microsoft Purview – Whats New in July 2026

July’s Purview updates lean heavily into preview territory, and that’s exactly where the interesting stuff lives right now. Three items stand out — all in preview, so treat them as things to test in a lab or pilot tenant, not to roll straight into production. I’ll flag the preview status on each, because it matters.

DLP meets the network layer: Global Secure Access integration (preview)

This is the one I would watch most closely. Purview DLP now integrates with Microsoft Entra Global Secure Access to intercept and inspect text and AI interactions at the network layer. In practice that means you can enforce DLP actions on sensitive data before it leaves for untrusted destinations — browsers, apps, APIs, add-ins, generative AI platforms, social media, collaboration tools — and surface risky behaviour through Insider Risk Management at the same time.

Why this matters: most DLP enforcement has lived inside the app or the endpoint. Pushing inspection down to the network layer closes a gap that shadow AI has been driving straight through. If users paste sensitive content into some random AI tool in the browser, this is the kind of control that can actually catch it.

The caveat, and it is a real one: this is in preview. Network-layer interception touches a lot of traffic, and the blast radius of a misconfiguration is wide. Test it in an isolated environment, understand exactly what it inspects before you enable enforcement, and do not point it at production users until you have seen how it behaves. Preview features can change or break without notice — plan accordingly.

Insider Risk Management: unified alert experience (preview)

IRM is consolidating the Triage Agent and Standard alert dashboards into a single alerts list. You manage both classic and agent-triaged alerts from one place, and you can preview agent summaries plus alert and user details directly on the list page. For anyone who has been bouncing between two dashboards during triage, this is a welcome simplification.

Still in preview, so expect the layout and behaviour to shift before GA. Fine to explore in a test tenant to get your analysts familiar with the flow.

IRM: richer user context during triage (preview)

Two related preview additions here. The unified alert experience now pulls extra user profile signals straight from Microsoft Entra — office location, employee type, department, last working date — so investigators get context without leaving the alert. Alongside that, expanded note capabilities let analysts add and view notes on both alerts and cases, with system-generated notes automatically logged when status, assignment, closure, or escalation changes.

Small on paper, meaningful in practice: knowing someone’s last working date while triaging a data-theft signal is exactly the context that changes how you prioritise. Again — in preview, so validate before you lean on it operationally.

The takeaway

July is a preview-heavy month, and that is a good thing if you like seeing where Purview is heading. The Global Secure Access DLP integration is the standout — network-layer data security is a genuine shift in posture. Just keep the golden rule in mind: preview means pilot, not production.

Source: Microsoft Learn – What is new in Microsoft Purview

Header photo by Philipp Katzenberger on Unsplash