August’s Purview updates are relatively focused — two areas dominate: DLP expanding beyond Microsoft 365 boundaries into non-Microsoft SaaS applications, and meaningful improvements to how auto-labeling policies behave in simulation mode. Both address real operational pain points that come up regularly in implementation work.
DLP for non-Microsoft connected apps (preview)
This is the standout update this month. You can now create DLP policies that protect sensitive data at rest in non-Microsoft connected applications — specifically Box and Google Workspace. The policies use the existing Microsoft Defender for Cloud Apps connectors and support the same classification engine available for Microsoft 365 locations.
Why this matters: most organisations running Microsoft 365 are not running it exclusively. Box and Google Workspace regularly coexist in enterprise environments, particularly after acquisitions or in businesses that standardised on Google before moving parts of the estate to Microsoft. Until now, Purview DLP stopped at the Microsoft boundary. Extending the same policy engine and sensitive information type definitions to these platforms closes a gap that has been awkward to explain to customers.
This is in preview. The connector dependency on Defender for Cloud Apps means your tenant needs to have those integrations already in place before this is useful — it is not a standalone feature. Validate your connector configuration in a test environment before you scope this to production workloads.
The same preview extends to sensitivity label auto-labeling policies for non-Microsoft connected apps. You can now create auto-labeling policies that protect sensitive data at rest in Box and Google Workspace using the same classification engine. Again, Defender for Cloud Apps connectors are the prerequisite.
Auto-labeling simulation mode: finally works the way it should
Two updates here that address a persistent frustration with auto-labeling policy management.
First, you can now run an auto-labeling policy in simulation mode before enforcement to identify which items it would label without making any changes. The match results and source distribution let you validate whether the policy is ready to enforce — which is exactly what you want before turning something on that will touch potentially thousands of items across SharePoint and OneDrive. This sounds obvious but was previously harder to do cleanly.
Second, a new Insights tab in the policy details panel gives an at-a-glance view of an auto-labeling policy’s performance. The information shown adapts depending on whether the policy is in simulation or enforcement mode. For anyone managing multiple auto-labeling policies across a complex environment, having a single panel that surfaces performance data without drilling into each policy individually is a genuine improvement.
Both features are generally available — not preview — so you can use these in production policy management immediately.
Also in August: role group expiration now available
Mentioned under July’s shared capabilities but worth repeating given how often this comes up in security reviews: Microsoft Purview role group assignments can now be configured with an expiration date. Temporary assignments can run from one day to two years, and access is revoked automatically when the period ends. Most built-in and custom role groups support this, with the exception of eDiscovery Administrator and eDiscovery Manager.
For organisations that regularly grant temporary access during incidents, audits, or project work and then rely on someone remembering to revoke it afterward — this removes that dependency entirely.
Looking ahead
The DLP non-Microsoft connected apps preview is the direction things are heading: Purview as a policy engine that operates across the full SaaS estate rather than just the Microsoft perimeter. The Box and Google Workspace starting point is logical given market prevalence, but the architecture suggests this will expand. Worth watching which connectors get added next.
Source: Microsoft Learn — What’s new in Microsoft Purview
Header photo by FLY:D on Unsplash
