A security analyst monitors a large cybersecurity dashboard with threat alerts, protected systems, and global network activity.
Government cloud tenants have been waiting a while for Microsoft Purview's redesigned Data Security Posture Management (DSPM) experience. Microsoft 365 roadmap item 561036 now gives GCC, GCC High and DoD a general availability target of October 2026. The roadmap still lists the item as "In development," for the web, in the General Availability ring.

The date matters because of what else is on the calendar. Microsoft has also scheduled the retirement of the older DSPM consoles for government clouds, and it starts only a few weeks later. That leaves government admins a short window to move.

What Microsoft says is coming​

The roadmap entry calls this a major redesign of Purview DSPM, meant to help organizations tighten data security while they adopt AI. Its main claims:

  • One view of all data. Traditional data stores and AI-driven environments are covered together, so teams don't have to open separate consoles.
  • Workflows organized by goal. Guided workflows turn findings into steps, so teams can rank risks and fix them faster.
  • AI observability and better posture reporting.
  • Security Copilot agents for tasks such as alert triage and policy management.
  • Third-party signals. Coverage now reaches beyond Microsoft data, with third-party signals from partners like BigID, Cyera, OneTrust, and Varonis, giving security teams a single, streamlined view of sensitive data across clouds and platforms.
  • Wider data risk assessments. Microsoft is extending Data Risk Assessments to Fabric and to item-level analysis with new remediation actions like bulk disabling of overshared SharePoint links.

The roadmap text still says "At Ignite." That wording is left over from the original commercial announcement and doesn't describe a new event.

Section summary: This isn't a single feature. It replaces the whole DSPM console, and government clouds are the last to get it.

The government cloud date has already moved​

Roadmap dates are estimates, and this one has slipped at least once. When the government entry first appeared, third-party roadmap trackers recorded Release date July CY2026 Platform Web Cloud Instance GCC, GCC High, DoD Created 2026-04-24. Planet Technologies' GCC High roadmap digest for the week of April 30 also tagged ID 561036 as July CY2026. The current entry says October 2026, about a quarter later.

Commercial tenants got it much earlier. The original worldwide message center notice, as captured by the M365 Admin tracker, gave these dates:

  • Public Preview (Worldwide): Rollout begins early December 2025 and completes by early April 2026.
  • General Availability (Worldwide): Rollout begins early April 2026 and completes by early May 2026.

So government tenants are running roughly five months behind worldwide. That fits the usual pattern for sovereign clouds, which go through extra compliance and accreditation work before features ship.

The deadline that matters: classic DSPM retires soon after​

Message center post MC1481315 says Microsoft will retire the Microsoft Purview DSPM classic and DSPM for AI classic experiences by December 31, 2026, unifying capabilities into a single current DSPM experience.

That retirement covers government clouds too. The schedule is listed as Retirement (Worldwide, GCC, GCC High, and DoD): Beginning in late November 2026 and expected to complete in late December 2026. After that, DSPM classic and DSPM for AI classic experiences will no longer be available after retirement. Organizations must use the current Microsoft Purview DSPM experience for posture management and investigation workflows.

If the new experience arrives in a GCC High tenant late in October, admins could have about a month before the classic console starts disappearing. If the roadmap date slips again, that window gets shorter.

One conflicting date is circulating. An Apps4.pro blog post from earlier this year said the classic versions would retire on September 30, 2026. MC1481315 is the official notice and is much more recent, so its late-November-to-late-December schedule is the one to plan around.

The upgrade itself should be painless. The original worldwide notice said existing policies and configurations remain unchanged, and that for customers already onboarded to DSPM (classic) and DSPM for AI (classic), onboarding steps will automatically carry over. That notice was for worldwide tenants. Government admins should expect the same behavior but confirm it in their own tenant.

Section summary: The October GA date isn't really the deadline. The late-December retirement is.

What the new experience does, according to Microsoft's documentation​

Commercial tenants already have the new DSPM, so Microsoft Learn documents it in detail. That shows what government admins should expect, with the usual caveat that sovereign clouds sometimes ship with gaps.

Data security objectives. The console is now organized around goal cards instead of separate tools. Examples include "Prevent oversharing of sensitive data," "Prevent exfiltration to risky locations," "Discover sensitive data in your organization," and preventing data exposure in Microsoft 365 Copilot interactions. Each objective pulls together the relevant parts of Purview:

  • Information Protection
  • DLP
  • Insider Risk Management
  • eDiscovery

Each one also shows metrics, ranked recommended actions, and one-click policies.

Posture page. Microsoft describes key metrics, the top objectives ranked by risk, a snapshot of data use across the estate, and a 30-day posture trend graph.

AI observability. This is an inventory of AI apps and agents with activity in the last 30 days, including Agent 365 agents. It counts how many are high risk and how many had sensitive interactions.

Activity explorer. An AI activities tab shows visits to generative AI sites, prompts and responses, whether they contained sensitive information, and any DLP rule matches. Some of this depends on configuration, so don't assume every AI app's prompts show up without setup.

Agents work under supervision. According to Microsoft Learn, agents can remove public sharing links, apply DLP policies or revoke permissions under admin guidance. Triage agents filter DLP and Insider Risk alerts. Microsoft stresses that admins review, approve or customize automated actions, and that agent actions are audited.

Partner and multicloud coverage. Microsoft Learn names Google Cloud Platform, Snowflake and Databricks as third-party platforms, alongside the Varonis, Cyera, BigID and OneTrust integrations. Partner integrations need setup. The step that connects Microsoft Sentinel data lake to partner solutions is still listed as preview. Check which of these connectors actually exist in your government cloud before you promise anyone a single view.

The assessment details: Fabric, SharePoint and the limits​

The roadmap's line about Fabric and item-level analysis is backed by specifics in Microsoft's documentation on preventing oversharing with data risk assessments. You'll find them under Microsoft Purview portal > DSPM > Discover > Data risk assessments.

SharePoint default assessment

  • Runs weekly against the top 100 SharePoint sites by usage.
  • The first default assessment takes four days to show results.
  • Custom assessments need at least 48 hours, and their results don't refresh. Run a new assessment to see changes.

Fabric setup (one time)

  • Register an app in Microsoft Entra.
  • Add it to a security group that you specify under Admin API settings in the Fabric admin portal.
  • In Purview, select Set config for Fabric data risk assessments.
  • Enter the authentication values. Microsoft recommends Federated Credentials as the more secure option; Client Secret also works.
  • Select Test connection, then Save. The default assessment starts scanning the top 100 Fabric workspaces by usage, weekly.

Scannable Fabric item types are Dashboard, Report, DataExploration, DataPipeline, KQLQuerySet, Lakehouse, Notebook, SQLAnalyticsEndpoint and Warehouse.

Item-level scanning has limits

ConstraintDocumented limit
ScopeMicrosoft 365 only, currently SharePoint sites
OneDriveNot supported for item-level scanning
Sites per item-level scanMaximum of 10
Items per location200,000 (counts may be off above 100,000)
PrerequisiteRegistered Entra app plus one-time authentication
Export formatsExcel, CSV, JSON, TSV

For items flagged as potentially overshared, the documented actions are:

  • Resolve
  • Apply a sensitivity label
  • Notify the site owner (the email can't be customized)
  • Remove the sharing link

Microsoft says link removal should be used sparingly because it can cut off legitimate access.

The roadmap promises bulk disabling of overshared links, but the current Learn documentation describes link removal only per item. Don't assume the bulk action exists in your tenant until you see it.

What government admins should do now​

  • Check permissions. You need the Entra Compliance Administrator role or the Purview Compliance Administrator role group. Security Copilot features also require the Data Security Viewer role.
  • Find what still depends on the classic consoles. That includes reports, runbooks and auditor walkthroughs.
  • Prepare the Entra app registrations now. Fabric assessments and item-level scanning both need them, and the change-control process in GCC High is slow.
  • Plan for delays. Microsoft says it can take about a day for tenant data to appear after setup. Add the four-day wait for the first default assessment. A blank dashboard on day one doesn't mean you have no risk.
  • Watch the retirement date. MC1481315's checklist says to confirm access via Microsoft Purview portal > Solutions > DSPM and move any remaining classic workflows before retirement.

The bottom line​

The unified DSPM is a clear improvement in design: you start from a security goal instead of hopping between five consoles to answer one question. But GCC, GCC High and DoD admins are getting it late, possibly with only weeks to spare before the classic consoles go. Commercial tenants had months to try it out. Government tenants may have to switch almost as soon as it arrives, so get the prerequisites done now.


Update: GCC, GCC High and DoD rollout pushed to January 2027 (October 9, 2026)​

Microsoft has moved roadmap item 561036 again. The official Microsoft 365 roadmap now lists the redesigned Purview DSPM experience for GCC, GCC High and DoD as general availability in January 2027, replacing the previous October 2026 target.

That creates a more serious timing problem than the earlier delay. Microsoft’s retirement plan for DSPM classic and DSPM for AI classic was still scheduled to begin in late November 2026 and complete by late December 2026. Unless Microsoft also changes that schedule, government tenants could face a gap in which the classic experiences are retired before the replacement reaches their cloud.

Government administrators should treat the current retirement timeline as needing urgent clarification from Microsoft. In particular, verify whether classic-console access will be extended for affected sovereign-cloud tenants, whether the January date is a broad target or staged rollout, and whether any current DSPM functionality remains available during the transition.

 

References

  1. Microsoft Purview: DSPM – New Microsoft Purview Data Security Posture Management Experience Microsoft AI at Work Roadmap 2026-10-08T23:04:12.038515Z
  2. Learn about Microsoft Purview Data Security Posture Management (DSPM) | Microsoft Learn learn.microsoft.com
  3. MC1481315 - Microsoft Purview: Retirement of Data Security Posture Management (DSPM) classic and DSPM for AI classic experiences mc.merill.net