That mismatch is the operational story behind the August 10 roadmap update. Microsoft’s roadmap describes an LLM-driven discovery tool that can interpret a natural-language request, search documents, email, and messages, then assign associated risk based on context rather than relying solely on keywords, sensitive information types, or classifiers. The Message Center notice tied to the same roadmap item said worldwide rollout would run from mid-June through late July 2026 and described the feature as generally available. Yet the Microsoft Learn pages that tell tenants how to activate, license, scope, and use it have not adopted that GA status.
For security teams, this is more than a labeling problem. Preview status affects change-control decisions, support expectations, workload suitability, and whether a result can be used as a discovery lead or as evidence in a formal investigation. Microsoft’s own documentation gives the answer: use the agent for fast, intent-based searches and human review—not as a replacement for eDiscovery, Audit, or Data Security Investigations.
Microsoft’s GA Record and Its Preview Documentation Do Not Match
The Roadmap entry updated August 10 lists both General Availability and Preview release rings, identifies Worldwide Standard Multi-Tenant as the cloud scope, and gives June 2026 as the GA date. A Microsoft 365 Message Center post, published May 21 and updated May 29, likewise said the agent would become generally available in DSPM during a worldwide rollout ending in late July. It also said the transition would not disrupt existing configurations and would require no changes to existing policies.
Microsoft Learn, however, currently says: “This feature is in preview” on the deployment guide for the Microsoft Purview Posture Agent. A separate DSPM considerations page, also currently available from Microsoft Learn, says the Data Security Posture Agent is “currently in preview.” The Data Security Investigations documentation goes further, saying that its Posture Agent uses the same agent as DSPM and that its functionality may change before GA.
Microsoft has not published an explanation for the differing status labels. The most charitable reading is that the surrounding modern DSPM experience completed its rollout while the underlying agent—or parts of its feature set—remains under preview terms. The less charitable but practical reading is that product-status communication has fallen behind rollout messaging. Either way, a tenant should preserve screenshots of the product’s current terms and feature state before approving it for production workflows.
The sensible conclusion is straightforward: the Roadmap’s “Launched” status means the capability is available to eligible tenants; it does not erase Microsoft’s own live preview notices. Until Microsoft updates its deployment guidance to call the agent generally available, risk teams should treat it as a controlled pilot capability.
The Agent Searches Microsoft 365 Content, Not an Undefined “Data Estate”
Microsoft’s description promises discovery across an organization’s “data estate,” a phrase broad enough to suggest cross-cloud coverage. The actual DSPM documentation is narrower and more useful. In its DSPM interface, the agent searches files in SharePoint and OneDrive, messages in Teams, Exchange email, and interactions with Copilot.
That is a significant distinction for organizations that store sensitive data in Azure Blob Storage, AWS, Google Workspace, Salesforce, ServiceNow, file shares, line-of-business databases, or third-party SaaS platforms. The roadmap entry does not say the agent discovers content in those locations, and the DSPM Agent guidance does not list them as supported search locations. Microsoft’s current Data Security Posture Management platform has broader ambitions and integrations, but the Posture Agent should be scoped according to what its own documentation confirms—not according to the broader DSPM brand.
The agent lives under DSPM > Discover > Asset explorer > Agent. Administrators can use Microsoft-provided prompts or build custom prompts, but custom searches require selecting data sources first. Choosing a user or group automatically brings related mailboxes, OneDrive accounts, or SharePoint sites into scope.
This makes the tool potentially useful for questions that conventional classification misses. A prompt could seek files that appear to contain unreleased acquisition plans, customer credentials pasted into support discussions, or finance material prepared for a board meeting. The point is not that the LLM creates a new security control. It provides a way to formulate an investigative intent without first knowing every phrase, classifier, or sensitive-information type that may appear in the content.
The tradeoff is repeatability. Microsoft’s guidance tells users to limit a prompt to a single intent, state the date range, avoid generic terminology, and make every request self-contained. Those are sensible prompt-engineering practices, but they also mean two analysts can obtain different results from slightly different wording. A finding should trigger verification in the underlying item and, where necessary, a formal search or investigation—not immediate incident closure.
Search Limits Make Scope Discipline Mandatory
The roadmap entry does not mention the limits that will determine whether the agent is useful on a large tenant. Microsoft Learn says DSPM searches should be restricted rather than tenant-wide for faster and more efficient processing. If a prompt contains no time period, discovery results default to the preceding seven days.
The DSPM page also says the search supports up to 1 GB of content and does not support metadata-based searches. An administrator can ask for files containing financial information, but not for files containing financial information and shared externally by a particular person in the last week. That second type of question needs metadata-aware tooling rather than an intent-based content search.
The deployment guide uses a different operational limit: in some cases, the agent downloads and scans up to 5 GB or 10,000 items from selected sources, then returns only the top 1,000 matching items. Microsoft has not explained on the public pages how its 1 GB search-content statement relates to the 5 GB or 10,000-item scan ceiling. Administrators should therefore not assume a tenant-wide prompt produces an exhaustive inventory, even when the interface returns a clean-looking risk summary.
This is particularly important for secret scanning. In the companion Data Security Investigations experience, the same agent can be assigned tenant-wide or targeted credential-scanning tasks across SharePoint, OneDrive, Exchange, and Teams. It produces risk and confidence scores, reasoning for each finding, a task-board workflow, downloadable reports, and Kusto Query Language access to the resulting credential findings. Microsoft positions that as an investigation-oriented workflow, but it still labels the shared agent preview.
A result set capped at the top 1,000 items is enough to identify urgent cleanup work. It is not enough to establish that no additional exposure exists. For that, organizations need a defined search scope, a documented time window, baseline classification and DLP coverage, and a follow-up workflow that can support an auditable conclusion.
“No Action Required” Does Not Mean the Agent Is Ready to Run
The May Message Center notice told tenants that no action was required for the rollout. That statement is technically true for the availability of the DSPM experience, but it obscures the implementation work required before the Posture Agent can analyze content.
Microsoft requires Microsoft 365 E5 licensing and Security Compute Units, or SCUs, provisioned for the agent. The agent uses SCUs each time it runs, with consumption varying according to the complexity of the analysis. It also requires both Microsoft Security Copilot onboarding and pay-as-you-go billing. The Roadmap entry does not disclose that continuing usage cost.
Tenants must also enable Microsoft 365 data sharing in Security Copilot and turn on the Microsoft Purview plug-in there. The agent has to be explicitly added and set up in the Purview portal; it is not automatically activated merely because DSPM appears in the tenant. Microsoft recommends using an agent identity for deployment, rather than binding the agent to an administrator’s personal account.
There is also a hard concurrency limit: only two prompts can run at the same time. Security operations teams contemplating routine searches should test queue behavior and SCU consumption before scheduling daily or weekly work. Microsoft supports recurring daily, weekly, and monthly prompts, which could make the agent a useful control for targeted watchlists, but recurring broad searches could become a cost and capacity problem quickly.
Access separation deserves equal attention. A Compliance Administrator, Security Reader, Data Security Viewer, or Data Security AI Admin can run the agent and view its summary, but those roles do not automatically permit viewing the matched content snippet, opening the actual file, or applying a label. Microsoft reserves that deeper access for roles such as Data Classification Content Viewer, Purview Content Analyst, and relevant Data Security Investigations roles.
That is a sound least-privilege design, but it creates an incident-response handoff. The person who sees a high-risk summary may be unable to validate the evidence or remediate the file. Organizations should map those roles and escalation paths before enabling scheduled searches, especially where the results may identify executives, legal material, source code, credentials, or regulated personal data.
Findings Can Start Protection, but They Do Not Prove the Case
The agent can apply existing Purview sensitivity labels directly to discovered files, with a limit of 10 selected files at once. That gives the feature a practical remediation step rather than leaving the analyst with a report alone. Microsoft says label status may take 30 to 60 minutes to update, and auditing must be enabled to view the latest status.
The agent’s risk level is based on how closely matched content aligns with the prompt. Microsoft also warns in its Data Security Investigations documentation that generative AI outputs may be inaccurate or incomplete and should be verified. That warning belongs at the center of any deployment plan: risk scores and LLM reasoning are prioritization signals, not evidence-grade determinations.
The near-term use case is therefore well defined. Use the Posture Agent to turn a vague but urgent concern into a targeted search: a suspected password-spreadsheet problem, sensitive project material in collaboration spaces, or a surge of unlabeled high-risk documents. Validate the results with the appropriate Purview investigation, audit, eDiscovery, DLP, or classification tools; then document the remediation outside the agent’s generated narrative.
Microsoft has made the agent available and has supplied enough detail to pilot it. What remains unresolved on August 11, 2026 is whether tenants can rely on a GA roadmap designation when the product’s own live documentation still says preview. Until that record is reconciled, the prudent deployment is a metered, limited-scope pilot with human validation—not an automated declaration that the organization’s sensitive-data discovery problem has been solved.