Chapter 1 of 6
Session scope#
What we will do#
Objective. Configure one scoped Microsoft Purview DLP policy for an approved nonproduction Agent Registry agent. After the policy is enabled and propagated, install it for the named test group. The agent can originate in Microsoft Foundry, Copilot Studio, or Agent Builder. Confirm that the included member can use the agent, the excluded user cannot, and the payload-free audit query returns current activity for the recorded agent instance.
Why it matters#
Problem. Agent Registry makes an agent discoverable, and group installation gives people access before any data-loss check runs.
Solution. This session gates installation on an enabled, propagated Purview DLP policy, so people get access only after the control is live.
Boundaries#
The scope covers one nonproduction agent, its Agent Registry entry, Entra test group, host product, labelled synthetic item, label, DLP action, and set of locations. Microsoft 365 admin center and Microsoft Purview remain the sources of truth for installation, consent, DLP, labels, audit, simulation, propagation, findings, and the approved change record.
Agent 365 DLP governs the selected agent's Microsoft 365 use, not the source platform's runtime. A Foundry agent's separate Data Security DLP path stays with its named Foundry owners, and a hosted or custom agent's SDK instrumentation stays with its developers; see Decisions and stop conditions for both paths.
Session preparation
Who should join
- Microsoft 365 and Microsoft Agent 365 administrators
- Data owners and Microsoft Purview administrators
- Microsoft Entra identity, source-platform, and audit owners
What you need
- An approved nonproduction Microsoft Foundry, Copilot Studio, or Agent Builder agent appears in Agent Registry with Available status and supports group installation through Microsoft 365 admin center.
- The source-platform owner confirms the agent's publication, named runtime owner, and approved lifecycle path. (Session 04 for a Foundry agent.)
- The delivery owner approves one nonproduction test group, host product, use case, labelled synthetic item, DLP action and locations, and restore route.
- The DLP and label operator has Compliance Data Administrator in the approved Microsoft 365 tenant. The audit operator has View-Only Audit Logs in Purview and Exchange admin center.
- The Microsoft Graph Audit Search application has AuditLogsQuery.Read.All application permission with administrator consent.