Chapter 6 of 6 · Validation and operations

Microsoft Agent 365 secure rollout and data controls

Governed foundation 4.5 hours in a non-production POC

Chapter 6 of 6

Confirm the result#

Intended path#

After propagation, run the labelled synthetic interaction through the approved path. Block stops the matched interaction. Audit allows it and records the match. Inspect the DLP result, scoped audit activity, and generated-content label behavior in Purview.

Blocked or failure path#

Repeat the interaction with the approved excluded-user alias. Keep the agent, source, label, direction, location, and action unchanged. The policy must not report a match.

Stop if the policy reaches a wider scope, the action differs, the output is treated as protected without the chosen output control, the excluded user finds the agent, the included member cannot find it, or audit activity remains absent after the recorded ingestion allowance.

Delivery-owner checkpoint#

The delivery owner observes the propagation wait, included-user availability, excluded-user denial, intended policy result, non-match, and scoped audit activity. Keep the policy in simulation or disable it if a check fails. Record the result in Purview and the approved change system.

After implementation#

What remainsOwner
DLP policy, simulation and enablement state, findings, and change historyPurview operator and Agent 365 owner
Label, encryption rights, and generated-content controlInformation protection owner
Agent Registry installation and deployment contractMicrosoft 365 administrator
Product-boundary ownership recordData governance owner
Published agent and native runtime controlsSource-platform owner
Payload-free query definition and audit operationAudit owner
Conditional Foundry Data Security rule and processContent integrationFoundry platform owner, Purview operator, and application developer

Restore through the approved Purview and Microsoft 365 change paths:

  1. Return the policy to TestWithNotifications.
  2. Disable it after reviewing dependencies.
  3. Remove the scoped agent installation and group assignment before deleting a policy created for this session.
  4. Remove label rights or source sharing after the data owner confirms that no Agent 365 dependency remains.

Do not delete a reused label, audit records, or source data. For a Foundry agent, use its separate dependency review to change Foundry coverage or billing. The data governance owner reviews coverage-handoff.md quarterly and after an owner or product-boundary change.

Session 05

Microsoft Agent 365 secure rollout and data controls slide deck