← Back
(Updated) Microsoft Purview: Credential scanning in Data Security Posture Agent
MC1259828 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2026-06-16 18:20:53
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
2026-03-31 00:00:00
Services
Microsoft Purview
Tags
Updated message, New feature, User impact, Admin impact
Master tags
Admin, Security, Compliance
Roadmap IDs
558436

One-line summary

Microsoft Purview Data Security Posture Agent adds credential scanning, using LLMs to detect exposed credentials and risks in selected locations, with a new insights and task board view.

Similar updates

More like this

Details

RoadmapIds
558436
Summary
Microsoft Purview's Data Security Posture Agent will add credential scanning using LLM-powered detection to identify exposed credentials like Entra ID credentials, private keys, and API tokens. Public preview starts late March 2026; general availability begins early October 2026. Admins can review findings via a task board with AI insights and risk scores.
Platforms
Web

Body (from Message Center)

Updated June 16, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction]

We are expanding the Data Security Posture Agent in Microsoft Purview with a new credential scanning capability. This update helps your organization discover exposed credentials and related data security risks across scoped locations. The agent analyzes selected data locations to detect sensitive credential types—including Microsoft Entra user credentials, private keys, and API tokens—and provides risk scores, AI-generated insights, confidence ratings, and credential categories so you can review, confirm, and take action from a single task board view.

This message is associated with Microsoft 365 Roadmap ID 558436.

[When this will happen]

  • Public Preview: Rollout will begin in late March 2026 and complete by early April 2026.
  • General Availability (Worldwide): Rollout will begin in early October 2026 (previously late June) and complete by early November 2026 (previously early July).

[How this affects your organization]

Who is affected

  • Admins who manage Microsoft Purview and use the Data Security Posture Agent within Microsoft 365 tenants

What will happen

  • A new credential scanning capability will be added to the Data Security Posture Agent under the Explore Agent tab (figures 1-5):

1.

user settings

2.

user settings

3.

user settings

4.

user settings

5.

user settings

  • The feature uses LLM-powered credential detection to:

    • Scan selected data locations for exposed credentials.
    • Detect Entra ID credentials, private keys, API tokens, and other credential types.

  • Each finding includes:
    • A risk score
    • AI-generated insights
    • A confidence score
    • A credential category
  • A task board experience will be available to track progress, review findings, and take action.

[What you can do to prepare]

  • Set up the Data Security Posture Agent in Microsoft Purview > Explore Agent using the required admin roles.
  • Communicate this change to your security and compliance teams.

Learn more: 

[Compliance considerations]

QuestionAnswer
Does the change alter how existing customer data is processed, stored, or accessed? The agent discovers exposed credentials and data security risks across scoped locations 
Does the change introduce or significantly modify AI/ML or agent capabilities that interact with or provide access to customer data? Introduces LLM-powered discovery and risk assessment. 
Does the change provide users any new way of interacting with generative AI? Admins receive GenAI-generated summaries and LLM-assisted tasks. 
Does the change include an admin control and can it be controlled through Entra ID group membership? Setup requires admin roles in Microsoft Purview

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": "2026-03-31T00:00:00Z",
    "ai_actions": [
      "Set up Data Security Posture Agent in Purview using required admin roles",
      "Communicate change to security and compliance teams"
    ],
    "ai_master_tags": [
      "Admin",
      "Security",
      "Compliance"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Microsoft Purview Data Security Posture Agent adds credential scanning, using LLMs to detect exposed credentials and risks in selected locations, with a new insights and task board view.",
    "ai_topics": [
      "Purview"
    ],
    "category": "stayInformed",
    "details_map": {
      "Platforms": "Web",
      "RoadmapIds": "558436",
      "Summary": "Microsoft Purview\u0027s Data Security Posture Agent will add credential scanning using LLM-powered detection to identify exposed credentials like Entra ID credentials, private keys, and API tokens. Public preview starts late March 2026; general availability begins early October 2026. Admins can review findings via a task board with AI insights and risk scores."
    },
    "id": "MC1259828",
    "importance": 4,
    "is_major_change": false,
    "last_modified": "2026-06-16T18:20:53Z",
    "ms_products": [
      "Purview"
    ],
    "platforms": "Web",
    "roadmap_ids": [
      "558436"
    ],
    "services": [
      "Microsoft Purview"
    ],
    "severity": "normal",
    "tags": [
      "Updated message",
      "New feature",
      "User impact",
      "Admin impact"
    ],
    "title": "(Updated) Microsoft Purview: Credential scanning in Data Security Posture Agent"
  }
}