Microsoft Purview | Data Security Investigations: Investigation templates for common data security scenarios
Microsoft Purview Data Security Investigations now includes pre-configured search templates for common data security scenarios, enabling faster, standardized investigations with minimal inputs. This feature is generally available worldwide, requires no admin action, and helps reduce setup time for security analysts using the solution. What and Why We’re adding search templates to Microsoft Purview Data Security Investigations to provide pre-configured search queries for common data security scenarios such as data exfiltration, compromised mailboxes, personal data exposure, and risky AI interactions. These templates help investigators quickly and consistently scope investigations in just a few clicks instead of manually building queries, reducing setup time and lowering the barrier for less-experienced analysts. Users can select a template, provide minimal inputs (such as a user or site), and begin their investigation. This message is associated with Microsoft 365 Roadmap ID 560326. Rollout Schedule General Availability (Worldwide): Available now Impact on Your Organization Who is affected Security analysts and investigators using Microsoft Purview Data Security Investigations Platforms/Services Microsoft Purview (web) Data Security Investigations solution What will happen Investigators can start a new investigation using prebuilt templates instead of creating search queries from scratch. Templates cover common data security scenarios and require only minimal inputs (for example, user, mailbox, or SharePoint site) to start an investigation. Investigations are automatically scoped and ready to run once inputs are provided. This reduces manual setup time and helps standardize investigation workflows. Existing investigations and custom queries are not affected. The feature will be available by default where Data Security Investigations is enabled. Screenshot – Creating an investigation from a template in Data Security Investigations: View image in new tab Typical workflow: Create a new investigation in Data Security Investigations. Select a template that matches your scenario. Provide the required inputs. Run the query to open a scoped investigation. Action Required/Recommendations No admin action is required. Recommended actions: Inform your security and investigation teams about this capability Encourage teams to use templates to standardize investigation workflows Review internal investigation procedures and update documentation if needed Learn more: Data Security Investigations | Microsoft Purview Learn about Data Security Investigations | Microsoft Purview […]
The post Microsoft Purview | Data Security Investigations: Investigation templates for common data security scenarios appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview | Data Security Investigations: Investigation templates for common data security scenarios
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot
Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...
Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role
Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...
Microsoft 365 Copilot: new guided Copilot onboarding experience
Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....
Microsoft Purview |Unified Classification Management Experience
Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...
Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot
Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...
Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)
Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...
Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering
We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...
Microsoft Teams: Impersonation Protection for Teams meetings
Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...
Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent
Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...