Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This feature is in preview.
The Microsoft Purview Posture Agent in Microsoft Purview Data Security Posture Management uses natural language prompts to help you find sensitive information across your organization. Follow these steps to deploy the Microsoft Purview Posture Agent in Microsoft Purview Data Security Posture Management.
Before you begin
If you're new to Microsoft Security Copilot Agent in Microsoft Purview, read this article.
SKU/subscriptions and licensing
This agent requires both the standard per seat licensing model and the pay-as-you-go billing model. Your organization must be licensed for:
- Microsoft 365 E5, with security compute units (SCUs) provisioned to use the Microsoft Purview posture agent in Data Security Posture Management.
The agent consumes security compute units (SCUs) as it performs its tasks. You must have SCUs provisioned for the agent to work. The agent consumes SCUs every time it is run based on the complexity of analysis it performs. For more information about SCUs, see Security compute units (SCUs). You can track your SCU consumption in the usage monitoring tool. For more information about onboarding into Microsoft Security Copilot, see Get started with Microsoft Security Copilot.
For information on Security Copilot licensing in E5 see, Learn about Security Copilot in Microsoft 365 E5.
For information on licensing, see
Permissions and Roles
You can enable and deploy the Microsoft Purview Posture Agent in Data Security Posture Management with either an organizational user account or an agent identity.
We recommend that you deploy the agent using an agent identity. The account used to deploy the agent with an agent identity must have the Role Management role. To get started with agent identities, see Governing Agent Identities (preview).
If you enable and deploy the agent with your organizational user account, see Permissions for deploying the Posture Agent.
There are different permissions and roles needed to perform different functions with the agent. For more information, see Permissions in the Microsoft Purview portal, and Roles and role groups in the Microsoft Purview portals.
Permissions for deploying, running and viewing results from the Posture Agent
Use an account that has one role from each group in the table.
| One from Group A | One from Group B | One from Group C | One from Group D |
|---|---|---|---|
| Purview Content Analyst | - Compliance Admin - Security reader - Data Security viewer - Data Security AI viewer - Data Security AI admin |
- Data Classification Content viewer - Data Classification List viewer |
- Security Copilot Contributor - Owner |
Deployment and configuration roadmap
Implementing the Microsoft Purview agents involves several phases:
Infrastructure prerequisites
- Your tenant must be onboarded to Microsoft Security Copilot. For more information on how to onboard, see Get started with Microsoft Security Copilot.
- You must enable Microsoft 365 data sharing in Security Copilot. For more information, see Accessing data from Microsoft 365 services.
- You must enable the Microsoft Purview plug-in in Microsoft Security Copilot. For more information, see Enable the Microsoft Purview source in Microsoft Security Copilot.
Enabling the agent
This procedure is for organizations that haven't enabled the Microsoft Purview Posture Agent for Data Security Posture Management or have removed it and want to enable it again. After you enable the agent, it's available in Microsoft Purview. There can be only one instance of each agent in a tenant.
- Sign in to the Microsoft Purview portal with an account that has the required permissions.
- In the left hand navigation pane, select Agents.
- Select Explore agents.
- Select the agent to enable, and then select Add. A page opens that shows the requirements to enable the agent.
- Select Setup, this opens the Deploy agent global configuration page. You can:
- Choose Create and use agent identity (recommended) or Assign and use my identity.
- Select Start. You see the Agent is now active message when the agent is successfully deployed.
Managing the agent configuration
After the agent is deployed, make minor changes to the agent configuration as needed.
- Sign in to the Microsoft Purview portal with an account that has the required permissions.
- In the left hand navigation pane, select Agents.
- Select Explore agents.
- Select Go to agent for the agent you want to manage. This opens the agent overview page.
- Select the elipses (three dots) on the upper right hand corner of the agent overview page, next to the Edit agent button. From here you can Deactivate agent which makes it inactive, but doesn't uninstall it. If you want to uninstall it, select Remove agent.
- Select Edit agent to update Agent identity under Deployment configuration.
Deactivate agent
- Sign in to the Microsoft Purview portal with an account that has the required permissions.
- In the left hand navigation pane, select Agents.
- Select Explore agents.
- Select View agent for the agent you want to pause. This opens the agent overview page.
- In the upper-right corner of the agent overview page, select the ellipsis (three dots) next to the Edit agent button.
- Select Deactivate agent. Deactivating the agent stops it from functioning. It doesn't remove the agent.
Remove agent
- Sign in to the Microsoft Purview portal with an account that has the required permissions.
- In the left hand navigation pane, select Agents.
- Select Explore agents.
- Select View agent for the agent you want to remove. This opens the agent overview page.
- On the far right upper right hand corner of the agent overview page, select the ellipses (three dots) that are located next to the Edit agent button.
- Select Remove agent. Removing the agent deletes it from Microsoft Purview. To use it again, follow Enabling the agent.
Monitoring SCU usage
- Sign in to the Microsoft Purview portal with an account that has the required permissions.
- In the left hand navigation pane, select Agents.
- Select Explore agents.
- Select View agent for the agent you want to edit. This opens the agent overview page.
- Select the Performance tab.
- Track your SCU consumption in the usage monitoring tool.