Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

Message ID
MC1181769
View in Message Center
Service
Microsoft Purview
Category
Stay Informed
Tags
New featureAdmin impact
Rollout
November 2025December 2025September 2026
Roadmap ID
522096
View in M365 Roadmap
Platform
Web

Summary

Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.

Details

Updated July 17, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction]

To help organizations better protect sensitive files in transit, we're introducing a public preview for extending Microsoft Purview Data Loss Prevention (DLP) policies to the network through integration with Entra Global Secure Access Internet Access. Through this integration, organizations can intercept and inspect file traffic at the network layer and enforce actions based on DLP policy conditions. It helps prevent sensitive files from being shared with untrusted cloud applications through browsers, apps, APIs, add-ins, and more—including generative AI platforms, cloud storage, and content-sharing services—while managing alerts and incidents through Purview and Microsoft Defender.

This message is associated with Roadmap ID 522096.

[When this will happen:]

  • Public preview: Rollout begins mid-November 2025 and completes by mid-December 2025.
  • General availability: Rollout begins September 2026 (previously mid-June) and completes by end of September 2026 (previously mid-July).

[How this affects your organization:]

  • Who is affected: Microsoft 365 tenants with E3 or E5 licenses; Admins managing Microsoft Purview DLP and Entra Global Secure Access.
  • What will happen:
    • A new “Inline Web Traffic” scenario will be available in Purview DLP policy creation.
    • Admins can configure granular policies and rules to detect and protect sensitive files transmitted to over 35,000 unmanaged cloud applications.
    • Policy matches, alerts, and incidents will be managed centrally in Microsoft Purview and Microsoft Defender.
    • The feature will be available by default but requires configuration to activate.

[What you can do to prepare:]

  • Ensure your GSA administrator configures the following in Entra Global Secure Access:
    • Enabled the internet access traffic profile and ensure the correct user assignments apply.
    • Configure TLS inspection and configure a TLS inspection policy.
    • Create a file policy and add a rule that specifies the action "Scan with Purview".
    • Configure a security profile with the above policies and link it to a conditional access policy.
  • Your global admin must activate Purview pay-as-you-go to enable this capability. No charges will apply during public preview.
  • Review your current DLP and network configurations to assess impact.
  • Communicate this change to helpdesk and security teams.
  • Update internal documentation to reflect new policy options.
  • For more details, refer to: Learn about data loss prevention

[Compliance considerations:]

Compliance Area Explanation
Alters how existing customer data is processed Sensitive file traffic is inspected at the network layer before reaching unmanaged cloud apps.
Introduces AI/ML capabilitiesDLP policies may interact with generative AI platforms to prevent data leakage.
Modifies DLP enforcementAdds network-layer enforcement to existing Purview DLP capabilities.
Adds integration to extend Purview DLP controls Integrates with Entra Global Secure Access Internet Access.
Includes admin controlControlled via Purview and Entra admin portals.
Can be controlled through Entra ID group membership Policy scoping can leverage Entra ID groups.

Change History

Show
July 17, 2026 at 6:30 PM Updated
Summary
Previous
Microsoft Purview DLP policies will integrate with Entra Global Secure Access Internet Access to inspect and control sensitive file traffic at the network layer. Public preview starts mid-November 2025, enabling granular policy enforcement across unmanaged cloud apps, with centralized alert management in Purview and Defender.
New
Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.
Last Updated Date
Previous
2025-10-31T00:10:10.607Z
New
2026-07-17T16:15:40.203Z
Tags
Previous
New feature,Admin impact
New
Updated message,New feature,Admin impact
Body Content
Previous
<p><b>[Introduction]</b></p> <p>To help organizations better protect sensitive files in transit, we're introducing a public preview for extending <b>Microsoft Purview Data Loss Prevention (DLP) policies to the network through integration with Entra Global Secure Access Internet Access</b>. Through this integration, organizations can intercept and inspect file traffic at the network layer and enforce actions based on DLP policy conditions. It helps prevent sensitive files from being shared with untrusted cloud applications through browsers, apps, APIs, add-ins, and more—including generative AI platforms, cloud storage, and content-sharing services—while managing alerts and incidents through Purview and Microsoft Defender.</p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?searchterms=522096" target="_blank">522096</a>.</p> <p><b>[When this will happen:]</b></p> <ul> <li><b>Public preview: </b>Rollout begins mid-November 2025 and completes by mid-December 2025.</li> <li><b>General availability: </b>Rollout begins mid-June 2026 and completes by mid-July 2026.</li> </ul> <p><b>[How this affects your organization:]</b></p> <ul> <li><b style="">Who is affected: </b>Microsoft 365 tenants with E3 or E5 licenses; Admins managing Microsoft Purview DLP and Entra Global Secure Access.</li> <li><b style="">What will happen: </b><ul> <li>A new “Inline Web Traffic” scenario will be available in Purview DLP policy creation.</li> <li>Admins can configure granular policies and rules to detect and protect sensitive files transmitted to over 35,000 unmanaged cloud applications.</li> <li>Policy matches, alerts, and incidents will be managed centrally in Microsoft Purview and Microsoft Defender.</li> <li>The feature will be available by default but requires configuration to activate.</li> </ul> </li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Ensure your GSA administrator configures the following in Entra Global Secure Access: <ul> <li>Enabled the internet access traffic profile and ensure the correct user assignments apply.</li> <li>Configure TLS inspection and configure a TLS inspection policy.</li><li>Create a file policy and add a rule that specifies the action "Scan with Purview".</li><li>Configure a security profile with the above policies and link it to a conditional access policy.</li> </ul> </li> <li>Your global admin must activate Purview pay-as-you-go to enable this capability. No charges will apply during public preview.</li> <li>Review your current DLP and network configurations to assess impact.</li> <li>Communicate this change to helpdesk and security teams.</li> <li>Update internal documentation to reflect new policy options.</li> <li>For more details, refer to: <a href="https://learn.microsoft.com/microsoft-365/compliance/data-loss-prevention-policies" target="_blank">Learn about data loss prevention</a></li> </ul><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="4" cellspacing="0"> <tbody><tr> <th>Compliance Area</th> <th>Explanation</th> </tr> <tr> <td>Alters how existing customer data is processed</td> <td>Sensitive file traffic is inspected at the network layer before reaching unmanaged cloud apps.</td> </tr> <tr> <td>Introduces AI/ML capabilities</td><td>DLP policies may interact with generative AI platforms to prevent data leakage.</td> </tr> <tr> <td>Modifies DLP enforcement</td><td>Adds network-layer enforcement to existing Purview DLP capabilities.</td> </tr> <tr> <td>Adds integration to extend Purview DLP controls</td> <td>Integrates with Entra Global Secure Access Internet Access.</td> </tr> <tr> <td>Includes admin control</td><td>Controlled via Purview and Entra admin portals.</td> </tr> <tr> <td>Can be controlled through Entra ID group membership</td> <td>Policy scoping can leverage Entra ID groups.</td> </tr> </tbody></table>
New
<p>Updated July 17, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p> <p>To help organizations better protect sensitive files in transit, we're introducing a public preview for extending <b>Microsoft Purview Data Loss Prevention (DLP) policies to the network through integration with Entra Global Secure Access Internet Access</b>. Through this integration, organizations can intercept and inspect file traffic at the network layer and enforce actions based on DLP policy conditions. It helps prevent sensitive files from being shared with untrusted cloud applications through browsers, apps, APIs, add-ins, and more—including generative AI platforms, cloud storage, and content-sharing services—while managing alerts and incidents through Purview and Microsoft Defender.</p><p>This message is associated with Roadmap ID <a href="https://www.microsoft.com/microsoft-365/roadmap?searchterms=522096" target="_blank">522096</a>.</p> <p><b>[When this will happen:]</b></p> <ul> <li><b>Public preview: </b>Rollout begins mid-November 2025 and completes by mid-December 2025.</li> <li><b>General availability: </b>Rollout begins September 2026 (previously mid-June) and completes by end of September 2026 (previously mid-July).</li> </ul> <p><b>[How this affects your organization:]</b></p> <ul> <li><b style="">Who is affected: </b>Microsoft 365 tenants with E3 or E5 licenses; Admins managing Microsoft Purview DLP and Entra Global Secure Access.</li> <li><b style="">What will happen: </b><ul> <li>A new “Inline Web Traffic” scenario will be available in Purview DLP policy creation.</li> <li>Admins can configure granular policies and rules to detect and protect sensitive files transmitted to over 35,000 unmanaged cloud applications.</li> <li>Policy matches, alerts, and incidents will be managed centrally in Microsoft Purview and Microsoft Defender.</li> <li>The feature will be available by default but requires configuration to activate.</li> </ul> </li> </ul> <p><b>[What you can do to prepare:]</b></p> <ul> <li>Ensure your GSA administrator configures the following in Entra Global Secure Access: <ul> <li>Enabled the internet access traffic profile and ensure the correct user assignments apply.</li> <li>Configure TLS inspection and configure a TLS inspection policy.</li><li>Create a file policy and add a rule that specifies the action "Scan with Purview".</li><li>Configure a security profile with the above policies and link it to a conditional access policy.</li> </ul> </li> <li>Your global admin must activate Purview pay-as-you-go to enable this capability. No charges will apply during public preview.</li> <li>Review your current DLP and network configurations to assess impact.</li> <li>Communicate this change to helpdesk and security teams.</li> <li>Update internal documentation to reflect new policy options.</li> <li>For more details, refer to: <a href="https://learn.microsoft.com/microsoft-365/compliance/data-loss-prevention-policies" target="_blank">Learn about data loss prevention</a></li> </ul><p><b>[Compliance considerations:]</b></p> <table border="1" cellpadding="4" cellspacing="0"> <tbody><tr> <th>Compliance Area</th> <th>Explanation</th> </tr> <tr> <td>Alters how existing customer data is processed</td> <td>Sensitive file traffic is inspected at the network layer before reaching unmanaged cloud apps.</td> </tr> <tr> <td>Introduces AI/ML capabilities</td><td>DLP policies may interact with generative AI platforms to prevent data leakage.</td> </tr> <tr> <td>Modifies DLP enforcement</td><td>Adds network-layer enforcement to existing Purview DLP capabilities.</td> </tr> <tr> <td>Adds integration to extend Purview DLP controls</td> <td>Integrates with Entra Global Secure Access Internet Access.</td> </tr> <tr> <td>Includes admin control</td><td>Controlled via Purview and Entra admin portals.</td> </tr> <tr> <td>Can be controlled through Entra ID group membership</td> <td>Policy scoping can leverage Entra ID groups.</td> </tr> </tbody></table>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.