Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Saturday, 6 June 2026

Microsoft Purview Insider Risk Management: When Data Movement Becomes Behaviour

Not all risk originates outside the organization and that is where data security gets complicated.

Traditional Data Loss Prevention (DLP) struggles to understand intent. An employee downloading large volumes of data could simply be doing their job, preparing to leave the company, or responding to operational pressure in ways no policy ever anticipated. This is where traditional data security breaks down:

DLP tells you what happened: It can stop, warn, or log an event.
Insider Risk Management tells you why: It connects isolated events to determine if they form part of a broader behavioral pattern over time.

What It Is vs. What It Actually Does
The Core Capability
Insider Risk Management in Microsoft Purview detects, analyzes, and prioritizes potentially risky user behavior across an organization. Instead of treating data security as a series of isolated incidents, it ingests signals from across the Microsoft ecosystem and correlates them into risk scenarios that security teams can investigate and act upon.

The Technical Workflow
At a technical level, the platform relies on a four-step pipeline: Signal Aggregation, Behavioral Analysis, Risk Scoring, and Entity Resolution.

Connecting to the Wider Security Ecosystem
Insider Risk Management does not replace existing controls; it interprets them.

PhaseTechnical Mechanism
Signal CollectionGathers indicators across the estate: M365 activity (emails, Teams, SharePoint), DLP alerts, identity signals from Microsoft Entra ID, endpoint activity (USB usage, printing, local file renames), and HR system data (e.g., resignation dates).
Behavioral AnalyticsEstablishes a dynamic baseline of "normal" behavior for a user or role. It identifies deviations, such as unusual data volumes, access to unfamiliar content types, or off-hours activity.
Policy EvaluationPredefined machine learning models (e.g., data exfiltration by departing employees, insider fraud) evaluate combinations of signals. Custom policies can also be built for organization-specific risks.
Scoring & ResolutionAssigns a risk score based on severity and frequency. Entity resolution links identities across disparate systems, stitching alerts into a single chronological narrative timeline for investigators.





  • DLP enforces; Insider Risk interprets. DLP provides initial event signals. Insider Risk aggregates those signals to determine if they are part of a larger malicious or negligent pattern.

  • Downstream Actions: Validated alerts feed directly into Microsoft Sentinel for broader SIEM correlation, trigger Data Security Investigations cases, or inform Data Security Posture Management (DSPM) by highlighting where sensitive data is routinely misused.

The Business Problem It Solves

Security teams are rarely starved for alerts; they are starved for context. High volumes of low-fidelity alerts make it incredibly difficult to distinguish between genuine risk and normal employee friction.

Insider-driven incidents are uniquely damaging because they happen gradually over time. The platform specifically solves for:

  • Departing employees quietly exfiltrating intellectual property.

  • Unintentional oversharing or data mishandling under operational pressure.

  • Privilege abuse and the gradual escalation of unauthorized access.

By shifting focus from isolated rules to holistic risk-based insights, organizations can filter out the noise and focus on what actually matters.

Where It Fits in the Big Picture

Within the Microsoft Purview stack, the data security lifecycle is divided into three distinct pillars:

  • Information Protection: Defines and classifies what data is sensitive.

  • Data Loss Prevention: Restricts and controls how that data moves.

  • Insider Risk Management: Interprets how people interact with that data over time.

This behavioral layer is critical in an AI-driven workplace. As users interact with data via generative AI tools and automated copilots, data movement becomes less direct and intent becomes obscured. Behavioral analytics provide the visibility needed to maintain control across complex, AI-enabled environments.

Strategic Implementation: Getting Started Properly

The biggest mistake organizations make is treating Insider Risk Management as a purely technical deployment. Because it monitors user behavior, it requires cross-functional governance involving Security, Compliance, Legal, and HR.

A Practical Deployment Framework

  • Start Focused: Begin with a limited number of high-value, high-predictability scenarios, such as Data Exfiltration by Departing Employees.

  • Allow Time to Learn: Let the system ingest signals to establish solid behavioral baselines before activating heavy alerting or strict policy thresholds.

  • Tune Aggressively: Refine indicators to minimize false positives and prevent alert fatigue.

  • Ensure Confidentiality: Use built-in pseudonymization features to protect user privacy during the initial stages of an investigation.

Common Pitfalls to Avoid:

  • Relying entirely on out-of-the-box policies without tuning them to your organization's culture.

  • Lacking a clear governance model regarding who owns the alerts and who is authorized to review unmasked user data.

Summary

Most organizations approach insider threats reactively: data is lost, an incident occurs, and a forensic investigation begins after the damage is done.

Microsoft Purview Insider Risk Management shifts the paradigm from reactive forensics to proactive mitigation. It allows organizations to see behavioral patterns before they escalate into data breaches making it an essential capability in a modern, data-centric security strategy.

References and learning

https://learn.microsoft.com/en-us/purview/insider-risk-management
https://learn.microsoft.com/en-us/purview/insider-risk-management-overview
https://learn.microsoft.com/en-us/training/paths/insider-risk-management/


 

Friday, 5 June 2026

Seen but Not Heard: The Age of Data Governance

There’s a phrase I remember being told as a child  “seen but not heard.”

At the time, it meant quiet compliance. Something present, something acknowledged, but not something that shaped the room or influenced what happened next. Strangely, that’s exactly how organizations have treated data governance for years. It has always been there, in the background. Policies exist, frameworks have been written, roles have been defined. If you look hard enough, every organization can point to where governance sits. It is visible. It is documented. It is technically present but it hasn’t truly been heard. It hasn’t influenced how systems are designed, how teams deliver, or how decisions are made in the way it should. Instead, governance has often been something that follows behind delivery as a correction, a control, a necessary inconvenience once the “real work” has already been done. That made sense, once but it doesn’t any longer.



What has changed is not governance itself, it is the world around it. We now operate in organizations where data is not a by-product of activity; it is the thing everything depends on. Strategy is built on it, operations are driven by it, and increasingly, decisions are delegated to systems that rely entirely on it. There is no part of a modern organization that sits outside of data anymore and yet, governance is still too often treated as if it does. That tension is becoming impossible to ignore because when every system depends on data, every issue becomes a governance issue. When numbers do not align between reports, when teams cannot agree on definitions, when ownership is unclear, when trust in outputs begins to erode these are not technical failures in isolation. They are symptoms of something deeper: a lack of embedded governance. You can see this play out repeatedly. Organizations invest in platforms, they modernise architectures, they implement analytics solutions, they adopt AI. Each initiative is presented as progress, and in isolation, it often is. But without governance woven into the fabric of these initiatives, complexity accumulates rather than resolves. Data spreads, inconsistency grows, and the ability to explain or trust what is being produced gradually diminishes. Governance, in those moments, has been seen but it was never allowed to shape the outcome.

The emergence of AI has brought this reality into sharper focus. For years, organizations could tolerate a degree of inconsistency in their data. It caused frustration, inefficiency, and occasionally risk, but it remained manageable. AI does not allow for that tolerance. It amplifies whatever it is given. Good data becomes insight at scale. Poor data becomes risk at scale. There is no neutral outcome. The old saying “garbage in, garbage out” still applies, but it now applies faster, at greater scale, and with far more impact than before. When decisions begin to be influenced or even made by systems fed on ungoverned data, the consequences are no longer contained within individual processes. They affect entire organizations. At that point, governance is no longer a supporting capability. It becomes the condition for whether anything works at all.

This is why the idea that governance can be added later no longer holds. It is not something that can sit alongside delivery or follow it. Governance determines what “good” looks like before anything is built. It defines ownership, establishes meaning, sets expectations, and ensures consistency. Without it, delivery moves forward, but coherence does not and that is the subtle but critical shift that is still being missed. We are not entering a stage where governance becomes more important as a standalone discipline. We are entering a stage where governance becomes inseparable from everything else. It is not another workstream to manage it is part of how every workstream operates. Every technology solution carries assumptions about data. Every integration defines how data flows. Every report reflects decisions about meaning, quality, and trust. Every AI model relies on choices about what data is used and how it is interpreted. In all of these cases, governance is already present. The difference is whether it has been made explicit, intentional, and embedded or whether it remains invisible until it fails.

One of the reasons organizations struggle with this shift is that governance has historically been framed in the wrong way. It has been positioned as a control mechanism, something that restricts or slows progress. It has been documented extensively, but lived infrequently. It has often been assigned to a function rather than understood as a shared organizational responsibility. As a result, it has been treated as optional in practice, even when it is mandatory in principle but when governance is embedded properly, it does not slow organizations down. It removes uncertainty. It allows decisions to be made with confidence because there is clarity around ownership, meaning, and quality. It reduces rework because expectations are clear from the outset. It enables innovation because it provides the guardrails that make experimentation safe. In other words, it makes progress sustainable.

The irony is that most organizations are already feeling the consequences of not doing this, even if they do not describe it in those terms. The questions that surface in meetings about which version of the truth to trust, about who is responsible for a dataset, about whether something can be used safely or compliantly are all governance questions. They just are not recognised as such and because they are not recognised, they are not addressed systematically. Instead, they are solved locally, temporarily, repeatedly. Governance remains visible in theory, but unheard in practice.

We are now at a point where that is no longer viable. If data is the thing that everything depends on, then governance must be the thing that everything contains. Not as an overlay, not as an afterthought, but as a standard, embedded part of how organizations operate. This is the age of data governance — not because governance is new, but because the absence of it is no longer survivable. The organizations that recognise this will not be the ones with the most advanced tools or the largest data estates. They will be the ones that understand their data well enough to trust it, control it, and use it consistently across every part of the business. They will be the ones that stop simply seeing data governance, and finally start listening to what it has been telling them all along.

Thursday, 4 June 2026

The Reality of Compliance in the Age of AI



Compliance used to be retrospective. Policies were written, audits were conducted and evidence was gathered after the fact to demonstrate that controls had been followed. That approach is no longer sufficient. AI has introduced a level of complexity where decisions are made faster, data is reused in ways that are difficult to track, and accountability becomes harder to define. Compliance cannot keep up if it remains a reactive process. It has to become something that is designed into how organizations operate.

The problem beneath the surface

Most organizations still treat compliance as a separate function. A team that interprets regulation. A set of policies that sit alongside operations. A series of controls that are checked periodically but the real challenge is not understanding regulation. It is applying it consistently across processes, systems, and increasingly, AI-driven outcomes.

  • What data can be used for training
  • How decisions are explained
  • Where sensitive information is retained or deleted

These are operational questions, not just compliance ones.

Where Purview comes in

Purview Compliance capabilities focus on managing these challenges in a structured way. Data lifecycle management defines how long data should exist and when it should be removed. Records management strengthens that by applying legal and regulatory context. Compliance Manager provides a framework to track controls and measure progress against requirements. More recently, these capabilities are being used to address AI-related concerns. Understanding data usage, managing retention, and demonstrating control are all foundational to responsible AI. The technology does not replace compliance thinking. It enables it to be applied consistently.

The technical layer that matters

Retention labels and policies are often seen as administrative tools. In reality, they directly influence how data is stored, preserved, or deleted across workloads. Records management introduces immutability and defensibility. Compliance Manager maps controls to regulatory standards, providing visibility into gaps and progress. These are not isolated features. They form a system where compliance is codified into policies that operate at scale.

Why this matters now

Regulation is evolving. The EU AI Act, data protection laws, and industry-specific requirements are all pushing organizations towards greater accountability. At the same time, AI is accelerating how data is used. This creates a tension. Organizations want to move quickly, but also need to demonstrate control. Manual processes cannot bridge that gap. Compliance has to become embedded. It has to operate continuously, not periodically.

The reality

In the age of AI, compliance is no longer about proving that controls exist. It is about proving that they are applied, monitored, and effective in a constantly changing environment. Purview provides the mechanisms to do this, but like governance and security, it depends on how it is used. Policies must reflect real business requirements. Controls must be implemented consistently. Ownership must be clear. Otherwise, compliance remains a reporting exercise rather than a capability.

References and learning

https://learn.microsoft.com/en-us/purview/compliance
https://learn.microsoft.com/en-us/purview/data-lifecycle-management-overview

Microsoft Announces Scout: An Always‑On Autonomous Agent for Work

Microsoft has unveiled Scout, its first Autopilot agent, an always‑on, autonomous digital assistant designed to work across Microsoft 365, proactively coordinating tasks, managing workflows, and keeping work moving even when you’re not in the loop. What makes Scout different is its ability to operate with its own identity, act within organisational policies, and build long‑term context through WorkIQ, learning how you work and what matters most. But beneath the excitement, there’s a deeper story for those of us working in data governance and Responsible AI.

Where Scout Meets Data Governance

Microsoft has been explicit: Scout is built with enterprise‑grade security, policy enforcement, and auditability from day one. Key governance‑aligned capabilities include: Policy‑constrained identity Scout acts only within the permissions and boundaries your organisation sets. Execution containers & OS‑level sandboxing  reducing risk when agents access files, run code, or interact with networks. Continuous policy conformance checks every action is validated against organisational guidelines, producing an audit trail. This is a significant shift: AI agents are no longer “black boxes” running in user sessions, they’re governed, monitored, and contained as first‑class enterprise actors.

Responsible AI: Built Into the Foundation

Microsoft has also published Responsible AI documentation for Scout, reinforcing that it is part of a broader commitment to safe, transparent, and accountable AI systems. 

Highlights include:
  • Responsible AI FAQs explaining how Scout works, what data it accesses, and how system owners can shape behaviour.  
  • Tiered permission systems for file access, shell commands, and browser automation.  
  • Human‑in‑the‑loop expectations and environmental considerations for deployment.  
This aligns Scout with Microsoft’s AI principles of fairness, reliability, safety, privacy, security, inclusiveness, transparency, and accountability.

Why This Matters

For organisations already investing in data governance, AI assurance, and operational Responsible AI, Scout represents a new category of enterprise agent:
  • Autonomous enough to reduce coordination overhead  
  • Governed enough to meet compliance and risk expectations  
  • Context‑aware enough to become a durable part of the digital workforce

This is the moment where AI agents stop being assistants and start becoming accountable digital colleagues  operating within the same governance frameworks as humans and systems.

Wednesday, 3 June 2026

Microsoft Build 2026: The Moment Governance Became the Bottleneck, Not Innovation

If last year’s narrative was about what AI can do, Microsoft Build 2026 marked a noticeable shift: the conversation has moved firmly to what organizations must control.

Across two days of announcements, Microsoft made one thing clear. The next phase of enterprise AI will not be defined by better models or more copilots. It will be defined by whether organizations can operationalise data readiness, governance, and trust at scale.

And that is where the most important announcements sit.

From “AI Features” to “AI Systems That Act”

The headline innovation at Build wasn’t just new models, it was the emergence of autonomous AI agents as first-class enterprise actors.

Microsoft introduced Scout, an always-on AI agent capable of continuously operating across enterprise systems, taking actions rather than waiting for prompts.
This marks a fundamental shift from assistive AI to operational AIsoftware that executes tasks, interacts with systems, and makes decisions within workflows. 

But this also introduces a new governance reality.

When AI moves from generating content to acting on behalf of a business, the questions change:

  • Who is accountable for the action?
  • What data did the agent access?
  • What policies constrained its behaviour?

Microsoft’s answer is not a single tool but an emerging governance architecture for agents.

Governance Is Now Part of the Platform (Not an Add-On)

Across the announcements, governance was not positioned as a compliance afterthought. It was embedded into the core platform.

Three developments stand out.

Agent identity, control, and auditability

Agents are now designed with their own identities, permissions, and audit trails that essentially are becoming governed entities within enterprise systems.
This is a critical shift: governance is no longer about users accessing data, but about non-human actors operating within policy boundaries. 

The rise of the agent control plane

With capabilities such as Agent 365 and broader governance frameworks, Microsoft is building what can only be described as a control layer for AI agents covering access control, visibility, monitoring, and compliance. 

This moves governance from static policies to continuous oversight of autonomous systems.

Built-in safety, evaluation, and testing

The introduction of evaluation frameworks like ASSERT (for testing AI behaviour against policy expectations) signals a shift toward engineering governance into the development lifecycle itself. 

This aligns closely with emerging standards (ISO/IEC 42001, EU AI Act), where governance is expected to be designed, evidenced, tested and not assumed.

Data Governance Quietly Took Centre Stage

While the headlines focused on models and agents, the more important story sits underneath: data is now the limiting factor for AI.

Microsoft’s investment in Fabric including a GPU accelerated data warehouse positioned as an execution layer for AI workloads reflects a deeper truth: organisations don’t lack AI capability, they lack AI-ready data environments. 

This reinforces a theme many of us have been seeing on the ground:

The challenge is no longer can we use AI?
It is can we trust the data, control its usage, and scale it responsibly?

Even outside the keynote announcements, updates across Microsoft Purview continue to evolve around:

  • data quality management,
  • data loss prevention for AI interactions,
  • and governance across expanding AI estates. 

Taken together, this signals a more mature positioning that data governance is not supporting AI, it is enabling it.

A New Stack: AI, Data, and Governance as One System

Perhaps the most important architectural shift is how Microsoft is framing the AI stack.

At Build 2026, governance was explicitly treated as a foundational layer alongside compute, models, and tools. 

This is subtle but significant.

Previously, governance sat outside the stack:

  • something imposed after deployment,
  • owned by risk or compliance functions,
  • often disconnected from engineering.

Now, governance is:

  • integrated into runtime environments,
  • embedded in agent frameworks,
  • and enforced through platform capabilities.

This is a move toward operational governance, not theoretical governance.

What This Means for Businesses

For organizations, these announcements are less about new features and more about a change in expectations.

AI adoption will be constrained by governance maturity

The organizations that succeed will not necessarily be those with the most advanced models but those with:

  • clear data ownership,
  • defined policies for AI usage,
  • and the ability to monitor and control AI behaviour continuously.

Governance becomes a cross-functional discipline

AI governance can no longer sit solely with data teams or compliance functions. It now spans:

  • data governance,
  • security,
  • enterprise architecture,
  • and operational risk.

Tools alone will not solve the problem

While Microsoft is building an increasingly comprehensive governance ecosystem, the platform assumes something critical:

Organisations already understand their data, risks, and policies.

In reality, many do not.

This is where the gap and the opportunity sits.

The Real Announcement wasn’t a Product

If you step back, the most important announcement at Build 2026 wasn’t a model, a Copilot update, or even an agent.

It was a shift in narrative.

Microsoft is signaling that:

  • AI is no longer experimental.
  • Agents will become embedded in everyday business operations.
  • And governance is now the primary barrier to scale.

In other words, we’ve moved from the innovation phase of AI to the industrialisation phase.

And industrialisation always introduces the same question:

How do you scale safely, consistently, and with accountability?

That is not a tooling question. It is a Data and AI governance question.

References

forbes.com  dqindia.co  theneuron.ai  microsoft.github.io  pulse2.com 

forbes.com  learn.microsoft.com  theneuron.ai

Tuesday, 2 June 2026

The Reality of Data Security in M365 (Purview Protection)



Data security has traditionally been viewed as a problem of access. Who can see what. Who can download it. Who can share it. In a world of structured systems and defined boundaries, that was enough. That world no longer exists. Data in M365 is fluid. It moves between emails, Teams chats, SharePoint sites, and endpoints. It is copied, embedded, summarised, and now increasingly, generated by AI. The idea that you can secure it by controlling entry points alone is no longer realistic. Data security has shifted from protecting locations to protecting the data itself.

The problem organizations are actually facing

Most organizations believe they have data security in place because they have policies but when you look closer, those policies are often disconnected from how data is used in practice. Labels are defined but not applied consistently. Data loss prevention rules exist but generate noise rather than insight. Users find workarounds because controls are either too restrictive or not aligned to real workflows. The result is a false sense of security. Controls exist, but coverage is inconsistent. Risks are identified, but not prioritised. Sensitive data continues to move, often without visibility.

What Purview is doing differently

Purview Protection capabilities bring together several controls that are often treated separately. Information Protection classifies and labels data, ideally at creation. Data Loss Prevention applies policies to control how that data moves. Insider Risk adds behavioural context, identifying patterns that indicate potential misuse or compromise. Individually, these are familiar concepts. Together, they form a model where protection is persistent and data-centric. Classification stays with the data. Policies follow it across services. Signals from usage and behaviour start to inform risk in real time. It is not just about blocking actions. It is about understanding how data is used and where risk actually exists.

The technical reality that matters

There is a level of technical depth that is often overlooked. Sensitivity labels are not just tags. They drive encryption, access control, and downstream policy enforcement. DLP is not just rule matching. It combines classification, conditions, and contextual signals. Insider Risk does not operate in isolation. It correlates activity across multiple workloads. These capabilities rely on integration. They rely on consistency. They rely on governance decisions being made upfront. Without that, the tooling becomes fragmented. With it, you start to see a unified security posture that is driven by data, not systems.

Why this matters now

The introduction of AI into everyday tools has changed the risk landscape. Content can be summarised, transformed, and shared at scale. Sensitive information can surface in places it was never intended to be. Traditional controls do not always detect these patterns because they were not designed for this level of fluidity. This is where data-centric security becomes essential. Not as an additional layer, but as the foundation for allowing organizations to use these tools with confidence.

The reality

Security is no longer about stopping access. It is about enabling the right use of data while reducing risk. Purview provides the controls to do this, but only when it is implemented as part of a coherent approach. Labels, policies, and signals must align. Business context must inform technical controls. Otherwise, organizations end up with visibility but no clarity, and policies but no control.

References and learning

https://learn.microsoft.com/en-us/purview/information-protection
https://learn.microsoft.com/en-us/training/paths/implement-data-loss-prevention/

An holistic view of how Microsoft Purview Connects to other tools in Microsoft Purview.



Monday, 1 June 2026

The Reality of Data Governance in 2026 (Purview Governance)

There is still a belief that data governance is something you implement. A programme. A tool. A project that runs for twelve months, delivers a catalogue, assigns a few owners, and quietly dissolves once the funding runs out. In 2026, that belief is not just outdated. It is actively holding organizations back. Data governance has become something else entirely. It is no longer a layer that sits on top of data. It is the condition that determines whether organizations can operate, scale, or even trust what they know. The shift is subtle, but critical. Governance is no longer about control. It is about confidence at scale.


A different kind of problem

Most organizations are not struggling because they do not have governance tools. They are struggling because they do not have governance embedded into the way data is created, moved, and used. The result is predictable. Data exists, but ownership does not. Definitions are documented, but not agreed. Catalogues are populated, but not used and AI initiatives start with optimism and quickly run into questions no one can answer.

  • What does this dataset actually represent
  • Who is accountable for its quality
  • Can we trust it enough to base decisions on it

These are not technical questions. They are governance failures.

Where Purview actually fits

Microsoft Purview, particularly the governance capabilities, is often positioned as a catalogue. A place to discover and classify data. That framing is too narrow. At its core, Purview Governance is about creating visibility, accountability, and context across the data estate. Scanning brings assets into view. Classification starts to describe them. Business glossaries and domains begin to connect them to meaning but the technology alone does not create governance. It exposes the gaps. If there is no ownership model, the catalogue becomes a list. If definitions are not agreed, the glossary becomes a dictionary with multiple interpretations. If governance is not embedded in delivery, the platform reflects fragmentation rather than resolving it. Used properly, Purview forces the right conversations. It highlights where business ownership is missing. It shows where critical data is unmanaged. It provides a structure to align people, process and technology.

Why this matters now

The pressure is not coming from governance programmes. It is coming from AI. Organizations are trying to move faster. They are trying to reuse data, combine it, expose it to models and automation. What they are discovering is that speed without control creates risk, and control without clarity creates friction. This is where governance has to evolve. Not as a retrospective exercise, but as something that is designed into the operating model from the start. Purview becomes valuable at that point, not because it catalogues data, but because it supports a model where governance is continuous, visible, and owned by the business.

The reality

In 2026, organizations that treat governance as optional will struggle to scale anything that depends on data. Those that embed it will not talk about governance as a separate function. It will simply be part of how they manage their products, their processes, and increasingly, their AI. The technology is ready. The frameworks are well understood. The challenge is no longer knowing what to do. It is choosing to do it properly.

References and learning

https://learn.microsoft.com/en-us/purview/data-governance
https://learn.microsoft.com/en-us/training/paths/manage-data-estate-purview/

For all 3 areas, see the full realities of data governance, data security and data compliance.