Microsoft Purview 現在可監察第三方 AI 工具(包括 Anthropic Claude),並將現有 DLP 政策應用到 AI prompt、上載內容及回應之中。[2][19] Purview Data Security Investigations 加入 OCR,可識別截圖、掃描文件或圖片內隱藏的敏感文字,補足以往只分析文字檔的盲點。[3][46] DSPM(Data Security Posture Management)為 AI 活動提供集中可視化,監察 Copilot、企業自建 AI、以及第三方 LLM 應用的數據風險。[31][35]

Create a landscape editorial hero image for this Studio Global article: How do Microsoft’s May 21, 2026 security updates expand enterprise AI governance—specifically the extension of Microsoft Purview to monitor. Article summary: Microsoft’s May 21, 2026 updates broaden AI governance in four practical ways: they extend Purview’s controls to more third-party AI activity, improve investigations of non-text data, make DSPM a more operational control. Topic tags: general, general web. Reference image context from search candidates: Reference image 1: visual subject "# Agent 365 May 2026 Update: Microsoft expands Enterprise AI governance. Microsoft continues to advance its vision for enterprise AI management with a major update to Agent 365 in" source context "Agent 365 May 2026 Update :AI Governance และ Security" Reference image 2: visual subject "# Governing AI Shadow IT with the Microsoft
企業導入 AI 的速度愈來愈快,但同時亦帶來新風險——例如敏感資料被輸入 AI、員工使用未受管控的「Shadow AI」工具,以及能自動執行任務的 AI agents。
Microsoft 在 2026 年 5 月 21 日 發布的安全更新,正正是針對這些問題。今次更新主要集中在幾個核心能力:擴展 Microsoft Purview 對第三方 AI 的監察、加入影像 OCR 調查功能、強化 DSPM 的 AI 可視化,以及推出 Windows 365 for Agents 作為 AI 代理的受控運行環境。
整體方向非常清晰:企業 AI 管治不再只是監察 Microsoft 自家的工具,而是要管理整個 AI 生態,包括 prompt、數據流、AI 代理和運行環境。
今次更新其中一個最受關注的改動,是 Microsoft Purview 現在可以監察第三方 AI 應用,包括 Anthropic 的 Claude。
對企業安全團隊來說,這一點非常重要。以往很多 AI 管治工具主要集中在 Microsoft 產品,例如 Microsoft 365 Copilot。但實際情況是,員工往往會同時使用多個 AI 平台。
透過 Purview 的網絡資料安全能力,企業可以:
這代表當員工把資料輸入 AI prompt、上載文件或從 AI 回應取得資料時,系統都可以檢測是否涉及敏感資訊。
換句話說,原本難以管理的「Shadow AI」使用情況,開始可以被納入企業的合規與安全政策之中。
另一個重要更新,是 Purview Data Security Investigations 新增 Optical Character Recognition(OCR)。
傳統資料安全工具大多只會分析文字內容,但現實中不少敏感資料其實是透過圖片形式流出,例如:
有了 OCR 之後,Purview 可以從圖片中抽取文字並進行分析,從而識別當中的敏感資訊。
啟用之後,企業原本的安全政策(例如 DLP 或 Insider Risk)都可以直接應用到圖片內容上,並涵蓋多個 Microsoft 服務,包括:
對事件回應團隊而言,這大大減少了數據外洩調查中的「盲區」。
Microsoft 另一個重點是 Data Security Posture Management(DSPM)。
DSPM 的定位,是讓企業可以在單一平台看到整個數據安全狀態,包括傳統應用、AI 系統以及 AI agents 的風險情況。
在 AI 場景中,DSPM 可以監察:
DSPM for AI 會集中顯示組織內的 AI 活動,例如 prompt 互動、代理行為及潛在資料外洩風險。
此外,它亦可與 Microsoft Security Copilot 整合,讓安全分析員用自然語言查詢數據風險或調查事件,加快分析與回應流程。
隨著 AI agents 開始能自動執行任務,AI 管治的焦點亦從「監察使用」延伸到 控制 AI 在哪裡運行。
Microsoft 為此推出 Windows 365 for Agents,提供專為 AI agents 設計的受控運行環境。
這個環境可以讓企業:
它亦配合 Microsoft 的 Agent 365 控制平面,讓 IT 與安全團隊可以在整個基礎架構中觀察、保護和管理 AI agents。
綜合來看,Microsoft 今次更新其實建立了一個 多層 AI 管治架構:
這顯示企業 AI 安全策略正在轉變。
AI 管治不再只是「哪些應用被使用」,而是要全面監察 prompt、資料流、AI 行為,以及代理運行環境。
Microsoft 今次的更新,正是朝向這種 端到端 AI 管治模式邁進。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Microsoft Purview 現在可監察第三方 AI 工具(包括 Anthropic Claude),並將現有 DLP 政策應用到 AI prompt、上載內容及回應之中。[2][19]
Microsoft Purview 現在可監察第三方 AI 工具(包括 Anthropic Claude),並將現有 DLP 政策應用到 AI prompt、上載內容及回應之中。[2][19] Purview Data Security Investigations 加入 OCR,可識別截圖、掃描文件或圖片內隱藏的敏感文字,補足以往只分析文字檔的盲點。[3][46]
DSPM(Data Security Posture Management)為 AI 活動提供集中可視化,監察 Copilot、企業自建 AI、以及第三方 LLM 應用的數據風險。[31][35]