Top 5

  1. Purview retention for Copilot Memory (GA) - Copilot memory items live in a hidden Exchange mailbox folder. Now you can apply retention and versioning to those items, which matters for eDiscovery, compliance investigations, and any regulatory requirement that extends to AI-generated context. Start planning your retention policies to include this data class before users accumulate significant memory history.

  2. Data Security Investigations launches from endpoint DLP alerts (Preview) - Instead of pivoting manually between DLP alerts and investigation workflows, analysts can now jump directly from an endpoint DLP alert into a DSI session pre-scoped to the relevant files, users, and time range. GA is September 2026; the preview is live now, so security teams should validate the workflow before it ships broadly.

  3. Organizational Messages now supports hybrid-joined devices (Preview) - This closes a gap that forced many organizations to choose between Organizational Messages and their hybrid estate. If you manage hybrid-joined devices and have been waiting on this, the preview is available now with GA in June 2026.

  4. Purview Data Lifecycle Management: Retention for Copilot Memory (GA) - Inactive memory versions are preserved and versioned in the user’s Exchange mailbox, giving admins visibility into memory changes over time. Compliance and legal teams should be briefed now so they can incorporate Copilot memory into hold and retention scope decisions.

  5. Ask Microsoft Anything: David Weston on Agentic Security - Weston leads frontier security model training, agentic defender systems, and AI-driven vulnerability discovery at Microsoft. If your team is evaluating AI security tooling or thinking through agentic risk posture, the recording is worth your time.

Security & Compliance

  • Reminder: Ask Microsoft Anything with David Weston [GA] - Weston leads Agentic Security at Microsoft, covering frontier security model training, autonomous defender agents, and AI-driven vulnerability discovery. His background spans exploit mitigation, APT research, and security engineering for Windows, Xbox, and Azure OS. Catch the recording if your team is working through agentic AI risk or evaluating AI-assisted defense tooling.

  • Microsoft Purview: Data Security Investigations - analyze files tied to endpoint DLP alerts [Preview] - DSI can now be launched directly from an endpoint DLP alert, automatically scoping the investigation to the files, users, endpoints, and time range that triggered the alert. This cuts the manual pivot between DLP alert triage and file-level investigation. Preview is live now; GA is targeted for September 2026, so run a pilot with your SOC team ahead of that date.

  • Microsoft 365 admin center: Organizational Messages now supports Hybrid-joined Devices [Preview] - Hybrid-joined devices can now receive Organizational Messages, removing the coverage gap that excluded them from targeted communications delivered via the admin center. Preview is available now; GA is June 2026. Organizations with mixed Azure AD join and hybrid-join estates should test targeting scenarios in preview to confirm expected reach before GA.

  • Microsoft Purview: Data Lifecycle Management - Retention for Copilot Memory [GA] - Retention and versioning now apply to Copilot memory items stored in users’ Exchange mailboxes, including saved memories and context inferred from chat history. Inactive memory versions are preserved so admins can track changes while active memory continues to be managed by Copilot. Update your DLM policies and inform legal and compliance stakeholders that Copilot memory is now a retainable data class.

Action Required

No CVEs were included in this week’s data. The items below are the highest-priority actions from this digest for the next 30 days.

Documentation Updates

Identity & Access

Endpoint & Device Management

  • Defender catch-up scan behavior updated in docs - Documentation covering Defender catch-up scan settings has been updated; review if your Intune antivirus policy relies on catch-up scan configuration to confirm your settings match the documented behavior.