AI Governance and Data Security Show

Ryan Murphy; Nikki Chapple

Formerly All Things M365 Compliance. Same hosts, expanded focus. Welcome to the AI Governance & Data Security Show. This channel helps organisations securely adopt AI, govern their data, and manage generative AI risk in the modern workplace. Hosted by Nikki Chapple, Principal Cloud Architect at CloudWay and Microsoft MVP, and Ryan John Murphy, Data Security Specialist at Microsoft and former Microsoft MVP, the show delivers practical insight grounded in real-world experience. Each episode focuses on challenges such as data oversharing, securing AI applications and agents, managing insider

  1. 2d ago

    EP6 - Governing Copilot with Sensitivity Labels, DLP & Microsoft Purview

    How do you secure Microsoft 365 Copilot without blockingproductivity? In Episode 6 of the AI Governance & Data Security Show, Nikki Chapple and Ryan John Murphy are joined by Johnny Sheehan, Microsoft MVP and AI security specialist, to explore how Microsoft Purview, Sensitivity Labels and Data Loss Prevention (DLP) can help organisations secure Copilot while enabling safe and productive AI adoption. Do you really need to label every file before you can trustMicrosoft 365 Copilot? The answer is more nuanced. In this episode, we explore how Copilot uses permissions andsensitivity labels, why encryption and extract rights matter, where DLP fits into the picture, and how organisations can take a practical, risk-based approach to AI governance without falling into "analysis paralysis". We also discuss Microsoft Purview's evolving capabilities,including Label Groups, SharePoint labelling, DSPM for AI, Adaptive Scopes and Block Content Analysis Service, and how these controls can help organisations build the trusted data foundation needed for Copilot andagent-based AI. In This Episode ✅ How Microsoft 365 Copilot uses permissions and sensitivity labels ✅ Do you really need to label everything before deploying Copilot? ✅ Why encryption settings and extract rights matter ✅ How Sensitivity Labels and DLP work together ✅ Common mistakes when designing sensitivity label taxonomies ✅ How to avoid "analysis paralysis" when preparing for AI ✅ Label Groups vs Sub Labels explained ✅ SharePoint and auto-labelling strategies ✅ Using DSPM for AI to discover and manage AI-related risks ✅ Practical guidance for securing Copilot and agent-based AI ✅ Why AI governance should accelerate adoption, not slow it down Key Takeaway AI governance isn't about blocking users or labellingeverything. It's about implementing the right combination of visibility,governance and evidence to create trusted data that enables secure AI adoption. Guest: Johnny Sheehan 🎙️ Johnny Sheehan Dual Microsoft MVP | Founder & Principal Consultant, SecureAi AI Security Specialist LinkedIn: https://www.linkedin.com/in/johnny-sheehan-68331819/ SecureAi: https://secureai.ie/ Resources Microsoft Purview: Manage data security and compliancefor Microsoft 365 Copilot and Microsoft 365 Copilot Chathttps://learn.microsoft.com/en-us/purview/ai-m365-copilot Microsoft Purview: Data security and complianceprotections for generative AI appshttps://learn.microsoft.com/en-us/purview/ai-microsoft-purview About the AI Governance & Data Security Show The AI Governance & Data Security Show helps organisations securely adopt AI, protect sensitive data, govern information and reduce risk across Microsoft 365. Hosted by: 🎙️ Nikki ChapplePrincipal Cloud Architect | Microsoft MVPLinkedIn: https://www.linkedin.com/in/nikkichapple/ 🎙️ Ryan John MurphyData Security Specialist | MicrosoftLinkedIn: https://www.linkedin.com/in/ryanjmurphym365consultant/ Subscribe for practical discussions about: 🔐 Microsoft Purview🤖 Microsoft 365 Copilot ✅ AI Governance 🛡️Data Security🚨 Insider Risk Management📋Data Loss Prevention🏷️ Information Protection📊 Compliance & Risk Management🤝Agent Governance 👍 If you found this episode useful, like, subscribe and share it with colleagues who are preparing for Microsoft 365 Copilot or agent-based AI. 💬 What approach is your organisation taking to Sensitivity Labels and Copilot? Leave your thoughts or questions in the comments. #MicrosoftPurview #Microsoft365Copilot #AIGovernance#DataSecurity #DLP #SensitivityLabels #DSPM #TrustedData

  2. Aug 12

    EP5 - Purview Referential Architecture Explained

    In this episode of the AI Governance & Data Security Show, hosts Nikki Chapple and Ryan John Murphy are joined by Maxime Bombardier, Principal Product Manager on Microsoft Engineering, to discuss Microsoft Purview Referential Architecture Diagrams and why they matter for real-world data security deployments. Purview is powerful, but many deployments stall because teams understand the individual workloads without seeing how the full system fits together. In this episode, Maxime explains how the referential architecture diagrams were created from field pressure, customer questions, and the need to help teams move from scattered documentation to a shared visual model. Nikki and Ryan bring the practitioner and field perspective, exploring why these diagrams have resonated with customers, partners, MVPs, and security teams. The conversation covers classification, sensitivity labels, endpoint DLP, SharePoint, browser DLP, Insider Risk, and Copilot, with a strong focus on what architects and admins need to understand before deploying at scale. Whether you are responsible for Microsoft Purview, Microsoft 365 Copilot, AI Governance, Data Security, Compliance, Risk Management, or Information Protection, this episode provides practical insights and real-world guidance. In This Episode ✅ Why classification is the foundation for almost everything else in Microsoft Purview ✅ How sensitivity labels act as a control plane, training mechanism, and security layer ✅ Why default labelling and service-side labelling are becoming critical for Copilot readiness ✅ How endpoint DLP testing, policy sync, and JIT are commonly misunderstood ✅ How SharePoint, browser DLP, Insider Risk, and Copilot connect across the data security ecosystem ✅ Why prompt-level protection and label-based Copilot controls behave differently ✅ How referential architecture diagrams help teams train, troubleshoot, and deploy faster ✅ Why visibility, governance, and evidence are essential for trusted data in the AI era Key Takeaway The key message from this episode is that Purview deployment success depends on understanding the system, not just configuring individual features. Classification helps organisations know their data, labels provide a consistent control plane, and DLP, Insider Risk, SharePoint, endpoint, browser, and Copilot controls all build on that foundation. The referential architecture diagrams give teams a practical map for making better design decisions and accelerating secure deployment Guests Maxime Bombardier Principal Product Manager, Microsoft Engineering Resources 🔗 Microsoft Purview ReferentialArchitecture Diagrams | Microsoft Community Hub About the AI Governance & Data Security Show The AI Governance & Data Security Show helps organisations securely adopt AI, protect sensitive data, govern information, and reduce risk across Microsoft 365. Hosted by: 🎙️ Nikki Chapple | Principal Cloud Architect, CloudWay | Microsoft MVP 🎙️ Ryan John Murphy | Data Security Specialist, Microsoft Subscribe for discussions on:🔐 Microsoft Purview 🤖 Microsoft 365 Copilot·        ✅ AI Governance·        🛡️ Data Security 🚨 Insider Risk Management 📋 Data Loss Prevention(DLP) 🏷️ InformationProtection   📊 Compliance & RiskManagement 👍 If you found this episode useful, please like, subscribe and share it with your colleagues. 💬 Have questions or feedback? Leave a comment below.

  3. Jul 22

    EP4- Microsoft Purview DSPM: See Your Data Risks with Anders Olsson

    In this episode of the AI Governance & Data Security Show, hosts Nikki Chapple and Ryan John Murphy are joined by Anders Olsson, Data Security Specialist at Onevinn, to explore Microsoft Purview Data Security Posture Management (DSPM) and how organisations can gain greater visibility into their data risks. As organisations adopt Microsoft 365 Copilot and other AI technologies, understanding where sensitive data exists, who can access it, how it is being used, and where the greatest risks lie has never been more important. Microsoft Purview DSPM brings together insights from Microsoft 365, AI applications, endpoints, user activity, data classification, and security controls to help organisations identify, prioritise, and reduce risk. In this conversation, we discuss how DSPM supports data security, compliance, and AI governance initiatives by providing visibility into oversharing, risky user activity, sensitive data exposure, Shadow AI usage, and information protection effectiveness. We also explore how DSPM works alongside Endpoint DLP, Activity Explorer, Defender for Cloud Apps, sensitivity labels, collection policies, and Microsoft Purview reporting to deliver actionable insights that support better security and governance decisions. Whether you're responsible for Microsoft Purview, Microsoft 365 Copilot, AI Governance, Data Security, Compliance, Risk Management, or Information Protection, this episode provides practical guidance for improving your organisation's data security posture. In This Episode ✅ What Microsoft Purview Data Security Posture Management (DSPM) is ✅ Why DSPM is about more than AI observability ✅ How to identify sensitive data risks across Microsoft 365 ✅ Reducing oversharing and improving data security posture ✅ Why classification, sensitivity labels, and sensitive information types still matter ✅ Improving data discovery through collection policies ✅ Monitoring Shadow AI and third-party AI applications with Endpoint DLP ✅ Using Activity Explorer to investigate risky data activity ✅ Prioritising remediation based on business risk ✅ Enabling better conversations between security teams and business owners Key TakeawayYou cannot protect what you cannot see.Microsoft Purview DSPM helps organisations understand and prioritise data risks by combining signals from sensitive data discovery, user activity, Data Loss Prevention (DLP), Insider Risk Management, AI usage, Endpoint DLP, and security recommendations. The real value comes from using that visibility to identify high-risk data, reduce oversharing, improve classification, engage business stakeholders, and take meaningful action to better protect sensitive information. Guest Anders Olsson - Data Security Specialist, Onevinn 🔗 LinkedIn: https://www.linkedin.com/in/mranders/ Resources 🔗 Learn about Microsoft Purview Data Security Posture Management (DSPM) | Microsoft Learn 🔗 Get started with endpoint data loss prevention | Microsoft Learn About the AI Governance & Data Security Show The AI Governance & Data Security Show helps organisations securely adopt AI, protect sensitive data, govern information, and reduce risk across Microsoft 365. Hosted by: 🎙️ Nikki Chapple Principal Cloud Architect | Microsoft MVP 🔗 LinkedIn: Nikki Chapple | LinkedIn 🎙️ Ryan John Murphy Data Security Specialist | Microsoft 🔗 LinkedIn: Ryan John Murphy | LinkedIn Subscribe for discussions on: 🔐 Microsoft Purview 🤖 Microsoft 365 Copilot ✅ AI Governance 🛡️ Data Security 🚨 Insider Risk Management 📋 Data Loss Prevention (DLP) 🏷️ Information Protection 📊 Compliance & Risk Management 👍 If you found this episode useful, please like, subscribe and share it with your colleagues. 💬 Have questions, experiences, or feedback about Microsoft Purview DSPM? Leave a comment below .#MicrosoftPurview #DSPM #DataSecurity #AIGovernance #Microsoft365 #MicrosoftCopilot #InformationProtection #DataProtection #CyberSecurity #Compliance

    EP4- Microsoft Purview DSPM: See Your Data Risks with Anders Olsson
  4. Jul 14

    Purview Data Security Investigations Deep Dive with Christophe Fiessinger

    Microsoft Purview Data Security Investigations (DSI) is changing the way organisations investigate data security incidents. In this episode of the AI Governance & Data Security Show, Nikki Chapple and Ryan John Murphy are joined by Microsoft Product Manager Christophe Fiessinger to explore Microsoft Purview Data Security Investigations (DSI), a new AI-powered capability designed to help security teams investigate insider risk, data exfiltration, compromised accounts, and sensitive data exposure across Microsoft 365. Christophe explains how DSI complements existing Microsoft Purview capabilities including Insider Risk Management, Data Loss Prevention (DLP), Microsoft Defender, Unified Audit Log, and eDiscovery. The discussion covers both reactive investigations and proactive risk hunting, helping organisations identify and mitigate data security risks before they become incidents. In this episode, we discuss: • What Microsoft Purview Data Security Investigations (DSI) is• How AI-powered investigations differ from traditional content searches• Insider risk and data exfiltration scenarios• Investigating Microsoft 365 data at scale• Unified Audit Log integration• DSI versus eDiscovery• Credential and sensitive data detection• AI-powered semantic analysis and multilingual investigations• Data remediation and purge capabilities• The future roadmap for Data Security Investigations Key Takeaway Traditional investigations often require analysts to manually review large volumes of emails, chats, documents, and files. Data Security Investigations uses AI, embeddings, and large language models to help organisations rapidly identify risk, understand the impact of incidents, and take action across Exchange Online, SharePoint, OneDrive, Teams, and Copilot data. Guest Christophe FiessingerProduct Manager, Microsoft Purview Follow Christophe on LinkedIn:Christophe Fiessinger About the Show The AI Governance & Data Security Show helps organisations securely adopt AI, protect sensitive data, govern information, and reduce risk across Microsoft 365. Hosted by: Nikki Chapple Principal Cloud Architect at CloudWay & Microsoft MVPRyan John Murphy Data Security Specialist at Microsoft Topics include: Microsoft PurviewAI GovernanceData SecurityMicrosoft 365 CopilotInsider Risk ManagementData Loss Prevention (DLP)Information ProtectionCompliance and Risk Management

    Purview Data Security Investigations Deep Dive with Christophe Fiessinger
  5. Jul 8

    Inside Purview DSPM: What's next?

    In this episode of the AI Governance & Data Security Show, Nikki Chapple and Ryan John Murphy sit down with Microsoft Purview leaders Maithili Dandige and Talhah Mir to go behind the scenes of Microsoft Purview Data Security Posture Management (DSPM). The conversation explores how DSPM combines data classification, data loss prevention, insider risk management, and AI-driven insights to help organisations understand and secure their data estate. You'll learn why data classification is becoming the foundation for AI readiness, how Microsoft is using AI to improve classification accuracy, and what upcoming innovations in posture management, triage agents, contextual classification, and personalised security experiences could mean for security and compliance teams. Key topics include: • Microsoft Purview DSPM• AI-powered data classification• Oversharing and exposure risks• Dark data discovery• Trainable classifiers and synthetic data• DLP and Insider Risk Management• Microsoft 365 Copilot readiness• AI governance and responsible AI If you're working with Microsoft Purview, data security, compliance, governance, or AI adoption, this episode offers practical insights into the future of securing data in the AI era. Trusted AI starts with trusted data. Subscribe for more episodes covering Microsoft Purview, AI governance, Microsoft 365 security, compliance, and responsible AI adoption. Links: https://learn.microsoft.com/en-us/purview/data-security-posture-management-learn-aboutMaithili Dandige | LinkedInTalhah Mir | LinkedIn #AIGovernance #MicrosoftPurview #DSPM #DataSecurity #Microsoft365Copilot #InformationProtection #Compliance #CyberSecurity

  6. 09/09/2025

    Purview Data Retention with Susan Lamb

    Title: Purview Data Retention with Susan Lamb | All Things M365 Compliance Description: What happens when data governance meets real-world complexity? In this episode of All Things M365 Compliance, @Nikki and I sit down with Susan Lamb to unpack the considerations and configurations of Microsoft Purview Data Retention. From unstructured data chaos to building a business case for compliance, Susan shares her leadership insights on how organisations can unlock Purview’s full potential, especially when the tech is in place but underutilised. Expect candid reflections, practical use cases, and a deep dive into how retention policies can support blended experiences, data quality, and governance at scale. Topics Covered: Why Purview matters for unstructured data Building a business case for retention Governance challenges in hybrid environments Aligning tech capabilities with real-world needs Lessons from the field: what works, what doesn’t Whether you're a compliance pro, data strategist, or just curious about what Purview can really do, this episode delivers clarity, direction, and a few shared truths. Tune in and reset your understanding of data retention—because good governance starts with knowing what to keep. #MicrosoftPurview #DataRetention #M365Compliance #AllThingsM365Compliance #RyanJohnMurphy #NikkiChapple #InformationGovernance #CompliancePodcast #Microsoft365 #DataGovernance #RetentionPolicies #UnstructuredData #HybridWork #TechLeadership #PodcastUK

About

Formerly All Things M365 Compliance. Same hosts, expanded focus. Welcome to the AI Governance & Data Security Show. This channel helps organisations securely adopt AI, govern their data, and manage generative AI risk in the modern workplace. Hosted by Nikki Chapple, Principal Cloud Architect at CloudWay and Microsoft MVP, and Ryan John Murphy, Data Security Specialist at Microsoft and former Microsoft MVP, the show delivers practical insight grounded in real-world experience. Each episode focuses on challenges such as data oversharing, securing AI applications and agents, managing insider