Skip to content
Security

Microsoft’s September Security Update Targets Shadow AI at the Network Layer

September 26, 2026
Microsoft’s September Security Update Targets Shadow AI at the Network Layer

Image: microsoft.com

The most consequential item in Microsoft’s September 2026 security update is a piece of plumbing. Microsoft Purview and Microsoft Entra Global Secure Access have reached general availability together, which puts Purview’s classification and policies at the network layer rather than the application layer.

The practical effect is that a sensitive document can be blocked on its way to an unsanctioned AI tool, regardless of which tool it is. Policy that only knows about approved applications cannot see the ones nobody registered; policy at the network layer does not need to know their names.

Elsewhere in the release, Defender and Security Copilot users get an email detonation summary — plain-language explanations of what URL and file sandboxing found, which turns a result an analyst has to interpret into one they can read.

Purview auto-labeling now simulates against up to 20 million items and 50,000 sites through adaptive scopes, and policies can be edited without re-running the simulation, which is the difference between an afternoon and a morning. Purview eDiscovery extends search, hold, review and export into user-owned SharePoint embedded containers, covering Copilot pages, Loop and notebooks. Data Lifecycle Management adds archiving for inactive SharePoint content and Priority Cleanup for permanently deleting stale Teams recordings.

For public-sector customers, Intune Enterprise Application Management, Microsoft Cloud PKI and Intune Remote Help are expanding to Government Community Cloud High, with Enterprise Application Management also reaching the Department of Defense.

Microsoft Ignite runs 17–20 November 2026 in San Francisco and online.

Related AI News

Enjoyed this? Get more in your inbox.

Weekly AI breakthroughs, tool reviews, and practical guides.