Microsoft has quietly launched a Copilot Prompt Gallery inside the Microsoft Purview compliance portal, giving security teams a curated set of natural-language investigations they can run against sensitive data exposure, risky users, and policy gaps. The feature, tied to Data Security Posture Management (DSPM), is listed as generally available since August 2025 under Microsoft 365 Roadmap ID 492618. It marks a deliberate shift: instead of a blank chat box, administrators now get pre-built prompts and multi-step promptbooks that turn Security Copilot into a repeatable investigative tool.

The Prompt Gallery lives inside the Purview DSPM experience and surfaces ready-made prompts organized around real-world investigation categories: alerts and policies, data at risk, potentially risky users, suspicious activity, and sensitive data. Each entry can be clicked to immediately run a Copilot query, eliminating the need to craft a prompt from scratch. More importantly, Microsoft includes promptbooks—chained sequences of up to six prompts that walk an analyst through a structured investigation. The risky-user promptbook, for instance, surfaces user details, sensitive data handling, external sharing, cloud uploads, alert correlations, and prevention suggestions in a guided flow. The sensitive-data-protection promptbook follows a similar arc. This is not a chatbot gimmick; it is workflow scaffolding for compliance operations.

Microsoft’s own documentation confirms the feature is available in Worldwide Standard Multi-Tenant clouds. The awkward roadmap chronology—preview listed after general availability with an October 2025 date—likely reflects metadata peculiarities rather than a rollback. The more reliable signal is the June 25, 2026 roadmap update, which shows active maintenance. For administrators, the practical takeaway is to verify tenant visibility, licensing, permissions, and portal experience immediately.

What it means for security practitioners

For the everyday analyst, the Prompt Gallery solves a real friction point: knowing what to ask. Security Copilot has always promised natural-language interrogation of security data, but without curated starting points, adoption often stalls. The gallery reduces the cognitive load, especially for junior team members who can begin any investigation with a vetted prompt. It also makes investigations more defensible; when an incident later faces an audit, the team can show they followed a standard promptbook rather than ad-hoc queries.

For IT managers and compliance leads, the feature introduces a governance opportunity and a risk. Standardized prompts can enforce consistency—but only if the team validates that Copilot’s outputs align with actual evidence. The prompts cannot magically fix broken permissions, missing sensitivity labels, or poorly tuned DLP policies. In fact, they will expose such gaps faster. Organizations should expect an uncomfortable but productive period where AI summarization shines a bright light on data-hygiene debt.

Power users and developers who rely on PowerShell or KQL should view the gallery as complementary, not a replacement. The prompts work best when underlying signals are already well-configured. Advanced investigations will still require direct query access, but the gallery accelerates the first 20 minutes of any incident—surfacing a clear picture without manual portal pivoting.

How the feature fits into Microsoft’s broader security AI push

Purview has long been the connective tissue for data governance across Microsoft 365, absorbing classification, DLP, Insider Risk Management, and eDiscovery. DSPM added a posture-management lens: continuous identification of oversharing, suspicious movement, and policy weaknesses. Security Copilot became the natural conversational layer on top. The Prompt Gallery is the logical next step—Microsoft is packaging expertise into clickable investigations. This mirrors a larger industry trend toward guided AI interactions in security tools, where the interface of the future relies on constrained, repeatable actions rather than open-ended wonderment.

The timing is not accidental. As Microsoft 365 Copilot, Copilot Chat, Copilot Studio, and agentic workflows proliferate inside enterprises, customers are demanding visibility into what AI itself can access. The Prompt Gallery positions Purview as the control plane for that anxiety: use AI to inspect the conditions under which AI operates. Microsoft’s tech community posts make clear that DSPM for AI is a strategic priority, and the Prompt Gallery is one of several signals that Purview is evolving into an AI-governance hub.

What to do now: A practical checklist

Microsoft 365 administrators should take immediate, practical steps:

  1. Verify availability. Confirm that your tenant is on Worldwide Standard Multi-Tenant and that the Purview DSPM solution is active. The feature may require specific role assignments—Purview Administrator, Compliance Administrator, or Security Administrator with appropriate Copilot permissions.
  2. Check licensing. DSPM and Security Copilot typically depend on Microsoft 365 E5 or equivalent add-on licenses. The Copilot experience may also involve consumption meter costs. Clarify the commercial model with your Microsoft account team before promising universal access.
  3. Configure prerequisites. Ensure that sensitivity labels, classifiers, DLP policies, and Insider Risk Management signals are already feeding Purview. Copilot can only reason over data that exists. Incomplete signals lead to incomplete investigations.
  4. Start with the built-in promptbooks. Run the risky-user and sensitive-data-protection promptbooks on a test group of known users with various access patterns. Compare Copilot’s summaries with raw evidence from Content Explorer, Activity Explorer, and alert logs to calibrate trust.
  5. Define access controls. A prompt that investigates employee activity is itself a governed capability. Limit who can run risky-user and sensitive-data prompts to individuals with a legitimate investigative role. Document the approved use cases.
  6. Build your own promptbooks. As you identify high-value custom prompts (e.g., “show me all external sharing of files with a credit card classifier in the past 7 days”), formalize them into shared promptbooks. Retire noisy prompts. Standardize expected output formats for escalation.
  7. Validate and iterate. Run a pilot for 30 days. Log all Copilot interactions, review outputs weekly, and hold a post-pilot retrospective to decide whether to expand access. Treat the gallery as live training wheels, not a finished autopilot.

What comes next

The Prompt Gallery is an early control surface for AI-mediated compliance operations. Microsoft’s trajectory suggests that prompts will eventually not just investigate but also propose remediation—drafting DLP policy updates, suggesting access changes, or queueing user notifications. The risk is that teams accept AI-generated conclusions too quickly; the remedy is to embed human review into every step. Organizations that succeed with this feature will be those that pair faster AI questions with slower, more deliberate human judgment. The Prompt Gallery is not the destination; it is the first structured step toward a console where asking the right question becomes as important as clicking the right button.