TeamsFoxTeamsFox
TeamsFox
  • Home
  • Product
    • By Feature
      • M365 License Management
      • M365 Governance
      • M365 Storage
      • M365 Security
      • Microsoft Copilot Readiness
      • M365 Green IT
    • By Team
      • For IT
      • For Finance and Procurement
      • For Sustainability
  • Pricing
  • Customers
  • Blog
  • Company
    • About Us
    • Contact Us
  • Try for free

Arrived compass prepare an on as. Reasonable particular on my it in sympathize. Size now easy eat hand how. Unwilling he departure elsewhere dejection at. Heart large seems may purse means few blind.

  • ADDRESS:

    California, TX 70240
  • EMAIL:

    support@validtheme.com
  • PHONE:

    +44-20-7328-4499

Get Subscribed!

The DLP Gap: Why Copilot Cowork’s Security Stack Isn’t Complete at Launch

IT security professional looks ahead thoughtfully, symbolizing the missing DLP control in Copilot Cowork's launch security stack
  • July 27, 2026

Microsoft shipped five governance controls with Copilot Cowork. The one most IT leaders would ask for first isn’t one of them, yet.

At a Glance

Copilot Cowork DLP gap stats: zero DLP controls shipped, 49% cite agentic AI as top security concern, 150,000+ AI agents projected by 2028
At a glance: zero DLP controls at GA, rising security concern over agentic AI, explosive agent growth projected by 2028, and the admin time TeamsFox already saves.

1. What Actually Shipped on 16 June

Copilot Cowork went generally available worldwide on 16 June 2026. At launch, the protected surface included audit log, Data Security Posture Management, eDiscovery, Insider Risk Management, Data Lifecycle Management, and Communication Compliance policies, all running through the Purview controls security teams already use for Microsoft 365 Copilot. That’s a genuinely serious list. It is also, by Microsoft’s own account, incomplete. Data Loss Prevention for Cowork is listed as “coming soon,” not shipped. For a feature that runs multi-step, tool-calling, connector-touching tasks across a tenant, that is not a small gap to leave open at general availability.

2. Why Copilot Cowork DLP Specifically Is the One That Matters

Audit logs tell you what happened after it happened. DSPM tells you where sensitive data sits. Insider Risk Management flags anomalous behaviour. None of those stops a Cowork agent, mid-task, from pulling a sensitive file into a connector it shouldn’t have reached, or surfacing regulated data in an output a user never asked to see. That is precisely the job DLP does, and precisely the control that is not live yet.

Cowork is agentic. It doesn’t wait for a person to open a file and copy a paragraph. It runs tasks across tools and connectors on its own initiative, inside the scope it’s been granted. Nine partner plugins were live at GA (Enosix, Harvey, LSEG, Miro, monday.com, Moody’s, Morningstar, S&P Global Energy, and TeamsMaestro), with eight more announced. Every plugin is a new path data can move through. Without DLP watching that traffic in real time, the organisation is relying on the agent’s own scope discipline and on detection after the fact, not prevention.

Consider what a single Cowork task can touch in practice. A “prepare the quarterly board pack” task might pull financial data from a connector, cross-reference it against a CRM record, draft commentary, and push a file to a shared workspace, all without a human reviewing each intermediate step. Each of those handoffs is a point where sensitive data could land somewhere it shouldn’t. DSPM will eventually tell a security team that data sat there. It won’t stop the agent from putting it there in the first place. That distinction, between detection and prevention, is exactly what DLP exists to close, and exactly what’s missing until Microsoft ships it.

A DLP policy that arrives after general availability is a DLP policy that arrives after the first quarter of production tasks have already run without it.

RISK: Every Cowork task that touches a connector, a file, or a partner plugin between 16 June and whenever DLP ships is running without real-time data loss prevention. For regulated industries (financial services under DORA, healthcare, anything touching personal data under GDPR) this is not a theoretical gap. It’s an active governance decision that the organisation is making right now, whether anyone has framed it that way or not: continue running Cowork tasks in the gap, or hold rollout back until DLP lands. Neither choice is wrong, but making it silently, by default, is the actual risk.

3. This Isn’t Just a Cowork Story, It’s an Identity Story

The DLP gap sits inside a much bigger shift that has already happened this year. Microsoft Entra Agent ID reached general availability in April 2026, giving agents the same identity constructs as human users: unique authentication, adaptive access policies, lifecycle management, and entitlement management through time-bound access packages. That is Microsoft Entra agent ID acknowledges, in the platform itself, that an agent is not a script running under a service account. It’s an identity, and it needs the same governance discipline organisations already apply, or should apply, to human accounts: a named owner, a defined lifecycle, and access that expires when the job is done.

Forrester’s Security Survey 2026 found 49% of security decision-makers name agentic AI as a top concern, and the firm’s guidance is direct: every agent should be treated as a governed identity, with unique credentials, least-privilege access, full logging, and a named owner responsible for its lifecycle. That is not a new governance principle. It is the exact discipline organisations already owe their human license estate, extended to a new identity type that happens to run code instead of typing a password.

Put Entra Agent ID and the Cowork DLP gap side by side, and the picture sharpens. Microsoft has built the identity layer an agent needs to be governed properly: sponsors, owners, time-bound access packages, lifecycle reviews, and months before it finished the data-protection layer that stops a governed identity from misusing its access anyway. Identity governance and data-loss prevention are two different jobs. Shipping one well ahead of the other means organisations can technically know who owns every agent while still having no real-time control over what that agent does with sensitive data mid-task.

4. Gartner’s Warning: One Policy Will Not Cover Every Agent

Gartner has been direct about the failure mode here. Applying uniform governance across every AI agent, regardless of autonomy level or scope, is itself a path to enterprise AI agent failure. Gartner projects the average Fortune 500 enterprise will run over 150,000 AI agents by 2028, up from fewer than 15 in 2025, and has set out six steps for managing that growth before it becomes sprawl: establish governance policy, build a centralised agent inventory, define identity and permissions per agent with a lifecycle model, govern the data those agents can access, monitor behaviour continuously, and build a culture that treats responsible agent use as a shared discipline, not a security-team afterthought.

Read that list again with a TeamsFox customer’s eyes. Centralised inventory. Identity and permissions per unit. Lifecycle management. Data governance. Continuous monitoring. These are the same five problems TeamsFox already solves for Microsoft 365 licenses, permissions, and storage, just applied to a new class of identity that happens to be an agent instead of a person.

It’s worth pausing on why Gartner frames uniform governance as a failure mode rather than a safe default. A finance-approvals agent with write access to a payment system carries a different risk profile to a meeting-notes summariser, yet both are Cowork tasks today, and both consume the same credit meter, run on the same underlying platform, and could easily end up under the same blanket policy if nobody tiers them. Least-privilege access only works if someone has actually classified what each agent can reach before deciding what it’s allowed to do. That classification step is exactly where most organisations are furthest behind, not because it’s technically hard, but because nobody has been assigned to own it.

5. What to Do Before DLP Ships

Waiting is not a strategy, and neither is pausing Cowork indefinitely on the strength of one missing control. Three things are worth doing this quarter, regardless of when Microsoft’s DLP release lands. First, build the agent inventory Gartner recommends before rollout grows past the point where anyone can list every active agent from memory. Second, assign a named owner to every agent with access to sensitive data, the same way a departing employee’s license gets reassigned rather than left active. Third, put continuous monitoring in place now, so the organisation has its own record of what agents touched, rather than relying solely on Microsoft’s audit log to reconstruct it after the fact.

None of this requires waiting for a vendor roadmap. It requires the same governance habits IT teams already know how to run, pointed at a newer, faster-moving identity type. A Copilot readiness assessment is a reasonable place to start mapping where agents already sit today. Organisations that already have strong license and permissions hygiene will find this a smaller lift than they expect. Organisations that don’t will find the DLP gap is the least of three governance problems they’re now facing at once.

Conclusion

Microsoft shipped a genuinely capable security stack alongside Copilot Cowork. It also shipped it with a named, acknowledged hole, and named holes are the ones organisations most often forget to track, precisely because Microsoft has already told everyone it’s coming. “Coming soon” is not a control. It’s a gap with a release date nobody has committed to.

The deeper story here isn’t really about DLP. It’s about what Entra Agent ID, Gartner’s sprawl warnings, and Forrester’s identity guidance all point to together: agents are identities now, not scripts, and they need the same governance rigour organisations already owe their license estate, their permissions model, and their data lifecycle. The organisations that already run that discipline well for humans have a head start. The ones that don’t will be relearning the same lessons, on a faster clock, with an agent population growing toward 150,000 per enterprise by 2028.

The organisations building that governance habit now- inventory, ownership, lifecycle, visibility- before agents are standard infrastructure, will be the ones in control when they are. The ones waiting for Microsoft’s roadmap to catch up will be governing from behind.

Frequently Asked Questions

Does Copilot Cowork have Data Loss Prevention at launch?

No. At general availability on 16 June 2026, Cowork’s security stack includes audit log, DSPM, eDiscovery, Insider Risk Management, Data Lifecycle Management, and Communication Compliance. DLP is listed as “coming soon.”

What is Microsoft Entra Agent ID?

Entra Agent ID, general availability April 2026, extends Microsoft Entra identity and governance capabilities to AI agents, giving each agent unique authentication, lifecycle management, access reviews, and a named owner, the same governance model already applied to human identities.

How many AI agents will enterprises run by 2028?

Gartner projects the average Fortune 500 enterprise will run over 150,000 AI agents by 2028, up from fewer than 15 in 2025.

Does TeamsFox offer AI agent governance today?

Not as a dedicated product. TeamsFox’s existing license, permissions, and lifecycle management capabilities already extend to agent identities, applying the same governance discipline used for human accounts and licenses.

Should we pause our Copilot Cowork rollout until DLP ships?

That’s an organisational risk decision, not a technical one. Regulated industries should weigh it explicitly rather than defaulting into the gap by inaction. Continuous monitoring and clear agent ownership reduce the exposure either way.

Ready to see this in your tenant? Run a free TeamsFox M365 analysis, no contract, no account changes. You will see your licence, storage, and governance exposure within 30 minutes.

About TeamsFox

TeamsFox is a Franco-German Microsoft 365 management and optimisation platform trusted in 20+ countries across Europe, MENA and Asia. TeamsFox customers see an average 30% reduction in license costs, 60% reduction in admin time, and 40% reduction in storage costs. Headquartered in Düsseldorf, Germany, TeamsFox gives IT and finance teams the tenant-wide visibility and control that native Microsoft tools and one-off scripts cannot sustain.

Run Your Free M365 Analysis

Share:

Previus Post
Light, Medium,

Leave a comment

Cancel reply

Categories

  • Copilot Readiness
  • Governance
  • Green IT
  • License Optimization

Recent Posts

  • IT security professional looks ahead thoughtfully, symbolizing the missing DLP control in Copilot Cowork's launch security stack
    27 July, 2026The DLP Gap: Why
  • Frustrated IT manager badges into locked office door, symbolizing Copilot Cowork access suspended after missed billing deadline
    27 July, 2026Light, Medium, Heavy: Budgeting
  • The 10 ways AI agents get hijacked: OWASP agentic risks mapped to Copilot Studio
    13 July, 2026OWASP Top 10 for
  • Copilot seat pricing vs Cowork usage billing: the hidden second meter on M365 costs
    13 July, 2026Copilot Cowork’s Fourth Meter:

Tags

Access Control Access Management Agentic AI governance AI agent governance AI Governance Azure Cool Storage Compliance Management copilot Copilot Cowork Copilot data governance Copilot ROI Copilot Studio governance Data Governance Data management Data Security Entra ID governance Governance Identity security Microsoft 365 Information Protection license management License Optimization M365 compliance audit log Microsoft 365 Microsoft 365 Copilot deployment Microsoft 365 cost reduction Microsoft 365 E7 Microsoft 365 governance Microsoft 365 Governance Microsoft 365 governance visibility Microsoft 365 licence automation Microsoft 365 licence hygiene Microsoft 365 licence optimisation Microsoft 365 Management Microsoft 365 real-time analytics Microsoft 365 storage management Microsoft 365 storage optimization Microsoft Copilot business case Microsoft Copilot readiness NIS2 compliance Risk Management ROT data ROT Data ROT data SharePoint SharePoint storage optimisation SharePoint storage waste

Quick Links

  • Home
  • Customers
  • Blog
  • Pricing
  • About Us
  • Contact Us

How We Help

  • M365 License Management
  • M365 Governance
  • M365 Storage
  • M365 Security
  • Microsoft Copilot Readiness
  • M365 Green IT
Contact Info
ADDRESS Erkrather Str. 401, 40233 Düsseldorf, Germany
ADDRESS 1 Rue Marguerin, 75014 Paris, France
EMAIL contact@teamsfox.com

Copyright 2026 TeamsFox. All Rights Reserved by TeamsFox GmbH

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • EULA