Discussion about this post

User's avatar
Marius Laurusevicius's avatar

The retention default is where this bites a company with no security team. Microsoft Purview Audit (Standard) keeps audit records for 180 days, and Microsoft's own documentation notes the default moved from 90 to 180 days on 17 October 2023. One year is Audit (Premium), and ten years needs a separate per-user add-on licence. A firm that switches on Copilot or a Teams agent inherits that window without deciding it. The cheap first step is not a pipeline purchase, it is writing down which tenant logs already exist, how long each is kept, and who can export them.

Amit Spitzer's avatar

The stat I keep coming back to is the 92% of breached orgs lacking proper AI access controls, next to only 40% of all orgs using any at all. That gap means most "AI security" purchases right now are buying visibility into a mess, not a smaller mess. In diligence I ask a vendor pitching AI observability one direct question: if I gave you 90 days of my agent telemetry today, could you tell me which agent touched a specific sensitive record, or does the answer stop at "an agent in this category touched something like it." Most of the market is still selling the second answer at the price of the first.

No posts

Ready for more?