Purview Browser Extension

If your organization needs to prevent data leakage when using third-party AI assistants—for example, ensuring that employees do not share internal information with ChatGPT—you need a way to regulate what employees do in their web browsers. Is an internal document uploaded to ChatGPT? Do prompts contain personal data or sensitive information? To determine this, browser activity must be monitored. This is where the Purview Browser Extension comes in to play.

Supported browsers

Purview Browser Extension is a browser extension that integrates directly with Microsoft Purview. The extension is available for Edge, Chrome, and Firefox. Although Edge has some built-in support for Purview, the general recommendation is to deploy the extension across all supported browsers. This also means that employees should not use other browsers such as Brave or Vivaldi. Since these browsers cannot be integrated with Purview, they should be blocked.

What the Purview Browser Extension monitors

Once the browser extension is deployed and a DLP/IRM policy is configured in Purview, the extension can send the following data to Purview:

  • Which AI assistant the employee visited (ChatGPT, Bard, Gemini, Perplexity, etc.)
  • Time of access
  • Username and IP address
  • Which policy was violated
  • Which policy action was taken (block, block with override, warning)

The browser extension does not monitor all user activity, nor does it capture the AI conversations themselves (prompts and responses) from third party AI-assistants. In other words, it does not provide the same level of insight as Microsoft Copilot.

How to deploy the browser extension

For organizations, the recommended deployment method is Intune. Microsoft has documented the steps for deploying the extension to Edge, Chrome, and Firefox.

As an example, let’s deploy the extension for Chrome using Intune:

After a few minutes, Chrome is updated and the Microsoft Purview Extension is installed. As shown, the extension cannot be disabled because it is managed through Intune.

It is also possible to install the extension directly in the browser, as it is available in the Chrome Web Store. This is always a good approach for testing the functionality before rolling it out organization-wide.

Don’t forget the the risk assessments

The browser extension increases the scope of logging and monitoring. Even though it does not log all browser activity, logging is triggered as soon as activity matches a policy. Organizations should therefore conduct relevant risk assessments (risk and vulnerability assessments and/or DPIAs), or update existing ones.