Posture Control (DSPM)
Release Upgrade Summary (2025)
This article provides a summary of all new features and enhancements for Posture Control (DSPM). To see scheduled maintenance updates for your cloud, visit the Trust Portal.
The following service updates were deployed to app.zsdpc.net on the following dates.
- Feature Available
Azure AI Foundry and Storage Account Association
AI services such as Azure AI Foundry Hub leverage storage accounts to host the AI training data. DSPM provides visibility of sensitive data that is exposed to Azure AI services and machine learning workspaces on the Data Inventory page. This information allows you to create policies or investigation queries and search for sensitive data exposed to the AI services.
To learn more, see About Data Inventory and Creating a New Investigation.
Data Posture Policies
The following new data posture policies for Azure are available:
- AzureClose
- Azure
Enhancements for Onboarding Azure Accounts
The Azure onboarding process is updated with the following enhancements:
Onboard Management Groups
DSPM now supports the onboarding of Azure management groups and scans the subscriptions within them. This option can be used when there are restrictions for onboarding at the tenant level.
To learn more, see Onboarding a Microsoft Azure Tenant.
Onboard Azure Services
You can now select and onboard a subset of the supported Azure services (storage accounts, databases, etc.). This option allows DSPM to have minimal permissions to monitor and scan the data only in these services.
To learn more, see Onboarding a Microsoft Azure Tenant and Managing Services.
Support for Scanning Unmanaged MSSQL Databases
DSPM provides support for onboarding and scanning unmanaged Microsoft SQL Server (MSSQL) databases hosted on Azure virtual machines. Based on the scan setting configuration, DSPM scans and classifies data in these databases and identifies misconfigurations and posture issues.
The scan results are displayed on the Data Inventory page. You can create custom policies and investigation queries to further optimize the protection.
To learn more, see About Unmanaged Databases and Configuring Scan Settings for Azure Unmanaged Databases.
- Feature Available
Compliance Dashboard
The Compliance dashboard provides an overview of the compliance breaches detected by DSPM for industry-standard data protection regulations and benchmarks such as CIS, NIST, PCI DSS, HIPAA, GDPR, DPDP, CCPA, RBI, ISO 27001, and SOC2. The Compliance dashboard provides insights into the overall compliance status and the total number of policies that failed to comply with each benchmark. You can also view the policy summary and compliance configuration details. The dashboard also provides actionable steps to remediate compliance violations.
To learn more, see About Compliance and Viewing Compliance Details.
Dashboard Enhancements
The dashboard includes the following enhancements:
- A legend is added to provide context to the risk score values displayed on the dashboard.
See image. - The scan statistics is moved to the Data Discovery tab.
See image.
To learn more, see About the Dashboard.
- A legend is added to provide context to the risk score values displayed on the dashboard.
Data Posture Policies
The following new data posture policies are available for cloud service providers:
- AWSClose
- AzureClose
- AWS
Enhancements to Cloud Accounts Onboarding Workflow
The Cloud Accounts onboarding process is updated with the following enhancements:
Deploy Orchestrator and Scanner Instances in Custom Network
DSPM provides support for deploying the orchestrator and scanner instances in your organization's existing network settings.
To learn more, see Onboarding an AWS Organization and Onboarding a Microsoft Azure Tenant.
Azure Diagnostic Logs Storage
You can specify an existing Azure storage account or configure a new Azure storage account to store the diagnostic logs.
To learn more, see Onboarding a Microsoft Azure Tenant.
Investigation and Policy Query Enhancements
The investigation and policy queries are enhanced with the following predicates and operators for improved metadata analysis and enrichment:
Custom Policy and Investigation Queries for AWS DynamoDB
DSPM supports entitlements for AWS DynamoDB and allows you to create custom policies and investigation queries. The predefined policies for DynamoDB are also extended to support entitlements.
To learn more, see Creating an Investigation and Creating Custom Policies.
Security Posture Logging for AWS EC2 Instances
The Logging state is added as a security posture for AWS EC2 instances. You can use the Logging predicate in policy and investigation queries to monitor the logging state of your EC2 instances.
To learn more, see Creating an Investigation, Creating Custom Policies, and Understanding the Security Posture State.
MFA for Local Users
To improve the security of user authentication, DSPM has enabled multi-factor authentication for local users while logging in. After entering the login ID, a verification code is sent to the registered email address, and this code is valid for 10 minutes.
To learn more, see Accessing and Navigating the DSPM Admin Portal.
Scan Settings Enhancements
The scan settings include the following enhancements:
Support for Azure-Managed PostgreSQL Flexible Server
DSPM provides support for scanning the Azure-Managed PostgreSQL Flexible Server. Based on the scan setting configuration, DSPM scans and classifies data in the relevant SQL servers, checks for misconfigurations, posture issues, and runs dedicated predefined policies for Azure PostgreSQL. All findings are displayed on the Data Inventory page. You can create custom policies and investigation queries to further optimize the protection.
To learn more, see Configuring Scan Settings for Azure Database.
Database Scanning Options
You can select the following options while configuring the scan settings for databases:
- Data Sampling Scan: Scans a sample of recent data in the database, providing a faster approach with lower cost.
- Full Scan: Scans all the databases across all onboarded accounts, providing a detailed data scan report.
To learn more, see Configuring Scan Settings for Azure Database and Configuring Scan Settings for AWS Database.