MoorAI vs Microsoft Purview
Last updated
Purview governs your Microsoft 365 data. MoorAI governs what AI agents do. Microsoft Purview labels, classifies, retains and protects data across Microsoft 365, Microsoft 365 Copilot, connected AI apps and onboarded endpoints.[2] MoorAI checks agent actions: the shell commands, file reads and MCP tool calls that Claude Code, Codex, Copilot CLI, Cursor and Gemini CLI make on the device. It runs the same checks inside the AI you build, through the Agent SDK, a localhost sidecar, a model proxy, an MCP gateway and an egress proxy.
Microsoft bundles AI data security into Microsoft 365. The Purview Suite for Microsoft 365 Business Premium is $10.00 per user per month, paid yearly, and the Defender and Purview Suites bundle is $15.00. Both sit on top of Business Premium, with a maximum of 300 seats. Microsoft 365 Copilot customers get 50% off the Purview Suite for the first year, on purchases between 1 December 2025 and 31 December 2026.[1] If you run Microsoft 365 Business Premium, Purview is one add-on away. This page shows what it covers and what it leaves to a tool like MoorAI.
Run both. They cover different ground and overlap in only a few places. MoorAI decides against a 79-threat matrix on the device and by default sends only category · risk · keyed one-way hash (plus the login and hostname, which the console pseudonymises on arrival). The agent is free and open source (MIT); the console is free for up to 200 users.
Three things this page does not state. (1) Enterprise licensing. The prices above are Microsoft’s list prices for small and medium businesses; enterprise plans are not compared. (2) That Purview cannot do something. A “—” mark means Microsoft’s documentation for that area does not describe it. (3) Other Microsoft products, with one exception: Microsoft Entra documents an MCP firewall in preview, covered in the third question below. Every Purview statement comes from Microsoft’s own pages, numbered and listed at the end, read on 9 October 2026.
The core difference is the unit each one governs: a piece of data, or an action an agent is about to take.
.env read, a curl uploading a secret file, an MCP call carrying an API key or an instruction planted in CLAUDE.md is checked before it runs. An enrolled device blocks, masks or asks for a signed justification per policy; an unenrolled one coaches.@moorai/agent-sdk in process, the moorai-serve sidecar for any framework, moorai-model-proxy between the agent and its model API, moorai-mcp-gateway for remote MCP servers, a stdio proxy for local ones, and moorai-egress-proxy for every other connection. Content is checked where the workload runs and is not sent anywhere to be checked.Who covers what
Read it by group. The first two groups are Purview’s ground, the last two are MoorAI’s. Purview marks cite the Microsoft page that documents them; — means that page does not describe it.
Scroll sideways →
| MoorAI | Microsoft Purview | |
|---|---|---|
| Microsoft 365 data and Microsoft’s own AI | ||
| Sensitivity labels and classification for Microsoft 365 files and email | ✗ | ✓[2] |
| SharePoint and OneDrive oversharing assessments before Copilot surfaces the content | ✗ | ✓[4] |
| Microsoft 365 Copilot and Copilot Chat inside Microsoft’s cloud: label-aware access and DLP | ✗outside MoorAI's view | ✓[2] |
| Copilot Studio, Microsoft Foundry and Entra-registered agents | ✗ | ✓[9] |
| Retention, eDiscovery and audit of AI prompts and responses | ✗keeps no prompt content by default | ✓[2] |
| Insider risk and communication compliance over AI interactions | ◐content-free trust scoring and anomaly signals | ✓[2] |
| Assessments for AI regulations | ◐OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO 42001, EU AI Act mapping of content-free records | ✓[2] |
| People using AI on the endpoint and in the browser | ||
| Endpoint DLP for USB, printing, network shares, clipboard and Bluetooth | ✗ | ✓[6] |
| Sensitive data pasted or uploaded into third-party AI sites | ◐Chrome and Edge extension, typed prompts in 8 chat apps, not uploads | ✓[3][7] |
| Discovering AI use across the organization | ◐AI apps, extensions, models and MCP servers on devices that run MoorAI | ✓[3][8] |
| What AI agents do | ||
| Shell commands checked before they run in Claude Code, Codex, Copilot CLI, Cursor and Gemini CLI | ✓pre-tool hook; validated end to end on Claude Code | —[6] |
An agent reading a secret file such as .env |
✓by path and by content, before the read | ◐[6]a restricted-apps list can stop listed apps opening protected files |
| MCP tool calls and results, local stdio and remote servers | ✓ | —[11]not in Purview's docs; Entra documents a remote-only MCP firewall in preview |
| Prompt injection and risky agent actions | ✓refused before the action runs, once enrolled | ◐[2]Risky AI usage template detects prompt injection for insider-risk scoring |
| Linux developer machines | ◐agent hooks; no desktop app | —[6]endpoint DLP lists Windows, macOS and Windows Server |
| The AI you build | ||
| Guardrails in AI apps and agents you build | ✓Agent SDK, sidecar, model proxy, MCP gateway, egress proxy | ✓[10]Purview APIs and Agent Framework middleware |
| The check runs next to the workload, with no prompt sent to a service to decide | ✓ | ✗[10]prompts and responses are passed to Purview |
| Open source | ✓agent MIT; console source-available | ✗ |
Same job, different mechanism
Where both touch the same job, the table describes how rather than scoring.
Scroll sideways →
| MoorAI does it by… | Purview does it by… | |
|---|---|---|
| Keeping sensitive data out of AI chat in the browser | A Chrome and Edge extension that checks typed prompts in ChatGPT, Claude, Microsoft Copilot, Gemini, Perplexity, Le Chat, DeepSeek and Grok before they are sent. It checks typed text, not uploads, and is loaded unpacked, with no store listing. | Endpoint DLP and Edge for Business. Endpoint DLP policies cover pastes and uploads to AI sites in Edge, Chrome and Firefox; Edge for Business applies DLP inline to a list of AI apps.[5][7] Microsoft’s page for other AI apps says managing these interactions requires pay-as-you-go billing.[3] |
| Recording AI activity | Content-free signals. The console receives a category, a risk level and a keyed one-way hash. Content is kept only if an administrator enables a capture tier. | The full interaction, in the tenant. Prompts and responses are captured in the unified audit log and stored in the user’s mailbox, where eDiscovery and retention policies reach them.[2] For third-party AI sites, content capture needs a collection policy.[3] |
| Guarding the AI apps you build | Components next to the workload that decide in process or on loopback: tool calls, model calls, MCP messages and the connections routed through the egress proxy, with nothing sent anywhere to be checked. | Sending prompts and responses to Purview through APIs in Microsoft Graph, Agent Framework middleware or the native Foundry integration, so its DLP, audit and retention policies apply.[10] |
| Rolling out | A per-device agent, pushed with Jamf Pro (macOS) or Microsoft Intune (Windows), plus the hooks in each coding agent. | Policies in the Purview portal, with devices onboarded to Purview and the Purview browser extension for third-party AI sites.[3] |
| Price | The agent is free and open source (MIT). The console is free for up to 200 users; beyond that, contact us. | $10.00 per user per month, paid yearly, for the Purview Suite on top of Microsoft 365 Business Premium, or $15.00 with the Defender Suite; a maximum of 300 seats.[1] |
Where Purview is stronger. Everything about the data itself. It labels and classifies Microsoft 365 content, finds overshared SharePoint sites before Copilot surfaces them,[4] keeps prompts and responses for retention and eDiscovery,[2] and runs DLP on endpoints for USB, printing and network shares.[6] It reaches Microsoft 365 Copilot, Copilot Studio, Foundry, ChatGPT Enterprise and Claude (Enterprise), and third-party AI sites from a list of more than 1,200 domains.[2][8] If you run Microsoft 365 Business Premium, it is one add-on away.
Where MoorAI is stronger. What an agent does, before it does it. The shell command, the file read, the file write, the MCP tool call and its result are checked on the device before they take effect, in five coding agents and in the AI apps you build. Nothing is sent anywhere to be checked, the console receives no content, and the code that guarantees that is MIT.
Run both. Let Purview own the Microsoft 365 data: labels, oversharing, retention, eDiscovery, endpoint DLP and the Copilot rollout. Put MoorAI where agents act: developer machines running Claude Code, Codex, Copilot CLI, Cursor or Gemini CLI, and the services, MCP servers and model calls of the AI you ship. Nothing in either product’s documentation says they conflict on one device. We have not run them together.
What MoorAI does not do here. It does not label or classify Microsoft 365 documents, does not assess or fix SharePoint or OneDrive oversharing, and does not see Microsoft 365 Copilot working inside Microsoft’s cloud. Its browser extension covers copilot.microsoft.com, not Microsoft 365 Copilot Chat. It sees only the devices and workloads where it is installed. MoorAI’s hook fails open if it crashes or times out: it is governance, not a sandbox.
Questions about MoorAI and Microsoft Purview
Does MoorAI replace Microsoft Purview?
No. Purview governs your Microsoft 365 data: sensitivity labels, data loss prevention, retention, eDiscovery, insider risk and oversharing assessments across Microsoft 365, Microsoft 365 Copilot, connected AI apps and onboarded endpoints. MoorAI governs what AI agents do: the shell commands, file reads and MCP tool calls that coding agents make on the device, and the tool calls, model calls and connections of the AI apps you build. They cover different ground, so run both.
Does Purview cover AI apps beyond Microsoft 365 Copilot?
Yes. Microsoft’s documentation lists Copilot experiences and agents, enterprise AI apps such as ChatGPT Enterprise, Anthropic Claude (Enterprise), Microsoft Foundry and Entra-registered apps, and other AI apps detected through browser activity, such as ChatGPT, Google Gemini and DeepSeek. On onboarded Windows devices, endpoint DLP can warn or block a user pasting sensitive information into a third-party AI site, and Edge for Business applies DLP inline to a list of AI apps. Microsoft’s page for other AI apps says managing those interactions requires pay-as-you-go billing.
Does Purview check a coding agent’s shell commands and MCP tool calls?
Microsoft’s Purview documentation for AI apps and endpoint DLP does not describe it. Endpoint DLP audits and restricts what users do with sensitive items, such as uploads, pastes, USB copies and printing, and can stop apps on a restricted-apps list from opening protected files. Microsoft Entra Global Secure Access documents an MCP firewall in preview for remote MCP servers, which needs TLS inspection and an Entra Internet Access license. MoorAI checks each shell command, file read, file write and MCP tool call in Claude Code, Codex, Copilot CLI, Cursor and Gemini CLI before it runs, on the device.
What does MoorAI leave to Purview?
MoorAI does not label or classify Microsoft 365 documents, does not assess or fix SharePoint or OneDrive oversharing, and does not see Microsoft 365 Copilot working inside Microsoft’s cloud. It keeps no prompt content by default, so it is not a retention or eDiscovery system, and it does not do endpoint DLP for USB, print or network shares. Its browser extension checks typed prompts in eight chat apps in Chrome and Edge, not uploads.
What does each cost?
Microsoft lists the Purview Suite for Microsoft 365 Business Premium at $10.00 per user per month, paid yearly, and the Defender and Purview Suites at $15.00, both requiring Business Premium, with a maximum of 300 seats. Microsoft 365 Copilot customers get 50% off the Purview Suite for the first year on purchases between 1 December 2025 and 31 December 2026. MoorAI’s agent is free and open source under MIT. Its console is free for up to 200 users; beyond that, contact us.
Sources
Every Purview statement on this page is from one of these Microsoft pages, read on 9 October 2026. The pricing address ending security-add-on-plans redirects to the first page below.
- Microsoft 365 Security Pricing for Business: advanced security suites (microsoft.com)
- Microsoft Purview data security and compliance protections for Microsoft 365 Copilot and other generative AI apps
- Use Microsoft Purview to manage data security & compliance for other AI apps
- Data Security Posture Management for AI (classic)
- Considerations for deploying DSPM for AI
- Learn about Endpoint data loss prevention
- Learn about Data Loss Prevention for Cloud Apps in Edge for Business
- Supported AI sites by Microsoft Purview for data security and compliance protections
- Use Microsoft Purview to manage data security & compliance for AI agents
- Develop and deploy secure and compliant Microsoft Foundry or custom AI apps
- Configure Global Secure Access MCP firewall to secure Model Context Protocol traffic (Microsoft Entra, not Purview)
Quoted phrases are Microsoft’s. MoorAI statements are from the MoorAI README at v1.9.1 and its capability spec. ◐ = partial: present but narrower than the other column. — = not described in the cited Microsoft documentation, which is not a claim that Purview lacks it. MoorAI marks reflect shipped capability: hook enforcement is validated end to end on Claude Code; Codex, Copilot CLI, Gemini CLI and Cursor block through their own pre-tool hooks and are tested against each vendor’s documented hook payloads, not yet against the live agents. A device that is not enrolled in a console coaches only. The agent runs on macOS and Windows, with the hooks on Linux; the console is source-available under the Elastic License 2.0 and free up to 200 users. Copilot CLI here is GitHub Copilot CLI, a coding agent, not Microsoft 365 Copilot. Microsoft, Microsoft 365, Microsoft Purview, Copilot and Microsoft Entra are trademarks of Microsoft Corporation; this page is independent and is not affiliated with or endorsed by Microsoft. Both products change, so check specifics against current documentation.