Purview enforces AI prompt DLP through the browser.
Aona enforces where the browser ends.
Purview reaches further into third-party AI than most comparisons admit. With Endpoint DLP and Browser Data Security in Microsoft Edge for Business, it inspects text typed or pasted into consumer AI apps such as ChatGPT, Google Gemini, and DeepSeek in real time and blocks the submission before it leaves the browser, plus file uploads, with Chrome covered through the Microsoft Purview extension. The browser is its control point, and that is also where its reach stops. This page sets out what each tool actually enforces, and where Aona adds coverage.
Data governance and DLP for the Microsoft 365 estate (SharePoint, OneDrive, Teams, Exchange).
The Workforce AI Security platform for companies adopting generative AI: enforcement that reaches native desktop AI apps as well as the browser, with layout-preserving redaction, 7-region residency, and published pricing.
Purview genuinely blocks sensitive prompts and file uploads to consumer AI apps through Edge for Business and the Purview extension for Chrome. If your employees only reach AI through a managed browser, that may be enough. Add Aona where the browser is not the whole picture: native desktop AI apps such as ChatGPT, Copilot, and Claude desktop, which browser-based enforcement does not reach; hard blocks with no user override path; and layout-preserving DOCX, XLSX, and PDF redaction that lets the document stay usable instead of being refused. Aona also ships 7-region data residency, published pricing from $9.99 per user per month, and a 30-day self-serve trial that deploys in hours via Intune and Entra, independent of your Microsoft licensing tier. Keep Purview for M365-native governance and labelling. They are complementary layers, not alternatives.
Jump to the decision matrixSOC 2 Type II · 30-day free trial · No credit card · Live in 1 hour
Vendor facts last verified July 2026
When to pick which
Five scenarios. The honest answer for each one.
Your workforce is standardised on Edge for Business and reaches AI only through the browser.
Purview already does this well. Endpoint DLP plus Browser Data Security in Edge for Business inspect text typed or pasted into consumer AI apps in real time and block the submission, and file uploads, before they leave the browser. Copilot and agent interactions are covered natively, with Purview for Agent 365 (Ignite, November 2025) extending DLP further. If no one is running a native desktop AI app, adding a second enforcement layer is over-buying.
Employees use third-party AI in the browser and you want blocked prompts to still get work done.
Purview blocks the prompt or the upload through Edge for Business and the Purview extension for Chrome. Aona adds the step after the block: layout-preserving DOCX, XLSX, and PDF redaction with length-matched, entity-class-aware replacement, so a cleaned document still reaches the AI tool. Running both means the browser is covered twice over and the employee is not simply stopped.
You need to discover and govern Shadow AI tool usage across the workforce.
Purview scopes unmanaged AI apps by category, and only the apps it supports in the browser. Aona's detection catalog covers 10,000+ AI tools, named individually, on managed devices running the Aona plugin or endpoint app. That catalog is detection and discovery scope, not enforcement scope: active policy runs on a narrower top tier.
Employees run native desktop AI apps: ChatGPT, Copilot, or Claude on the desktop rather than in a tab.
Purview's control point for consumer AI is the browser. A native desktop client does not pass through Edge or the Chrome extension, so prompt text sent from it is not inspected. Aona's native endpoint app intercepts those apps directly and hard-blocks on a match, with no user override path.
You want one set of sensitivity classifications applied consistently across both M365 data and AI usage.
Purview owns the labels. Aona's Purview integration is in scoping today; once shipped, label-aware AI policy enforcement is the layered story. Until then, classifications stay in Purview and Aona's policies run independently.
What each tool actually does
Three columns on the Aona side because the browser plugin and the native endpoint app cover different surfaces. Browser-only customers will see fewer green checks than customers with both.
| Capability | Aona browser plugin | Aona native app | Microsoft Purview |
|---|---|---|---|
| Discover | |||
| Discovery of AI tool usage on managed devices | Browser AI tools | Browser plus native AI apps | Unified DSPM plus Edge and Network Data Security signals |
| Native desktop AI app interception (ChatGPT, Copilot, Claude desktop) | MITM proxy for desktop apps | Browser is the control point for consumer AI | |
| Named catalog of 10,000+ third-party AI tools (detection scope) | Detection scope; enforcement runs on a narrower top tier | Same catalog, same detection-not-enforcement caveat | Generative AI category scope, supported apps only |
| Discovery of files leaving M365 into AI tools | Inspected at browser upload | Inspected at browser plus native upload | Endpoint DLP blocks upload to AI app sites |
| Govern | |||
| Hard-block DLP on AI prompts in the browser (third-party AI) | Modal pauses, no override | Modal pauses, no override | Edge for Business, plus Purview extension for Chrome |
| Hard-block DLP on prompts inside native desktop AI apps | Enforced outside the browser, no override | Desktop clients bypass Edge and the Chrome extension | |
| Real-time employee coaching at the moment of action | Policy tips in M365 apps and Edge, no learn-at-the-moment loop | ||
| Sensitivity labels and classification taxonomy | Purview integration scoping | Purview integration scoping | Mature label and DLP policy engine |
| Policy templates for EU AI Act / ISO 42001 | Platform feature | Platform feature | General compliance templates |
| Protect | |||
| Native DLP across SharePoint / OneDrive / Teams / Exchange | Core capability | ||
| File redaction with layout preservation (DOCX / XLSX / PDF) | Length-matched, entity-class-aware, real-time on upload | Length-matched, entity-class-aware, real-time on upload | Block or label, not redact-then-share |
| Operations | |||
| Time to first signal | Hours | Hours | Already deployed |
| Licensing required | Business $9.99 per user per month; Enterprise custom | Business $9.99 per user per month; Enterprise custom | M365 E5 for the full experience; reduced on E3 plus Copilot; pay-as-you-go meters |
| macOS at enterprise scale (managed via MDM) | Plugin pushed via MDM | Manual install only today | |
Based on vendor documentation as of July 2026. Email trust@aona.ai if you find a factual error.
What it takes to ship each one
- Microsoft Intune (Windows MDM, only path shipped)
- Microsoft Entra (admin SSO + user/group sync)
- Active M365 tenant with Purview licensing
Where each one falls short
From public docs and customer interviews. If you find a factual error, email trust@aona.ai.
- Newer vendor: founded 2023, with a far smaller enterprise install base than Microsoft.
- SOC 2 Type II only today. No FedRAMP or IRAP, and none of the government-cloud certifications Microsoft holds.
- Purview integration is scoping, not shipped. Sensitivity-label-aware AI policy is a future feature, not a current one.
- The browser plugin ships for Chrome and Edge only. Firefox is a production candidate, not shipped today.
- Coverage requires the Aona plugin or endpoint app on a managed device. Personal and unmanaged devices are not covered.
- Inline AI enforcement is browser-bound. Native desktop AI clients do not pass through Edge or the Chrome extension, so prompt text sent from them is not inspected.
- Outside Edge, and Chrome with the Purview extension, a block policy works by preventing the browser from opening rather than by inspecting the prompt. Firefox and other browsers are stopped at the device level, not governed.
- Adaptive app scopes cover only the unmanaged AI apps supported in Edge for Business, so coverage is a supported list rather than every AI destination.
- Policy tips exist in M365 apps and in Edge, but there is no real-time coaching loop that teaches the employee at the moment of the prompt.
- File redaction means classification or blocking, not layout-preserving entity replacement that lets the document still be useful in the AI tool.
- Licensing is complex: the full DSPM for AI experience needs M365 E5 (a reduced version runs on E3 plus Copilot licenses), third-party AI coverage needs E5 plus connectors, and pay-as-you-go meters are reported hard to predict. As of July 2026.
What your security review will ask
Certifications, pricing reality, data handling, and residency for both vendors, answered up front so your GRC and legal review can start from this page.
| Aona | Microsoft Purview | |
|---|---|---|
| Certifications | SOC 2 Type II (audit window ended February 2026). No FedRAMP or IRAP today. | FedRAMP High, IRAP, and a broad ISO portfolio via the Microsoft 365 platform. As of July 2026. |
| Pricing and trial | Published pricing: Business plan $9.99 per user per month, Enterprise custom. 30-day self-serve free trial, no credit card. As of July 2026. | Included with M365 E5 for the full experience; a reduced version runs on E3 plus Copilot licenses. Third-party AI coverage needs E5 plus connectors, with pay-as-you-go meters reported hard to predict. As of July 2026. |
| Where prompts are processed | Prompt content is processed server-side by the Aona API in your chosen region. Retention configurable: 30, 90, or 180 days. | Copilot and agent interactions are processed inside the Microsoft 365 service boundary. Consumer AI enforcement runs via Endpoint DLP and Edge on the device. |
| Data residency | 7 live regions: Australia, France, UK, Germany, US, Singapore, Hong Kong. Prompts, files, and audit logs stay in-region. | Follows your Microsoft 365 tenant region, with Advanced Data Residency add-ons for stricter commitments. |
| DPA and security docs | DPA available on request. Security overview at aona.ai/security. SOC 2 report under NDA. | Covered by the Microsoft Products and Services Data Protection Addendum; documentation on the Microsoft Trust Center. |
Competitor facts come from public documentation and pricing pages. Where a vendor does not publish a fact, we say so rather than guess. Corrections: trust@aona.ai.
How Aona and Microsoft Purview work together
The two work as adjacent layers, and the boundary is not where most comparisons draw it. Purview governs data inside Microsoft 365 and reaches out through the browser: Endpoint DLP and Browser Data Security in Edge for Business, plus the Purview extension for Chrome, inspect and block sensitive text and file uploads heading into consumer AI apps. Aona governs the surfaces past that boundary: native desktop AI clients that never touch a managed browser, blocks the employee cannot override, and redaction that returns a usable document instead of a refusal. Together you get coverage from the document, through the browser, to the desktop app.
Microsoft 365 and managed-browser layer
Purview classifies data at rest, applies sensitivity labels, and blocks sensitive text and file uploads to consumer AI apps through Edge for Business and the Purview extension for Chrome.
Desktop AI and redaction layer
Aona's native endpoint app reaches the desktop AI clients the browser never sees. Hard blocks with no override, and layout-preserving redaction so the work can continue.
End-to-end coverage
Sensitive data is governed from where it lives in M365 to where employees take it in AI tools.
Govern AI usage outside the Microsoft estate
30-day free trial. Deploys alongside Purview via Intune and Entra in under an hour. No Purview reconfiguration, no commitment.