Home / Microsoft Purview
πŸ”’

Microsoft Purview

Data security, compliance, information protection, DLP & governance

What is Microsoft Purview?

Microsoft Purview is a comprehensive set of solutions that helps organizations govern, protect, and manage data. It brings together data security, data governance, risk, and compliance solutions to help organizations protect sensitive data across clouds, apps, and endpoints, while managing regulatory compliance requirements.

Purview Solutions

Data Security

Data Compliance

Data Governance

Copilot in Purview

Security Copilot integrates with Microsoft Purview to help you investigate data security incidents, understand compliance requirements, and get contextual guidance.

Purview Labs

Data governance and compliance labs. deploy sensitivity labels, configure DLP, manage insider risk, and run eDiscovery investigations in real enterprise scenarios.

01
Beginner⏱ 75 min · 10 steps

Deploy Sensitivity Labels with Auto-Labeling

Create a sensitivity label taxonomy aligned to your data classification policy, configure visual markings and encryption settings, publish labels to pilot groups, set up auto-labeling policies for credit card and SSN detection, and monitor adoption with Activity Explorer.

02
Intermediate⏱ 90 min · 12 steps

Configure DLP for Exchange & SharePoint

Create DLP policies using built-in and custom sensitive information types, configure policy tips and end-user notifications, set up incident reports for compliance officers, test with simulated data sharing scenarios, and tune rules to minimize false positives.

03
Intermediate⏱ 120 min · 14 steps

Set Up Insider Risk Management

Configure prerequisites (audit logging, HR data connector), create insider risk policies for data theft by departing employees, set up priority user groups and risk indicators, investigate triggered alerts in the case management workflow, and escalate to eDiscovery.

04
Advanced⏱ 150 min · 18 steps

Run a Premium eDiscovery Investigation

Create a Premium eDiscovery case for a legal hold scenario, add custodians and non-custodial data sources, build targeted search queries with KQL, process and review collected data in review sets, apply predictive coding for relevance scoring, and export the final production set for legal counsel.

05
Intermediate⏱ 90 min · 12 steps

Configure Communication Compliance, Audit & Data Lifecycle Management

Configure communication compliance policies for regulatory monitoring, enable unified audit logging, set up adaptive retention policies with intelligent scoping, and design a data lifecycle management framework.

06
Advanced⏱ 120 min · 12 steps

Deploy Records Management, Information Barriers & Compliance Manager

Deploy records management with file plan descriptors, configure information barriers for regulated teams, set up Compliance Manager assessments, and create event-based retention triggers.

07
Advanced⏱ 130 min · 16 steps

Data Security Posture Management for AI Workloads

Configure DSPM for AI in Microsoft Purview, discover AI data flows, classify sensitive training data, monitor AI interactions with labeled content, and enforce responsible AI compliance policies.

Purview Resources

Microsoft Purview FAQ

What is included in Microsoft Purview?

Microsoft Purview is a comprehensive data security, governance, and compliance platform that includes:

  • Information Protection: Sensitivity labels to classify and protect documents and emails with encryption, visual markings, and access restrictions
  • Data Loss Prevention (DLP): Policies to detect and prevent sensitive data from being shared through Exchange, Teams, SharePoint, OneDrive, endpoints, and Power BI
  • Insider Risk Management: ML-powered detection of risky user behaviours like data exfiltration by departing employees, policy violations, and security breaches
  • eDiscovery: Standard (content search, basic cases) and Premium (custodian management, review sets, predictive coding) for legal and compliance investigations
  • Communication Compliance: Monitoring of email and Teams messages for regulatory compliance, code of conduct, and policy violations
  • Data Lifecycle Management: Retention and deletion policies with adaptive scopes for compliance-driven data governance
  • Records Management: Regulatory record declaration with event-based retention triggers
  • Compliance Manager: Assessment framework for tracking compliance against 350+ regulatory templates (GDPR, HIPAA, ISO 27001, etc.)

Purview compliance solutions

What licensing is required for Purview?

Purview capabilities are tiered across licence levels:

  • Microsoft 365 E3: Basic sensitivity labels (manual only), basic DLP for Exchange, eDiscovery Standard, basic retention policies, manual records management
  • Microsoft 365 E5 / E5 Compliance: Auto-labeling, full DLP (endpoints, Teams, SharePoint, Power BI), Insider Risk Management, eDiscovery Premium (review sets, predictive coding), Communication Compliance, adaptive scopes, advanced Data Lifecycle
  • E5 Information Protection & Governance: Standalone add-on for auto-labeling and advanced DLP if you have E3
  • E5 Insider Risk Management: Standalone add-on for Insider Risk features
  • E5 eDiscovery: Standalone add-on for Premium eDiscovery

For most organisations, Microsoft 365 E5 or the E5 Compliance add-on provides the best value as it unlocks all Purview capabilities. Individual add-ons are available if you only need specific features.

Purview licensing

How do sensitivity labels work?

Sensitivity labels are the foundation of Microsoft Purview Information Protection. They classify and protect content across your digital estate:

  • Visual markings: Headers, footers, and watermarks applied to documents and emails so users know the classification at a glance
  • Encryption: Azure Rights Management encryption that restricts who can open, edit, copy, print, or forward the content. even if it leaves your organisation
  • Access restrictions: Define which users or groups can access content (e.g., only Finance department, or only internal users)
  • Application methods: Users apply labels manually in Office apps and Outlook, admins can recommend labels via policy tips (e.g., "This document contains credit card numbers. apply Confidential?"), or auto-label based on content matching sensitive information types
  • Container labels: Labels can protect entire containers: SharePoint sites, Teams, and Microsoft 365 Groups. controlling external sharing, guest access, and unmanaged device access

Labels persist with the content wherever it travels. inside and outside your organisation. A properly encrypted document remains protected even if someone emails it to a personal account.

Sensitivity labels overview

What is Insider Risk Management and how does it work?

Insider Risk Management detects and helps respond to potentially risky activities by users within your organisation. It correlates signals across multiple sources to identify patterns that may indicate data theft, security violations, or policy breaches:

  • Signal sources: Endpoint activity (file copies, USB usage, print), email sending patterns, cloud app uploads, SharePoint/OneDrive sharing, and HR system triggers (resignation, termination dates from Workday/SAP)
  • Policy templates: Data theft by departing employees, data leaks, security policy violations, patient data misuse (healthcare), and financial regulatory violations
  • Risk scoring: Each user receives a dynamic risk score based on the volume, severity, and pattern of their activities. High-risk users trigger alerts for analyst review.
  • Investigation workflow: Analysts see a pseudonymised activity timeline, can escalate to eDiscovery cases, and coordinate with HR/Legal. User identities can be revealed with appropriate privileges.
  • Adaptive Protection: Automatically adjusts DLP policy strictness based on user risk level. high-risk users get stricter controls without manual intervention

All Insider Risk data is privacy-controlled with role-based access, pseudonymisation by default, and audit logging of investigator actions.

Insider Risk Management

What is the difference between eDiscovery Standard and Premium?

Both tiers support legal investigations but differ significantly in capability:

  • eDiscovery Standard (included in E3): Content search across Exchange, SharePoint, OneDrive; basic case management; export to PST/ZIP; litigation hold on mailboxes
  • eDiscovery Premium (requires E5): Adds custodian management (track and communicate with data custodians), legal hold notifications with acknowledgement tracking, advanced review sets with conversation threading and near-duplicate detection, predictive coding (AI-assisted relevance classification), privilege detection for attorney-client content, analytics dashboards for case management, and CJK language support

For routine HR investigations or simple content searches, Standard is sufficient. For litigation, regulatory investigations, or large-scale document review with legal counsel, Premium is essential.

eDiscovery overview

Can Purview protect data on endpoints?

Yes. Endpoint DLP extends data loss prevention to Windows 10/11 and macOS devices, monitoring and controlling sensitive data operations at the device level:

  • Copy to USB/removable media: Block or audit when users copy files containing sensitive data to USB drives
  • Print: Warn or block printing of files containing credit card numbers, SSNs, or other sensitive information types
  • Copy to clipboard: Audit clipboard operations that move sensitive content between applications
  • Upload to cloud service: Block uploads of sensitive files to personal cloud storage (Dropbox, Google Drive personal)
  • Access by unallowed apps: Prevent specified applications from opening files with sensitivity labels
  • Bluetooth transfer: Block sensitive file transfer via Bluetooth

Endpoint DLP requires devices onboarded to Microsoft Defender for Endpoint (MDE). DLP alerts appear in both the Purview compliance portal and the Defender XDR incident queue for unified investigation.

Endpoint DLP