Microsoft Purview: The Big Picture
Microsoft Purview is your data guardian — information protection, DLP, insider risk, communication compliance, and more. Before diving into each tool, let's see how they all fit together.
What is Microsoft Purview?
Think of Purview as a team of specialists protecting your organisation’s data.
One specialist labels everything — “this is confidential, this is public” (Information Protection). Another watches the exits — “you can’t email that spreadsheet to a personal account” (DLP). A third watches the people — “this employee just downloaded 500 files, that’s unusual” (Insider Risk). A fourth reads the room — “that Teams message violates our conduct policy” (Communication Compliance).
They all work together because data threats come from many directions. Purview covers them all.
The Purview family at a glance
| Feature | What It Does | Key Question It Answers |
|---|---|---|
| Information Protection | Classifies and labels data based on sensitivity | What kind of data do we have? |
| Data Loss Prevention (DLP) | Prevents sensitive data from leaving the organisation | Is someone trying to share something they shouldn't? |
| Insider Risk Management | Detects risky user behaviour patterns | Is an employee acting suspiciously? |
| Communication Compliance | Monitors messages for policy violations | Is anyone saying something that violates our policies? |
| DSPM for AI | Discovers and governs AI-related data activity | How is data being used with AI tools? |
| Data Lifecycle Management | Manages retention and deletion of data | How long do we keep things, and when do we delete them? |
Key exam concept: Each Purview tool solves a DIFFERENT problem. The exam tests whether you can pick the right tool for a given scenario. If data needs labelling → Information Protection. If data is being shared inappropriately → DLP. If a user is acting suspiciously → Insider Risk. If a message violates policy → Communication Compliance.
How the Purview tools connect
These tools work as a pipeline — each step feeds the next:
- Information Protection → labels data as “Confidential”, “Internal”, “Public”
- DLP → uses those labels to enforce rules (“don’t email Confidential files externally”)
- Insider Risk → detects when someone tries to bypass those rules repeatedly
- Communication Compliance → catches policy violations in Teams/Outlook messages
- DSPM for AI → monitors how labelled data is used with Copilot and other AI tools
- Data Lifecycle → retains data for compliance periods, then auto-deletes
Scenario: Clearfield Council's data governance journey
Officer Patel implements Purview across Clearfield Council:
Month 1: Know your data
- Enable Information Protection → auto-classify documents containing personal data
- Apply sensitivity labels: “Public”, “Official”, “Sensitive”, “Highly Sensitive”
Month 2: Protect your data
- Set up DLP policies → block external sharing of anything labelled “Sensitive” or above
- Alert Officer Patel when DLP triggers
Month 3: Detect risks
- Enable Insider Risk Management → flag unusual download patterns (e.g., 500 files in one hour)
- Enable Communication Compliance → monitor for discriminatory language in official channels
Month 4: Govern AI
- Deploy Copilot → enable DSPM for AI → monitor which labelled data Copilot accesses
- Set up alerts for Copilot accessing “Highly Sensitive” content
Ongoing: Manage lifecycle
- Retention policies → keep council records for 7 years, then auto-delete
- Retention labels → legal hold on anything related to active investigations
Each layer adds protection. Together, they create a comprehensive data governance framework.
Where to find Purview
Purview tools are accessed through the Microsoft Purview portal (purview.microsoft.com):
| Section | What You’ll Find |
|---|---|
| Information protection | Sensitivity labels, label policies, auto-labelling |
| Data loss prevention | DLP policies, alerts, activity explorer |
| Insider risk management | Policies, alerts, cases, analytics |
| Communication compliance | Policies, alerts, investigations |
| Data security posture management | AI activity, data security insights |
| Data lifecycle management | Retention policies, labels, disposition |
| eDiscovery | Content search, cases, legal holds |
| Compliance Manager | Compliance score, assessments, improvement actions |
🎬 Video walkthrough
🎬 Video coming soon
Microsoft Purview Overview — AB-900 Module 11
Microsoft Purview Overview — AB-900 Module 11
~10 minFlashcards
Knowledge Check
Northwave discovers that an employee has been downloading hundreds of customer files to a USB drive every night for the past week. Which Purview tool would detect this behaviour?
Clearfield Council wants to ensure that documents labelled 'Highly Sensitive' cannot be emailed to external recipients. Which Purview tool should they configure?
Next up: Sensitivity Labels & Data Classification — how to identify and label your data so the rest of Purview can protect it.