Provisional editorial research based on public documentation, not tested effectiveness.
First edition · Reviewed · Rubric 1.1
Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.
Comparable discovery, classification, and data-security posture (DSPM/access-posture) offerings. Microsoft Purview is assessed on classifiers, sensitivity labeling as classification, and Data Security Posture Management only. This cohort does not compare enterprise DLP suites or equate cloud DSPM with channel DLP enforcement. Forcepoint, Proofpoint, Symantec, Netskope, and Zscaler DLP are excluded as peers.
Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.
Separated marks connect to their exact positions. Separation does not change scores.
Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.
Missing evidence for this view
Unknown is not a low score. Select an offering above to inspect its evidence.
A position is only half the story
Momentum
Building history
Baseline recorded 2026-09-21. A second comparable review is needed to show movement.
Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.
Microsoft Purview Data Security· movement by dimension
Dimension
Own movement
Against peers
Operational maturity
Building history
Not available yetNo direction inferred
Shipped innovation
Building history
Not available yetNo direction inferred
Capability breadth
Building history
Not available yetNo direction inferred
Ecosystem & integration
Building history
Not available yetNo direction inferred
Governance & control
Building history
Not available yetNo direction inferred
Operator enablement
Building history
Not available yetNo direction inferred
History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.
Review history & what changed
The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.
2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
Varonis Data Security Platform (medium confidence) has the highest documented score (4.7) for Operational maturity among assessed offerings in this comparison group. 2 offerings remain unknown for this dimension.
Microsoft Purview Data Security (low confidence) and Varonis Data Security Platform (low confidence) and Cyera Data Security (low confidence) and BigID (low confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.
Unknowns and gaps
Unknown is not low quality. Marks are omitted where a required score is unknown.
Microsoft Purview Data Security: no unknown dimensions.
Varonis Data Security Platform: Operator enablement
Cyera Data Security: Operational maturity, Governance & control, Operator enablement
A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.
Selected evidence
Microsoft Purview Data Security · Microsoft
Microsoft Purview Information Protection classifiers and current Data Security Posture Management (not classic DSPM, not DLP-suite comparison) · Assessed 2026-09-21 · Research preview
Operational maturity
How completely do public docs describe safeguards operators use to run discovery and posture without treating marketing claims as proof of reliability?
Documented operating safeguards for running discovery and posture: connector or collector permissions, tenant isolation, encryption of metadata, operator roles, and operational limits. Not vendor age, uptime, or claimed reliability.
Purview documents SITs, trainable classifiers, labels, and current DSPM objectives that correlate Microsoft 365 posture with partner-fed non-Microsoft stores. This assessment covers classification and DSPM only; DLP, Insider Risk, and encryption are adjacent and not scored as peers.
Score4.0 / 5.0medium confidence
Comparison:
Rationale and sources
Learn docs list supporting licenses, Purview permissions, Copilot and Fabric prerequisites, and administrative-unit scoping that hides other units from restricted admins. Inactive tenants pause Microsoft 365 DSPM refresh after 60 days and resume on return. That matches documented operational safeguards (anchor 4). Shared-responsibility residency and tenant incident notification for DSPM itself are not documented here, so not anchor 5. The Data Security Posture Agent is preview and is not used as a safeguard.
How this score is built
Constraints
Edition scoped to Information Protection classifiers/labels and current DSPM; DLP, Insider Risk Management, Information Barriers, Privileged Access Management, and Customer Key or Double Key Encryption are adjacent and not compared as DLP-suite peers.
Prerequisite: supporting Purview license, supported region, and Purview permissions; Copilot, Fabric, Edge, and Entra-registered AI apps have additional documented prerequisites.
Microsoft locations in asset explorer currently include Microsoft 365 only; GCP, Snowflake, Databricks and similar stores depend on partner integrations.
Data Security Posture Agent and Sentinel data lake partner setup are preview; they are not treated as GA.
Classic DSPM and DSPM for AI remain available but are not the evaluated edition.
Classification and posture coverage by workload is license-dependent and unverified in a lab.
Innovation stages reflect contemporary baseline evidence; no workflow differentiation beyond the shared baseline was established in this first edition.
0 — Primary evidence affirmatively establishes that the evaluated scope does not provide operating safeguards for the scoped assessment workflow. Missing evidence is unknown, never zero.
1 — A concrete basic operating safeguard is documented for the evaluated edition.
2 — License or permission prerequisites and a basic administrator role for the console are documented.
3 — A connector or collector permission model plus encryption in transit or tenant isolation for metadata is documented.
4 — Operational safeguards such as admin-unit scoping, operator audit, inactivity handling, or in-network collectors that do not persist customer content are documented.
5 — An end-to-end operating program is documented, including residency choice, tenant incident notification, reversible remediations, and shared-responsibility operator controls.
Assessed offerings inDiscovery, classification, and access posture. Unknown means not scored, not low quality.
First edition dated 2026-09-21; no historical assessments are available.
The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
Contemporary cohort baseline: Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.
Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
Rubric 1.1 divides the new maturity anchor 5 requirements into residency choice (two tenths), tenant incident notification (two), reversible remediation (three), and shared-responsibility operator controls (three). Reversibility and ongoing customer control receive the larger shares because they directly govern safe operation; these are shared editorial weights, not measured performance. Purview receives no extra credit from adjacent services or preview agents. Cyera and BigID operating safeguards remain unknown. Documented baseline innovation stays tied at 3.0.
All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.
How to read these scores
Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.
What this edition covers.
First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.
First edition dated 2026-09-21; no historical assessments are available.
The four selected existing-catalog offerings form one explicitly scoped cohort. Assessment applies only to named editions and documented modules; adjacent products and managed-service outcomes are excluded.
Primary sources establish documented capabilities and their prerequisites, not actual effectiveness, reliability, deployment effort, staffing savings or return on investment.
Confidence reflects evidence and inference within the stated scope, not vendor size, age or source count.
Contemporary cohort baseline: Discovery, classification, sensitivity/access/exposure correlation, data-owner context, posture prioritization, and owner-routed or automated remediation are contemporary DSPM baseline capabilities. Access graphs, risk scores, AI labels and remediation queues alone do not establish differentiation.
Innovation stage 3 indicates supported baseline workflows, not market novelty. No stage 4 or 5 differentiation is established by this first-edition evidence. Public-documentation confidence is low for cross-offering calibration.
Zero requires affirmative evidence of absence. Missing, gated or incomplete documentation remains unknown; a lower stage is not assigned merely because documentation is unavailable.
Scores were checked against cumulative stage prerequisites; selected operating/control cells remain unknown where those prerequisites could not be verified.
Rubric 1.1 divides the new maturity anchor 5 requirements into residency choice (two tenths), tenant incident notification (two), reversible remediation (three), and shared-responsibility operator controls (three). Reversibility and ongoing customer control receive the larger shares because they directly govern safe operation; these are shared editorial weights, not measured performance. Purview receives no extra credit from adjacent services or preview agents. Cyera and BigID operating safeguards remain unknown. Documented baseline innovation stays tied at 3.0.
All six dimensions were reviewed for the 2026-09-21 momentum baseline. Source-backed corrections and retained evidence gaps are recorded in docs/research/2026-09-21-momentum-baseline-a.md. These are baseline research decisions, not longitudinal vendor movement; unknowns remain unknown and the rubric/edition scopes are unchanged.
Discovery, classification, and access posture
Comparable discovery, classification, and data-security posture (DSPM/access-posture) offerings. Microsoft Purview is assessed on classifiers, sensitivity labeling as classification, and Data Security Posture Management only. This cohort does not compare enterprise DLP suites or equate cloud DSPM with channel DLP enforcement. Forcepoint, Proofpoint, Symantec, Netskope, and Zscaler DLP are excluded as peers.