DLP / DSPM / Microsoft

Microsoft Purview Data Security

Microsoft Purview brings together tools for finding sensitive information, labeling it, examining exposure, and applying data loss prevention policies. For practitioners, the useful distinction is between identifying a sensitive document and enforcing a rule when someone shares that document.

Classification, DLP and postureResearch reviewed

What you are evaluating

This profile covers Information Protection, data loss prevention and data security posture management. Coverage varies by licensed workload and connector; encryption and customer key options are separate decisions, not properties of every label.

A useful evaluation context

A Microsoft-centered team can evaluate whether shared labels and workload policies connect its information owners, endpoint administrators and security analysts.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Sensitive information types and trainable classifiers identify content that policies can classify or label.
  • Data loss prevention policies apply to supported Microsoft services, endpoints and other documented locations, with simulation options before enforcement.
  • Posture management presents exposure objectives and remediation guidance; sensitivity labels can connect classification to configured protection.

Where it fits in the work

  1. Inventory the Microsoft workloads and endpoint types in a lab, and map each one to an explicitly licensed policy location.
  2. Create synthetic documents containing two data classes, then observe classification and policy matches in simulation before deciding whether to block.
  3. Test sharing, approved exceptions and incident review on the selected locations; record which controls require a separate connector or license.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Place a synthetic customer spreadsheet in a lab Microsoft 365 site, label it, and attempt a share covered by an audit-only policy.

Evidence to look for

The policy match identifies the test document and chosen location; after an approved change to blocking, the same scoped share is prevented and logged.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which selected locations support the required detection and action under the actual subscription?
  2. Does a sensitivity label merely classify the document, or also apply the intended encryption and access settings?
  3. How will reviewers distinguish a false positive from a justified business exception without exposing document contents unnecessarily?

Find your next idea.

Tip: press / to open search. Escape closes this window.