Understand data protection and governance tasks for Microsoft 365 and Copilot
Compliance Posture, Exploration, and eDiscovery
CoreChoose the Purview surface that answers posture, item inventory, activity, AI-risk, or investigation-search questions.
Aligned to the current AB-900 guide, verified July 22, 2026.
Why this matters
AB-900 tests whether you can choose the correct Purview view for compliance posture, data location, user activity, AI data risk, or investigation search.
Must Know
- Compliance Manager uses assessments, controls, improvement actions, and a compliance score to guide risk reduction; it is not legal proof of compliance.
- Data Explorer answers where classified or labeled content exists; Activity explorer answers what happened to sensitive or labeled content.
- DSPM identifies sensitive-data exposure and risk and supports investigation and remediation; DSPM for AI is the blueprint term for AI-focused scenarios.
- DLP enforces rules on risky activities; DSPM provides broader posture, discovery, and guided remediation.
- eDiscovery Content search finds potentially responsive files, messages, and other supported content for an investigation.
- These tools can use related data but differ in role scope, filters, processing windows, and purpose, so their counts may differ.
Compare and Distinguish
- Compliance Manager vs DSPM: compliance assessments/improvements vs sensitive-data risk visibility and remediation.
- Data Explorer vs Activity explorer: inventory/state of items vs historical actions on items.
- Activity explorer vs audit search: curated sensitive-data activity view vs broader searchable raw audit records.
- DSPM vs DLP: posture, discovery, investigation, and guided remediation vs enforcement of risky data activities.
- eDiscovery Content search vs Data Explorer: investigation query for responsive content vs classification inventory.
Scenario examples
- Scenario: A team asks which compliance improvements Microsoft recommends. Think: Open the relevant Compliance Manager assessment and improvement actions.
- Scenario: An administrator asks where files containing national IDs exist. Think: Use Data Explorer.
- Scenario: An administrator asks who downgraded labels last week. Think: Use Activity explorer or supporting audit evidence.
- Scenario: Legal needs emails and files matching people, dates, and keywords. Think: Use eDiscovery Content search.
- Scenario: Security wants to see sensitive data interacting with AI apps and agents. Think: Use current DSPM AI views and recognize the blueprint term DSPM for AI.
Exam traps
- A compliance score does not certify legal compliance.
- Data Explorer does not show the same activity history as Activity explorer.
- DSPM identifies and helps remediate posture risk; it is not simply another name for Compliance Manager.
- Content search finds candidates; it does not decide final legal relevance or replace retention/hold decisions.
Key takeaways
- Improvements → Compliance Manager; items → Data Explorer; actions → Activity explorer.
- Sensitive-data/AI posture → DSPM; investigation content → eDiscovery.
- Scope, roles, time window, and refresh explain many apparent report differences.
How it works
- Compliance Manager connects a regulation/template to controls and improvement actions; administrators document and implement work, which changes the measured score where applicable.
- Data Explorer aggregates classification scans; Activity explorer consumes audit events. DSPM combines posture, activity, policy, and risk signals into guided data-security views.
- Content search queries indexed supported data sources and returns matching items for authorized review/export within an eDiscovery workflow.
Objects and administrative surfaces
- Assessments, regulations, controls, improvement actions, and compliance score — Compliance Manager in Microsoft Purview.
- Classified item inventory — Data Explorer; user/system activities — Activity explorer.
- Data risks, AI apps/agents, security objectives, assessments, policies, and AI activities — DSPM in Microsoft Purview.
- Cases, searches, data sources/custodians, queries, results, review/export — eDiscovery in Microsoft Purview.
When to use it
- Use Compliance Manager to identify and prioritize compliance improvement work.
- Use Data Explorer to locate categories of sensitive content and Activity explorer to inspect related activity.
- Use DSPM for sensitive-data/AI posture and eDiscovery Content search for a scoped investigation or legal request.
Security and governance implications
- Assign compliance, data-reader, investigator, and eDiscovery roles narrowly; item previews and search exports can expose highly sensitive data.
- Treat scores and automated recommendations as decision support requiring organizational and legal context.
- Define case purpose, custodians/locations, query scope, evidence handling, and retention for investigation exports.
Troubleshooting signals
- Restate the question as recommendations, items, activities, AI posture, or investigation content; then choose the matching surface.
- Check roles, filters, locations, time windows, indexing/classification/audit availability, and processing delay when expected data is absent.
- When reports disagree, compare population, date range, data source, classification method, and refresh time before treating either as wrong.
More detail
- Compliance Manager organizes regulatory or internal requirements into assessments, controls, and improvement actions. The compliance score is a risk-based measure of progress for assessed actions, not legal advice or proof of compliance.
- Data Explorer answers “Where are classified or labeled items?” It summarizes items by sensitive information type, label, location, and other dimensions so administrators can understand data inventory and exposure.
- Activity explorer answers “What happened to those items?” It presents transformed audit activity such as label applied/changed, file read, DLP-related actions, and supported AI interactions over its available window.
- Microsoft Purview Data Security Posture Management (DSPM) is the current broader solution for discovering, protecting, and investigating sensitive-data risk across Microsoft 365, Azure, Fabric, SaaS, and AI apps/agents. The exam blueprint says DSPM for AI; recognize that label for AI-specific dashboards, policies, and interaction discovery, while current documentation labels the previous experience DSPM for AI (classic).
- eDiscovery Content search finds files, emails, and other supported content that match custodians/locations, keywords, dates, participants, and properties for an investigation. It retrieves potentially responsive content; it does not judge relevance or automatically protect the source.
- These tools can share classification and audit foundations but require separate roles, scopes, filters, and processing windows. Their counts need not match exactly at the same moment.
Ready for the quiz?
- How do Compliance Manager and DSPM answer different questions?
- Which tool answers “where is the data?” and which answers “what happened to it?”
- Why is DSPM not the same as DLP?
- What does eDiscovery Content search produce—and what decision does it not make?
Related objectives
- D2.3.a — Identify compliance risks and recommendations by using Microsoft Purview Compliance Manager
- D2.3.b — Identify sensitive information by using Microsoft Purview Data Explorer
- D2.3.f — Identify user activities reported by Microsoft Purview activity explorer
- D2.3.g — Discover and manage AI activity by using DSPM for AI
- D2.3.h — Search for files and emails by using Content search in Microsoft Purview eDiscovery