Understand data protection and governance tasks for Microsoft 365 and Copilot
Information Protection and Classification
Understand the Purview solution map, classify content accurately, and apply sensitivity protection without confusing classification with lifecycle or activity controls.
What you need to know
- Microsoft Purview is a family of solutions, not one generic control. Information Protection answers “What is sensitive and how should it be marked or protected?” Data Lifecycle Management answers “How long should it be kept and what happens afterward?” DLP answers “Which risky movement or use should be warned, audited, or blocked?”
- Insider Risk Management asks whether a pattern of user behavior may represent insider risk. Communication Compliance asks which messages may violate conduct or regulatory policy. Compliance Manager asks which improvement actions help address compliance requirements.
- Data Explorer answers “Where are classified or labeled items?” Activity explorer answers “What happened to sensitive or labeled items?” DSPM is the current broader posture solution for sensitive-data risk across traditional and AI environments; the blueprint’s DSPM for AI term remains important for recognizing AI-specific discovery and policy scenarios.
- eDiscovery Content search asks “Which files, emails, or other supported content match an investigation query?” Search results are evidence for a case; eDiscovery is not a protection or automatic remediation control.
- A sensitivity label can classify and, depending on configuration, apply markings, encryption, or container settings. The label must be published to the intended users or locations before they can use it. A label does not repair incorrect SharePoint membership.
- Sensitive information types use patterns such as regular expressions, keywords, checksums, and supporting evidence to find items such as identifiers. Trainable classifiers use machine learning and example content to recognize categories whose meaning depends more on context than a stable pattern.
How it works
- Classification identifies content. A sensitivity label can be applied manually, recommended, or automatically where supported; protection settings then travel with supported content according to the label configuration.
- Purview solutions reuse classifiers. The same sensitive information type can be a DLP condition, an auto-labeling signal, or a reporting dimension, while each solution still performs a different action.
- Data Explorer aggregates item/classification information; Activity explorer transforms audit events into an activity view. Their data can have processing delay and requires appropriate roles.
Compare and distinguish
- Sensitivity vs retention: persistent classification/protection vs keep/delete lifecycle behavior.
- Sensitivity label vs sensitive information type: a policy-bearing label applied to content vs a detector used to recognize content.
- Sensitive information type vs trainable classifier: patterned evidence vs contextual category learned from examples.
- Data Explorer vs Activity explorer: where classified items are vs what users/systems did to them.
- Compliance Manager vs DSPM: compliance assessments and recommended improvement actions vs visibility and remediation for sensitive-data risk, including AI.
- eDiscovery search vs Information Protection: find responsive content for investigation vs classify and protect content.
Objects and administrative surfaces
- Sensitivity labels, publishing policies, auto-labeling, sensitive information types, trainable classifiers, Data Explorer, and Activity explorer — Microsoft Purview portal.
- Compliance Manager assessments/improvement actions, DSPM dashboards, DLP, risk solutions, audit, and eDiscovery — their specific solutions in Microsoft Purview.
- Container label settings can affect Microsoft 365 groups, Teams, and SharePoint sites; item labels protect supported files and emails.
Scenario examples
- Scenario: Confidential contracts must remain encrypted after download — reasoning: apply a sensitivity label with the required encryption, not a retention label.
- Scenario: The organization must detect payment-card numbers — reasoning: use a sensitive information type and then consume it in the relevant label or DLP policy.
- Scenario: The organization must identify résumés with varied layouts — reasoning: use a trainable classifier because the category is contextual.
- Scenario: An investigator asks where Confidential files exist and what users did with them — reasoning: use Data Explorer for the inventory question and Activity explorer for the activity question.
When to use it
- Use a sensitivity label when content needs a business classification, marking, encryption, or supported container setting.
- Use a sensitive information type for stable patterns and evidence; use a trainable classifier when examples and context define the category.
- Use the Purview solution map to translate the administrator’s question into the specific tool before configuring a policy.
Security and governance implications
- Design an understandable label taxonomy, publish labels to the correct population, test automatic actions, and avoid labels so numerous that users cannot choose reliably.
- Grant data-reader and content-explorer roles narrowly because previews and search results can expose sensitive information.
- Treat classifier matches as evidence with confidence and context, not infallible declarations.
Troubleshooting signals
- If a sensitivity label is absent, check publishing policy scope, user/location, policy status and propagation, licensing, and supported application/content type.
- If classification misses content, inspect pattern/context evidence, confidence, instance count, language/file support, and whether processing/indexing is complete.
- If Explorer counts differ, confirm time windows, roles, filters, supported locations, and ingestion delay before concluding that protection failed.
Exam traps
- A sensitivity label can protect content but does not define how long it must be kept unless another lifecycle control is configured.
- Classification identifies content; it does not automatically block sharing without a label, DLP rule, or other configured action.
- Data Explorer is not Activity explorer, and neither is a substitute for eDiscovery search.
- The current umbrella term DSPM is broader than the older DSPM for AI experience; recognize both when the exam blueprint names DSPM for AI.
Key takeaways
- Question first: what is it, how protect it, what happened, how long keep it, or where is investigation content?
- Pattern → sensitive information type; context → trainable classifier; protection → sensitivity label.
- Items → Data Explorer; activities → Activity explorer; improvements → Compliance Manager; sensitive-data/AI posture → DSPM.
Related objectives
- D2.1.a
- D2.1.b
- D2.1.c