Microsoft Purview Explained: What It Does and What You Need to Make It Work
Short Answer
Microsoft Purview is the compliance and data governance toolset within the Microsoft 365 ecosystem. It provides sensitivity labelling, data loss prevention, retention policies, eDiscovery, and compliance management capabilities. Purview is powerful but requires governance decisions before configuration; the tooling cannot substitute for the policy decisions that determine how it is used.
Microsoft Purview is the umbrella name for a suite of compliance and data governance capabilities that Microsoft has assembled within the Microsoft 365 and Azure ecosystems. It includes Microsoft Information Protection for sensitivity labelling and data classification, data loss prevention for preventing inappropriate data movement, records management for retention and disposition, eDiscovery for legal and regulatory investigation, and compliance management for tracking obligations and controls. Understanding what each capability does, and what is required to make it work, is the starting point for getting value from the investment already included in many Microsoft 365 licences.
Sensitivity labelling is the foundation of Purview's information protection capability. Labels classify documents and emails according to their sensitivity, and that classification can drive encryption, access controls, and data loss prevention rules. Labels work when the label taxonomy reflects the organisation's actual information classification policy and when users apply labels consistently. A labelling scheme that is too complex will not be adopted. Labels that are not enforced at the policy level rely entirely on user compliance, which is insufficient for sensitive data protection. Purview can enforce labelling on certain content types automatically, reducing reliance on user decisions.
Data loss prevention prevents sensitive information from leaving the organisation through unapproved channels. Purview DLP can monitor email, Teams messages, SharePoint and OneDrive sharing, and endpoint device activity, and can apply policies that block, warn, or audit transfers of sensitive content. Effective DLP requires knowing what data types need to be protected, defining the channels and destinations that represent risk, and tuning the policies to avoid excessive false positives that lead users to work around the controls. DLP that generates too many alerts or blocks legitimate activity will be bypassed.
Retention policies determine how long content is kept and what happens to it when the retention period expires. This capability is relevant to legal, regulatory, and business requirements: some content must be retained for a defined period, some must be deleted after a defined period, and some must be retained indefinitely. Purview can apply retention policies across Microsoft 365 services automatically, but the policies must reflect accurate retention schedules that have been determined from legal and regulatory requirements, not assumed from default settings.
eDiscovery in Purview enables organisations to identify, preserve, and export content relevant to legal proceedings or regulatory investigations. This capability is relevant to any organisation that faces litigation risk or regulatory scrutiny. Purview eDiscovery allows searches across Exchange, Teams, SharePoint, and OneDrive, with holds that prevent content from being deleted while proceedings are active. Organisations that have not configured eDiscovery before it is needed may find that content they need has been deleted under retention policies or cannot be located efficiently without the collection capabilities Purview provides.
Purview requires governance decisions before configuration will be effective. Labels require an information classification policy. DLP rules require knowledge of which data types are sensitive and which sharing channels carry risk. Retention policies require accurate retention schedules. Without these governance inputs, Purview is a set of tools configured around assumptions rather than requirements. The most common failure mode is organisations that configure Purview without having made the underlying governance decisions, producing a technical implementation that does not match the organisation's actual compliance obligations.
Related Service
Frequently Asked Questions
Related Reading
Ready to discuss?
No sales script. Initial discussion is obligation-free.