Section 4: Data Protection with Microsoft Purview
Chapter 31: Introduction to Microsoft Purview
Microsoft Purview is a comprehensive family of solutions for data governance, protection, and
compliance. In the context of the AB-900 exam, Purview is the "safety engine" for AI. It ensures
that as Copilot and agents interact with your data, they do so within a framework of visibility and
control.
Chapter 32: Data Classification Basics
Classification is the process of identifying what kind of data you have. Purview uses two primary
methods:
Sensitive Information Types (SITs): Pattern-based classifiers (e.g., Credit Card
numbers, Passport IDs, or custom Regex).
Trainable Classifiers: Machine learning models that recognize "intent" or "categories"
like "Legal Agreements," "HR Documents," or "Source Code."
Chapter 33: Understanding Sensitivity Labels
Sensitivity labels are persistent tags that stay with the data wherever it goes.
Metadata: They attach metadata to the file that describes its sensitivity (e.g., Public,
General, Confidential).
Protection: Labels can trigger encryption or add visual markings (watermarks,
headers/footers).
Copilot Context: Copilot respects these labels. If a file is labeled "Highly Confidential,"
Copilot will maintain that protection level in its summaries.
Chapter 34: How to Create a Sensitivity Label
1. Navigate to the Microsoft Purview portal.
2. Go to Information Protection > Labels.
3. Click + Create a label.
4. Define the Scope (Files, Emails, Meetings, or Sites).
5. Set the Protection actions (Encryption or Content Marking).
Chapter 35: Applying Labels to Documents
Labels can be applied in three ways:
Manual: The user selects the label from the ribbon in Word/Excel/Outlook.
Recommended: Purview detects sensitive data (like a credit card number) and prompts
the user to apply a label.
Automatic: The label is applied instantly based on pre-defined rules without user
intervention.
Chapter 36: Using Labels for Containers (Teams/Groups)
You can apply sensitivity labels to entire Teams, M365 Groups, or SharePoint Sites.
Governance: A label on a Team can automatically set the privacy to "Private" and block
"Guest Access."
Inheritance: Files uploaded to a labeled container do not automatically inherit the label,
but the container's security settings (like "Unmanaged Device" blocks) will apply to
anyone trying to access them.
Chapter 37: Data Loss Prevention (DLP) Concepts
DLP is about preventing the accidental sharing of sensitive info.
Locations: DLP policies can monitor Exchange, SharePoint, OneDrive, Teams, and now
Copilot Chat.
Conditions: "If the content contains a Credit Card number..."
Actions: "...then block the share and notify the user."
Chapter 38: Creating a DLP Policy
DLP policies consist of:
1. Locations: Where to monitor (e.g., Teams chat).
2. Rules: The logic (Condition + Action).
3. Policy Tips: Brief messages that appear to users (e.g., "This message was blocked
because it contains sensitive data").
Chapter 39: How DLP Interacts with Copilot
This is a high-priority AB-900 topic.
Prompt Protection: DLP can now detect SITs (like SSNs) inside a user's prompt to
Copilot and block the interaction in real-time.
Response Protection: If Copilot tries to generate a response using a file that has a
"Blocked" sensitivity label, DLP can prevent that response from being shown to the user.
Chapter 40: Protecting Sensitive Information Types
Microsoft provides over 300+ built-in SITs. For the exam, know that you can:
Combine SITs: Create a rule that triggers only if both a "Name" and a "Bank Account
Number" are found together.
Confidence Levels: Set thresholds (e.g., 85% confidence) to reduce "false positives" in
your reports.
Chapter 41: Insider Risk Management
Unlike DLP (which looks at data), Insider Risk Management looks at user behavior.
Signals: A user downloading a high volume of files from SharePoint right before
resigning.
Privacy: By default, usernames are pseudonymized (e.g., "Anon123") to protect privacy
during initial investigations.
Chapter 42: Communication Compliance
Specifically designed to monitor "workplace conduct."
AI Interventions: It can detect harassment, threats, or inappropriate language in Teams
chats and Copilot Prompts.
Triage: Investigators can "Resolve," "Notify," or "Escalate" an alert to a legal case.
Chapter 43: eDiscovery: When You Need to Search Data
eDiscovery is used for legal or internal investigations to "preserve" and "export" data.
Content Search: Quickly find every time a specific keyword was used in Copilot
prompts across the organization.
Legal Hold: Ensures that even if a user deletes their chat history, the data is preserved
for the investigation.
Chapter 44: Compliance Manager: Your Roadmap
Think of Compliance Manager as a "checklist" for regulatory standards (like GDPR, HIPAA,
or ISO).
Compliance Score: A total percentage of how well you meet a specific standard.
Improvement Actions: Step-by-step guides on what to configure (e.g., "Enable
Sensitivity Labels for Teams") to raise your score.
Chapter 45: Privacy Management in M365 (Microsoft Priva)
Priva helps organizations manage personal data and handle Subject Rights Requests (SRRs).
Privacy Risk: Identifies where personal data (PII) is overshared or "stale" (not used for
years).
SRRs: Automates the search for every piece of data you have on a specific individual if
they request their "Right to be Forgotten."