Microsoft Purview: a unified platform for data
Microsoft Purview brings together under a single control plane data security, regulatory compliance, and information asset governance. The stated objective: cover data wherever it resides, whether stored on-premises, in a multi-cloud environment, in third-party SaaS applications or natively in Microsoft 365.
This approach addresses a concrete problem for IT and security teams: fragmentation of compliance and protection tools multiplies blind spots. Purview proposes a common repository rather than a collection of disjointed tools. Here's how this platform is organized, its technical flows, its licensing implications and key points to understand before any deployment.
The three functional pillars of Purview
Purview's architecture rests on three complementary functional columns. They correspond to three distinct questions: what must I protect, what must I prove, and what must I understand about my data assets.
Data Security: protecting sensitive information
This first pillar groups active protection capabilities:
- Data Loss Prevention (DLP) on Windows, macOS, USB devices, network and cloud
- Microsoft Defender for Cloud Apps, the CASB (Cloud Access Security Broker) of the suite
- Information protection via sensitivity labeling and encryption
- Insider Risk Management to detect risky internal behaviors
- Adaptive Protection, which dynamically adjusts policies based on a user's risk level
- Data Security Posture Management (DSPM), to continuously assess sensitive data exposure
Data Compliance: proving compliance
This second pillar structures the organization's ability to demonstrate its compliance:
- eDiscovery in Standard and Premium versions, for investigations and litigation
- Records Management, the management of regulatory records
- Management of data lifecycle (retention, deletion, archiving)
- Communication Compliance, to monitor internal and external exchanges
- Compliance Manager, which centralizes regulatory assessments and compliance scores
- Privileged Access Management, to govern access with elevated privileges
Data Governance: mapping the data asset landscape
The third pillar addresses a question prior to any security policy: where sensitive data actually resides. It relies on the Data Map, the unified Data Catalog, data domain estimation, business glossaries and automatic classification engines.
Good to know
Without reliable mapping via the Data Map, DLP and classification policies rely on assumptions rather than actual inventory. Governance logically precedes security in a coherent Purview deployment.
Technical architecture and operational flows
On the architecture side, Purview relies on connectors to Microsoft 365 data sources, on-premises environments, multi-cloud (Azure, AWS, Box notably) and business databases. Two flows deserve particular attention during deployment:
- The Endpoint DLP flow: it works in conjunction with Microsoft Defender for Endpoint and the central policy engine. Events detected on the endpoint (copy to USB, printing, cloud upload) transit to the rules engine before action application (blocking, warning, audit only).
- The classic DLP workflow: creating or importing sensitivity labels, configuring labeling parameters, publishing policies, then effective application of protection to relevant contents.
- The CASB flow (Defender for Cloud Apps): discovery of cloud applications used (shadow IT), application of conditional access policies, then alert generation in case of anomalous behavior.
These flows are not independent: a poorly configured sensitivity label upstream degrades the precision of CASB alerts and DLP rules downstream. An audit of existing rules before migration or extension of scope remains essential.
Microsoft 365 E3 and E5 licenses: which scope for which cost
The license choice directly determines the available functional scope. In practice, most of Purview's advanced security and compliance capabilities are reserved for Microsoft 365 E5, while Microsoft 365 E3 covers a more restricted base.
| Pillar | Key capabilities | License positioning |
|---|---|---|
| Data Security | Endpoint and cloud DLP, Defender for Cloud Apps (CASB), labeling and encryption, Insider Risk Management, Adaptive Protection, DSPM | Essentially Microsoft 365 E5 |
| Data Compliance | Standard and Premium eDiscovery, Records Management, lifecycle, Communication Compliance, Compliance Manager, Privileged Access Management | Standard eDiscovery in E3, the rest mostly in E5 |
| Data Governance | Data Map, unified Data Catalog, business glossaries, classification, data domain estimation | Add-on Microsoft Purview billed according to processing capacity |
Caution
Some Data Governance capabilities (Data Map, Data Catalog) fall under a capacity-based billing model, separate from E3/E5 subscription. Check the actual cost via the Azure pricing calculator before extending the scan to your entire data assets.
For organizations already under Microsoft 365 E3, activating advanced DLP, Insider Risk Management or Communication Compliance requires either moving to E5 or purchasing Ă la carte E5 compliance add-ons.
Generative AI, Copilot and data protection
The integration of artificial intelligence changes the game for governance. Purview now integrates a dedicated component for data protection for AI and agents, with a dual challenge:
- Ensuring that Microsoft 365 Copilot and generative agents respect sensitivity labels already applied to contents
- Preventing a generated response from exposing information that the end user normally doesn't have access to (respect of underlying permissions)
This point is critical: a Copilot deployment without prior classification of sensitive contents amounts to opening an uncontrolled access door to protected data. Classification and labeling are therefore no longer simple compliance exercises, but a technical prerequisite for any secure generative AI deployment.
Deployment roadmap and best practices
The governance lifecycle, as represented in the Purview architecture, follows a circular logic around data: discovery, classification, labeling, protection, monitoring, audit. This cycle repeats continuously, not in a single pass.
For a phased deployment, the following order minimizes false positives and user blocking:
- Map assets via the Data Map before any protection policy
- Deploy sensitivity labels in audit-only mode, without blocking
- Activate DLP policies in simulation mode, then analyze reports
- Gradually switch to application mode (effective blocking)
- Expand to Insider Risk Management and Adaptive Protection once the DLP foundation is stabilized
Tip
Follow concrete indicators rather than simply the policy activation rate: number of DLP false positives, volume of manually reclassified content, average eDiscovery processing time. These KPIs better reflect the actual maturity of the governance program.
To dive deeper into technical configuration, official documentation remains the current reference: Microsoft Purview overview and DLP principles on Microsoft Learn.
Key takeaways
- Purview structures governance around three complementary pillars: Data Security, Data Compliance, Data Governance
- Governance (mapping, classification) must precede activation of security policies to avoid false positives
- Most advanced capabilities remain reserved for Microsoft 365 E5, with a more limited base in E3
- Data Map and Data Catalog often fall under capacity-based billing, separate from E3/E5 subscription
- Using Copilot and AI agents requires prior classification of contents to avoid any sensitive data exposure
- A progressive deployment (audit before blocking) limits user friction and false positive incidents
Before extending Purview scope to the entire organization, an audit of licenses in place and existing DLP policies remains the most cost-effective step to avoid unwelcome surprises in both cost and coverage.



