Microsoft Learn references
Microsoft Purview Field Guides: The Complete Collection
Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.
Part 1: Insider Risk Management
Core overview
- Microsoft Purview Insider Risk Management, Solution overview
- Learn about Insider Risk Management
- Plan for Insider Risk Management
- Get started with Insider Risk Management
Policies and templates
- Create and manage Insider Risk Management policies
- Learn about Insider Risk Management policy templates
- Limits in Insider Risk Management
- Configure policy indicators in Insider Risk Management
AI and agents
- Pay-as-you-go billing models in Microsoft Purview
- Manage and monitor Microsoft Purview pay-as-you-go billing usage
Settings and connectors
- Insider Risk Management settings: Analytics
- Set up a connector to import HR data
- Assign permissions in Insider Risk Management
- Learn about collection policies
Analytics and tuning
- Insider Risk Management settings: Intelligent detections
- Insider Risk Management settings: Inline alert customization
- Insider Risk Management settings: Global exclusions
- Insider Risk Management settings: Detection groups
- Best practices for alert tuning in Insider Risk Management
- Insider Risk Management reports
Adaptive Protection
Investigation and cases
- Investigate Microsoft Purview Insider Risk Management activities
- Take action on Insider Risk Management cases
- Insider Risk Management Data risk graph
- Get started with the Triage Agent in Insider Risk Management
Forensic evidence
- Learn about Insider Risk Management forensic evidence
- Get started with Insider Risk Management forensic evidence
- Manage Insider Risk Management forensic evidence
- Onboard Azure Virtual Desktop session hosts to forensic evidence
Privacy
Newer / preview
Adjacent products (referenced throughout)
- Microsoft Purview Data Loss Prevention overview
- Data Loss Prevention policy reference
- Microsoft Purview Information Protection (sensitivity labels)
- Learn about eDiscovery
- Microsoft Purview Communication Compliance
- Microsoft Defender for Endpoint advanced features
- Conditional Access: Insider risk based policy
- Microsoft Tech Community, Purview blog
Licensing references
Part 2: Data Loss Prevention
Core overview and planning
- Learn about data loss prevention
- Plan for data loss prevention
- Design a DLP policy
- Create and deploy a DLP policy
Policy reference, conditions, and actions
- DLP policy reference
- DLP conditions and actions in Exchange
- Sensitivity label as a condition in DLP policies
- Use notifications and policy tips
- Reference for DLP policy tips
- Configuration best practices for mail flow rules
- How mail flow rules are applied to messages
Detection and classification
- Restrict access to encrypted content (encryption and sensitivity labels)
- Sensitive information type limits
- Test a sensitive information type
- Increase classifier accuracy
- Reduce false positives (deployment models)
- Prevent guest access to files while DLP rules are applied (sensitive by default)
Workloads
Endpoint DLP
- Learn about Endpoint DLP
- Get started with Endpoint DLP
- Configure endpoint DLP settings
- Files that Endpoint DLP does not scan
- Copy matched items in Endpoint DLP
- Auto-quarantine for OneDrive in Endpoint DLP
- Learn about just-in-time protection in Endpoint DLP
- Get started with just-in-time protection
- Learn about DLP for Chrome and Firefox
- Get started with the Purview extension for Chrome
Device onboarding
- Device onboarding overview
- Configure device proxy for onboarding
- Onboard devices using a local script
- Onboard devices using Microsoft Intune
- Device control overview (Defender for Endpoint)
- Enrolling devices vs. onboarding devices
Non-Microsoft cloud apps (Defender for Cloud Apps)
- Use DLP policies for non-Microsoft cloud apps
- Defender for Cloud Apps data protection policies
- Connect apps for visibility, protection, and governance
- File governance actions
- Content inspection for protected files
- Protect Box
- Defender for Cloud Apps editions for Office 365
Adaptive Protection
- Learn about Adaptive Protection in DLP
- Help dynamically mitigate risks with Adaptive Protection
- Adaptive Protection configuration guide
Investigation, alerts, and reporting
- Learn about DLP alert investigation
- Get started with DLP alerts
- Investigate DLP alerts with Defender XDR
- Configure email notifications in Defender XDR
- Activity explorer
- Export audit log records
- Insider Risk Management: share data with other Microsoft solutions
Simulation and troubleshooting
- Learn about simulation mode
- Get started with simulation mode
- Troubleshoot endpoint DLP device and policy sync
- DLP policies do not work as expected
- DLP policy tips troubleshooting
- Diagnose DLP policy tip display issues
- SharePoint Online data residency migration
PowerShell and Graph
- Connect to Security & Compliance PowerShell
- Exchange Online PowerShell V2
- App-only authentication for Exchange Online PowerShell
- New-DlpCompliancePolicy
- New-DlpComplianceRule
- Set-DlpCompliancePolicy
- Export-ActivityExplorerData
- Get-DlpIncidentDetailReport
- Test-MgBetaInformationProtectionDataLossPreventionPolicy
- Microsoft Graph data security and governance overview
- Microsoft Purview SDK documentation overview
Licensing
- Microsoft Purview service description
- Microsoft 365 security & compliance licensing guidance
- Microsoft 365 enterprise subscriptions page
- Layering content and context (Australian Government PSPF label publishing)
Part 3: Sensitivity Labels and Data Classification
Core overview
- Learn about sensitivity labels
- Get started with sensitivity labels
- Microsoft Purview Information Protection (sensitivity labels)
- Data classification and labels (data classification framework)
Taxonomy and label scheme
- Create and configure sensitivity labels
- Migrate to the new sensitivity label scheme
- Default sensitivity labels and policies
- Secure by default deployment model
Auto-labeling
Encryption and content marking
- Configure usage rights for the Azure Rights Management service
- Configure encryption super users
- Enable co-authoring for files encrypted with sensitivity labels
Message encryption (OME / AME)
- Microsoft Purview Message Encryption
- Set up new Message Encryption capabilities
- Message encryption FAQ
- Compare versions of message encryption
- Define mail flow rules to encrypt email messages
- Add your organization's brand to encrypted messages
- Manage Microsoft Purview Message Encryption
- Advanced Message Encryption
- Set an expiration date for email encrypted by Advanced Message Encryption
- Revoke email encrypted by Advanced Message Encryption
- New-OMEConfiguration
- Set-OMEMessageRevocation
Container labeling and workloads
- Use sensitivity labels to protect content in Teams, groups, and sites
- Sensitivity labels for Microsoft Teams
- Power BI implementation planning: information protection
Clients, file types, and the scanner
- Manage sensitivity labels in Office apps
- Minimum versions for sensitivity labels in Office apps
- Enable sensitivity labels for files in SharePoint and OneDrive
- Learn about the information protection scanner
- Information protection scanner prerequisites
- Microsoft Office 2010 Filter Packs (Office iFilter)
- Microsoft 365 Apps administrative template files
- Microsoft Purview Information Protection client download
DLP, Insider Risk, and Copilot
- Use sensitivity labels as conditions in DLP policies
- Data loss prevention policy reference
- Learn about Advanced label-based protection for files on devices
- Help dynamically mitigate risks with Adaptive Protection
- How data is protected and audited in Microsoft 365 and Microsoft 365 Copilot
Adjacent products
Licensing
Part 4: Data Lifecycle and Records Management
Core overview
- Learn about retention policies and retention labels
- Learn about records management
- Microsoft Purview data governance overview
Settings, scopes, and limits
- Settings for retaining and deleting content
- Adaptive scopes for retention and records management
- Limits for retention policies and retention label policies
- Learn about the principles of retention and precedence (flowchart)
- How a retention label is applied and its retention enforced (flow)
Policies and labels
- Create and configure retention policies
- Create retention labels for data lifecycle management
- Publish retention labels and apply them in apps
- Automatically apply a retention label
Workloads
- How retention works for Exchange
- How retention works for SharePoint and OneDrive
- How retention works for Microsoft Teams
- Manage retention policies for Microsoft Teams
- How retention works with Microsoft Copilot and AI apps
- Recoverable Items folder in Exchange Online
- Mailbox retention hold in Exchange Online
Records management and disposition
- Declare records by using retention labels
- Use record versioning
- Get started with records management
- File plan manager
- Start retention when an event occurs (event-driven retention)
- Disposition of content
- Use Preservation Lock to restrict changes to policies
Priority cleanup
Investigation and auditing
Getting started, portal, and trials
- Get started with data lifecycle management
- Learn about the Microsoft Purview portal
- Learn about the Microsoft Purview Suite trial
- Try or buy a Microsoft 365 for business subscription
- Set up the Microsoft 365 trial (Defender XDR evaluation lab)
Permissions and licensing
- Permissions in the Microsoft Purview portal
- Microsoft Purview service description
- Microsoft Purview billing models
PowerShell
- Connect to Security & Compliance PowerShell
- Connect-IPPSSession reference
- New-RetentionCompliancePolicy reference
- New-RetentionComplianceRule reference
- Set-RetentionCompliancePolicy reference
- New-ComplianceTag reference
- New-AdaptiveScope reference
- Retention cmdlets for older and newer locations
- Create and publish retention labels by using PowerShell
Troubleshooting
- Resolve errors in retention and retention label policies
- Auto-apply retention label does not apply to messages
- Exclude or remove sites from a retention policy
Part 5: Audit, Alerts, and Investigation
Audit core
- Search the audit log
- Learn about auditing solutions in Microsoft Purview
- Turn auditing on or off
- Investigate compromised accounts using auditing data
- Audit logging for Copilot and AI activities
Retention, export, and troubleshooting
- Manage audit log retention policies
- Export, configure, and view audit log records
- Search the audit log to investigate common support issues
Mailbox auditing
Explorers and classification
DLP and alerts
- Learn about data loss prevention
- Get started with the data loss prevention alerts dashboard
- Alert policies in the Microsoft Defender portal
Insider Risk and Communication Compliance
- Insider Risk Management settings: Privacy
- Share Insider Risk Management data with other solutions
- Create and manage Communication Compliance policies
eDiscovery and Content Search
DSPM for AI
- Microsoft Purview Data Security Posture Management for AI (classic)
- Learn about Data Security Posture Management
- Considerations for deploying DSPM for AI
- DSPM task mapping
- Microsoft Purview data security and compliance protections for Microsoft 365 Copilot
- Supported AI sites and other AI apps
- Permissions for Microsoft Purview AI scenarios
Licensing references
Part 6: eDiscovery
Core overview
- Learn about eDiscovery, Features and capabilities
- Get started with eDiscovery
- Learn about eDiscovery features and components
- Learn about the eDiscovery workflow
Permissions and roles
Settings
- Configure general settings in eDiscovery
- Case settings in eDiscovery
- Learn about search and analytics settings in eDiscovery cases
Licensing and billing
Limits
Searching and queries
- Create a search for a case in eDiscovery
- Use Keyword Query Language to create search queries in eDiscovery
- Partially indexed items in eDiscovery
- Advanced indexing in eDiscovery
Holds and preservation
Review sets, analytics, and decryption
- Manage review sets in eDiscovery
- Add search results to a review set in eDiscovery
- Decryption in eDiscovery
Export and production
Predictive coding (legacy, now scoped to 21Vianet)
Auditing
Automation (Graph and PowerShell)
Portal
Part 7: Communication Compliance
Core overview
- Learn about Communication Compliance
- Communication Compliance solution overview
- Plan for Communication Compliance
- Get started with Communication Compliance
Policies and templates
Detection and classifiers
Channels and sources
Review and alerts
- Best practices for managing alert volume
- Use Communication Compliance reports and audits
- Investigate and remediate Communication Compliance alerts
- Use notification templates in Communication Compliance
Permissions and privacy
- Assign permissions in Communication Compliance
- Insider Risk Management and Communication Compliance privacy guide
PowerShell
- Connect to Security & Compliance PowerShell
- Connect-IPPSSession
- App-only authentication for unattended scripts
- New-SupervisoryReviewPolicyV2
- New-SupervisoryReviewRule
- Get-SupervisoryReviewPolicyV2
- Set-SupervisoryReviewPolicyV2
- Get-SupervisoryReviewRule
- Get-SupervisoryReviewActivity
- Get-SupervisoryReviewReport