Browse all topics

What is Microsoft Purview?

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

Microsoft Purview is the umbrella brand for data security, compliance, and governance in Microsoft 365 — labels, DLP, retention, eDiscovery, insider risk, and the data-governance catalogue. What's in it, how the two halves differ, and where to start.

Microsoft Purview is Microsoft's umbrella brand for everything that governs, protects, and accounts for data — sensitivity labels, data loss prevention, retention, eDiscovery, audit, insider risk, and a data-governance catalogue that reaches beyond Microsoft 365 into databases and other clouds. If Entra ID answers "who can get in", Purview answers "what happens to the data once they're in".

The brand is confusing because it covers two products that started life separately and still feel separate in daily use. This guide maps the whole thing, then tells you where to actually start.

The two Purviews

In 2022 Microsoft merged two brands into one name:

Microsoft 365 compliance (formerly the Microsoft 365 compliance centre, and before that the Security & Compliance Center) became Purview risk and compliance. This is the half most Microsoft 365 admins mean when they say "Purview": sensitivity labels, DLP, retention, eDiscovery, Communication Compliance, Insider Risk Management, audit. It lives at purview.microsoft.com and works on data inside Microsoft 365 — Exchange, SharePoint, OneDrive, Teams.

Azure Purview (a data-governance catalogue for the data-platform world) became Purview data governance: Data Map, Data Catalog, data lineage, scanning of SQL databases, Azure storage, Amazon S3, and other estates. This half is aimed at data engineers and data-platform teams, is priced on consumption rather than per user, and has almost nothing to do with mailbox retention.

Same brand, one portal, two audiences. When someone says "we should look at Purview", the first question is always: which half? The rest of this guide focuses on the risk-and-compliance half, because that's the Microsoft 365 story — the data-governance side is covered separately in the Microsoft Purview Data Map overview.

The four jobs Purview does

The risk-and-compliance workloads cluster into four jobs.

Know and classify your data. Sensitive information types (credit-card numbers, national ID numbers, health records), trainable classifiers, and sensitivity labels that stamp a classification onto files and emails — with encryption and access restrictions that travel with the file. Labels are the foundation almost everything else builds on; the deep dive is in Purview sensitivity labels and the automation story in Purview auto-labelling policies.

Prevent data leaving. Data loss prevention (DLP) watches content in motion — email, Teams chat, files being shared or copied to USB — and blocks, warns, or logs based on policy. Endpoint DLP extends this to actions on Windows and macOS devices. The full picture is in the Purview DLP deep dive.

Keep and dispose of data deliberately. Retention policies and retention labels decide how long content lives and whether users can delete it; Records Management adds declaration, disposition review, and defensible deletion for regulated records. Covered in Purview retention policies explained and Purview records management.

Investigate and account. eDiscovery (Standard and Premium) for legal holds, collections, and review; Audit for the who-did-what-when log across the tenant; Insider Risk Management and Communication Compliance for detecting risky user behaviour and policy-violating communications; Information Barriers for keeping groups of users apart. Start with Purview eDiscovery standard vs premium and Purview audit and retention.

What's in the box at each licence level

Purview licensing follows the E3/E5 split, and the split matters more here than almost anywhere else in Microsoft 365:

  • Microsoft 365 E3 (and Business Premium): manual sensitivity labels, basic DLP for Exchange/SharePoint/OneDrive, org-wide retention policies, eDiscovery Standard, 180-day audit retention.
  • Microsoft 365 E5 (or the E5 Compliance add-on): auto-labelling, endpoint DLP, Teams DLP, adaptive retention scopes, Records Management, eDiscovery Premium, one-year audit retention, Insider Risk Management, Communication Compliance, Information Barriers, Customer Key, Customer Lockbox.

The honest summary: E3 lets you do compliance manually; E5 lets you automate it and investigate properly. Small tenants can live on E3-level Purview for years. Regulated organisations almost always end up needing the E5 tier, and usually only for the subset of users in scope — the step-up pattern from Microsoft 365 E3 vs E5 applies directly.

Purview data governance (Data Map, Catalog) is licensed separately on consumption-based pricing and is not included in any Microsoft 365 suite.

How Purview relates to the rest of the stack

Purview does not stand alone; it is wired into everything:

  • Entra ID provides the identities that labels, DLP, and Information Barriers key off.
  • Defender handles threats; Purview handles data. The two meet in places like Insider Risk (signals from Defender for Endpoint) and DLP alerts surfacing in the Defender portal.
  • Copilot for Microsoft 365 respects sensitivity labels and is the reason label programmes went from "nice governance idea" to urgent in many tenants — Copilot surfaces whatever the user can already access, and labels plus DLP are the primary containment tools. See Microsoft 365 Copilot data security and privacy.
  • Teams, SharePoint, Exchange are where the policies actually land — retention behaves differently per workload, and the operational details live in the per-workload guides.

Where organisations actually start

A recommended order, based on what pays off fastest:

  1. Turn on audit and check retention defaults. Zero user impact, immediate investigative value. Most tenants have this on by default now, but verify.
  2. Deploy a small sensitivity-label taxonomy. Three to five labels (e.g. Public, Internal, Confidential, Highly Confidential), published to everyone, manual labelling first. Resist the 15-label taxonomy the compliance workshop produced — nobody will use it.
  3. Baseline retention policies. One org-wide policy per workload answering "how long do we keep mail / files / Teams messages by default". This forces the conversation with legal that most organisations have postponed for years.
  4. DLP in audit mode. Start with the obvious sensitive-info types for your jurisdiction, watch what fires for a few weeks, then enforce on the noisy-but-real policies.
  5. Then the E5 tier — auto-labelling, Insider Risk, eDiscovery Premium — once the basics are embedded and someone owns the alerts.

The single most common Purview failure mode is buying E5 Compliance, running a workshop, publishing forty policies in enforce mode, and drowning the helpdesk. Policies in audit mode first, always.

The short version

Purview is one brand over two products: Microsoft 365 risk and compliance (labels, DLP, retention, eDiscovery, audit, insider risk) and a consumption-priced data-governance catalogue for the wider data estate. For Microsoft 365 work, the compliance half is what you care about.

E3 gives you the manual versions; E5 gives you automation and investigation. Start with audit, a small label taxonomy, and baseline retention — in audit mode — before touching the advanced workloads. And when someone says "Purview" in a meeting, ask which half they mean before agreeing to anything.

Frequently asked questions

What is Microsoft Purview?
One brand covering two products: the Microsoft 365 risk-and-compliance stack (sensitivity labels, DLP, retention, eDiscovery, audit, insider risk) and a separate data-governance catalogue (Data Map, Data Catalog) for databases and other clouds. When someone says Purview in a meeting, ask which half they mean before agreeing to anything.
Is Purview included in Microsoft 365?
The risk-and-compliance half is, at a level that depends on your SKU — E3 and Business Premium get the manual basics, E5 or the E5 Compliance add-on gets automation and investigation. The data-governance half is licensed separately on consumption pricing and is not included in any Microsoft 365 suite.
What do I get with E5 Purview that E3 doesn't have?
Auto-labelling, endpoint and Teams DLP, adaptive retention scopes, Records Management, eDiscovery Premium, one-year audit retention, Insider Risk Management, Communication Compliance, Information Barriers, Customer Key, and Customer Lockbox. The honest summary: E3 lets you do compliance manually; E5 lets you automate it and investigate properly.
Where should we start with Purview?
Verify audit is on, deploy a small sensitivity-label taxonomy (three to five labels, manual first), set baseline retention policies per workload, and run DLP in audit mode before enforcing anything. The most common failure mode is publishing forty policies in enforce mode after a workshop and drowning the helpdesk.

Further reading

Spot something wrong or want a topic covered? Send it through the contact form.