What's changed: Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 2 (Domain 2 "Data protection and governance": Purview = Information Protection/sensitivity labels, DLP, Insider Risk, Communication Compliance, DSPM for AI, Data Lifecycle Management/classification; Copilot data security = within existing permissions/Microsoft Graph grounding/overlap of permissions-Purview-Defender/responsible AI; risk identification and oversharing = Compliance Manager/Data-Activity Explorer/DLP alerts/eDiscovery Content search/data access governance report/SharePoint Advanced Management restricted site access)
2.1Data protection with Microsoft Purview
Understand the key Microsoft Purview capabilities (Information Protection and sensitivity labels, Data Loss Prevention (DLP), Insider Risk Management, Communication Compliance, DSPM for AI, Data Lifecycle Management) plus data classification and retention.
Microsoft Purview is a set of solutions to discover, classify, protect, and govern organizational data. Because Copilot generates answers across the data a user can access, whether sensitive data is properly classified and protected directly affects safe Copilot use. For AB-900, map each Purview capability to its purpose.
2.1.1Key Purview capabilities
- Information Protection / sensitivity labels: classify data (e.g., Confidential) and apply encryption, access restriction, and watermarks.
- Data Loss Prevention (DLP): detect and block unintended sharing/sending of sensitive info like credit card numbers.
- Insider Risk Management: detect signs of data exfiltration or misconduct by internal users.
- Communication Compliance: detect inappropriate language or policy violations in chat/email.
- DSPM for AI: visualize and manage sensitive-data risk and usage by Copilot and AI apps.
- Data Lifecycle Management / retention: retain data or delete it at expiry, preventing over-retention or premature deletion.
2.1.2Data classification
Protection starts with data classification. Trainable classifiers and sensitive information types (patterns like credit cards, national IDs) automatically identify data and determine what gets sensitivity labels, DLP, or retention. The more accurate the classification, the more precise the protection of data Copilot handles.
| Goal | Purview capability | Key point |
|---|---|---|
| Classify and protect sensitive data | Information Protection / sensitivity labels | Encryption, access restriction, watermarks |
| Prevent leakage of sensitive info | DLP | Detect/block sharing/sending |
| Detect insider risk signs | Insider Risk Management | Exfiltration/misconduct detection |
| Detect inappropriate comms | Communication Compliance | Detect chat/email violations |
| Visualize Copilot/AI data risk | DSPM for AI | Sensitive-data use and risk |
| Manage retention/deletion | Data Lifecycle Management | Retention labels/policies |
Watch the mix-ups: (1) sensitivity labels (classify and apply protection) vs retention labels (control retention/deletion). (2) DLP (prevent leakage outward) vs Insider Risk Management (detect internal user behavior). (3) DSPM for AI (visualize Copilot/AI data risk) is AI-specific posture.
Common: requirement → Purview capability. E.g., "classify a doc as confidential and encrypt" = sensitivity labels; "stop external sending of card numbers" = DLP; "detect mass downloads by a departing employee" = Insider Risk Management; "detect inappropriate Teams messages" = Communication Compliance; "understand risk of sensitive data Copilot touches" = DSPM for AI; "retain email then delete after a period" = Data Lifecycle Management/retention.
2.1.3Section summary
- Purview = discover/classify/protect/govern data; a prerequisite for safe Copilot use
- Information Protection/sensitivity labels, DLP, Insider Risk, Communication Compliance, DSPM for AI, Data Lifecycle Management (retention)
- Data classification (sensitive info types / trainable classifiers) is the starting point
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which Purview capability detects and blocks unintended external sharing/sending of sensitive info like credit card numbers?
Q2. Which classifies documents (e.g., Confidential) and applies encryption, access restriction, and watermarks?
Q3. Which Purview capability visualizes and manages sensitive-data risk and usage by Copilot and AI apps?
Q4. Which detects signs of data exfiltration by internal users, such as mass downloads by a departing employee?
Q5. Which retains data for a period and deletes it at expiry, preventing over-retention or premature deletion?
Q6. Which Purview capability detects inappropriate language or policy violations in Teams chat and email?

