What's changed: Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 2 (Domain 2 "Data protection and governance": Purview = Information Protection/sensitivity labels, DLP, Insider Risk, Communication Compliance, DSPM for AI, Data Lifecycle Management/classification; Copilot data security = within existing permissions/Microsoft Graph grounding/overlap of permissions-Purview-Defender/responsible AI; risk identification and oversharing = Compliance Manager/Data-Activity Explorer/DLP alerts/eDiscovery Content search/data access governance report/SharePoint Advanced Management restricted site access)
2.3Data protection risks and SharePoint oversharing
Understand ways to identify risks—Compliance Manager, Purview Data/Activity Explorer, Insider Risk Management, DLP alerts, Communication Compliance violations, DSPM for AI, eDiscovery Content search—and how to identify SharePoint oversharing (data access governance report, SharePoint Advanced Management restricted site access).
To deploy Copilot safely, it is important to identify where sensitive data is and its risks and to remediate oversharing. Microsoft Purview and SharePoint provide visibility and investigation tools for this.
2.3.1Ways to identify risk
- Compliance Manager: assess conformance to regulations, risks, and recommended improvements.
- Data Explorer / Activity Explorer: see where sensitive info is and user activities like labeling and access.
- DLP alerts: review and respond to events where sensitive sharing/sending was blocked/warned.
- Communication Compliance violations: review policy violations in inappropriate communications.
- DSPM for AI: discover and manage sensitive-data use and risk by Copilot/AI.
- eDiscovery Content search: search across files and emails for investigations.
2.3.2Identifying and fixing SharePoint oversharing
To keep Copilot from exposing sensitive data, find and fix SharePoint oversharing (over-broad sharing). The data access governance (DAG) report surfaces widely shared / sensitivity-labeled sites. Additionally, SharePoint Advanced Management provides advanced controls such as restricted site access (protecting specific sites from anyone but allowed users), reducing oversharing risk.
| Goal | Tool | Key point |
|---|---|---|
| Assess compliance and risk | Compliance Manager | Recommended improvements |
| See sensitive data location/activity | Data/Activity Explorer | Classification and user activity |
| Search across for investigation | eDiscovery Content search | Search files/emails |
| Copilot/AI data risk | DSPM for AI | Discover/manage AI activity |
| Find oversharing sites | Data access governance report | Widely shared/labeled sites |
| Advanced site access limits | SharePoint Advanced Management (restricted site access) | Reduce oversharing |
Scenario: pre-Copilot review. Use the data access governance report to find widely shared sites → remediate with restricted site access in SharePoint Advanced Management → protect sensitive info with sensitivity labels / DLP → continuously monitor Copilot/AI data use with DSPM for AI. This narrows down "data Copilot must not touch."
Common: requirement → tool. E.g., "find widely shared sites" = data access governance report; "protect specific sites from all but allowed users" = restricted site access (SharePoint Advanced Management); "assess compliance and risk" = Compliance Manager; "search files/emails for an investigation" = eDiscovery Content search; "understand Copilot/AI sensitive-data use" = DSPM for AI.
2.3.3Section summary
- Identify risk: Compliance Manager / Data-Activity Explorer / DLP alerts / Communication Compliance / DSPM for AI / eDiscovery Content search
- Oversharing: find via data access governance report → fix via SharePoint Advanced Management (restricted site access)
- Before deploying Copilot, review sensitive-data location, risk, and oversharing
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which report surfaces widely shared or sensitivity-labeled SharePoint sites?
Q2. Which SharePoint Advanced Management feature protects specific sites from all but allowed users, reducing oversharing?
Q3. Which Purview tool assesses conformance to regulations, risks, and recommended improvements?
Q4. Which Purview eDiscovery capability searches across files and emails for an investigation?
Q5. Which is part of the most appropriate pre-Copilot review?
Q6. Which is used to discover and manage how Copilot or AI uses sensitive data?

