What's changed: Created MS-102 Chapter 5 (domain: Manage compliance by using Microsoft Purview). Information protection (sensitive information types keyword/regex, sensitivity labels classify/encrypt/marking and label policies, Content/Activity explorer), data lifecycle management (retention labels item-level, retention label policies publish/auto-apply, retention policies location-level bulk retain/delete), and DLP (Exchange/SharePoint/OneDrive/Teams workload DLP, policy tips, Endpoint DLP device control, DLP alerts/events/reports). This completes the MS-102 textbook: all 5 chapters / 13 sections.
5.1Information protection
Understand defining sensitive data with sensitive information types, classifying/encrypting/marking with sensitivity labels and label policies, and visibility via Content explorer and Activity explorer.
Information protection flows: "define what is sensitive"→"classify and apply protection"→"visualize the state". Each is a separate feature.
5.1.1Sensitive information types
Sensitive information types (SITs) define patterns of sensitive data like credit card or national ID numbers, detecting via keywords, keyword lists, regular expressions, checksums, and proximity. A SIT is a "detection rule that decides whether something is sensitive"—not protection itself (used as conditions for DLP and auto-labeling).
5.1.2Sensitivity labels and policies
Sensitivity labels classify content (e.g., Confidential, Highly Confidential) and apply protection—encryption, content marking (header/footer/watermark), access restrictions. Publish labels to users/locations via a label policy, setting default/mandatory labels; auto-labeling can use SITs as conditions. Labels "classify and protect"—distinct from SITs (detection definitions).
5.1.3Content explorer and Activity explorer
Content explorer shows the actual content and location of items that are labeled or contain sensitive data. Activity explorer audits label-related activities (apply/change/download). Remember: "what/where the content is" = Content explorer; "what was done" = Activity explorer.
Cues: "detect sensitive data patterns (keyword/regex)" = sensitive information type. "classify and apply encryption/marking" = sensitivity label. "publish to users/locations" = label policy. "content and location of labeled/sensitive items" = Content explorer. "audit label activities" = Activity explorer.
Watch the mix-ups: (1) Sensitive information type (detection definition) vs sensitivity label (classify/protect). (2) Content explorer (content/location) vs Activity explorer (audit of actions). (3) Sensitivity label (classify/encrypt) vs DLP (prevent leakage) vs retention (preserve) are different layers. (4) Labels are published via label policies.
5.1.4Section summary
- Sensitive information types define detection of sensitive data via keywords/regex
- Sensitivity labels classify and apply encryption/marking; published via label policies
- Content explorer = content/location; Activity explorer = audit of label activities
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want a definition that detects credit card number patterns via regex and checksum to flag as sensitive. Best?
Q2. You want to classify a document as Confidential and auto-apply encryption and header/watermark marking. Best?
Q3. You want to make created sensitivity labels available to specific users/locations and set a default label. Best?
Q4. You want to see where labeled/sensitive items actually reside and what their content is. Best?
Q5. You want to audit who applied/changed/downloaded sensitivity labels and when. Best?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

