Chapter 4 · Microsoft Compliance Solutions·v2.0.0·Updated 6/3/2026·~8 min
What's changed: Deepened SC-900 Chapter 4 to the AZ-900 baseline (Service Trust Portal vs Purview/Compliance Manager with shared-responsibility mapping & table; sensitivity labels/DLP/retention classify→protect→lifecycle flow & table; insider risk/eDiscovery/audit table & scenario; FAQ, traps). Localized 3 figures
4.2Information Protection and Data Lifecycle Management
Key points
Understand sensitivity labels, data loss prevention (DLP), and retention policies for classifying, protecting, and retaining/deleting sensitive data.
Data is protected by "classify → protect → retain/delete for the right period." Microsoft Purview provides these capabilities.
4.2.1Key capabilities
- Sensitivity labels: classify data/email and apply protection by label—encryption, watermarks, usage restrictions (e.g., Confidential). Labels travel with the file, so protection persists even outside the org.
- Data loss prevention (DLP): detect and block improper sharing/sending of sensitive info (credit card or ID numbers) across email, Teams, SharePoint, etc.
- Retention policies / labels: keep data for the required period and delete it when no longer needed—addressing both legal retention duties and "keeping too much" risk.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

