In the SC-900 exam, the Microsoft Purview section focuses heavily on "how to evaluate compliance posture, and how to classify and protect sensitive data." Multiple features come up, but understanding what problem each feature solves makes them easy to remember.
Microsoft Purview Compliance Manager — The Compliance Scoreboard
If you run a restaurant, you need regular health inspections. An inspector comes in and checks refrigerator temperatures, handwashing procedures, ingredient expiration dates, and assigns a score. It's the same for businesses. Tracking how well an organization complies with regulations like GDPR, HIPAA, or ISO 27001 — across hundreds of individual requirements — is no easy task. Microsoft Purview Compliance Manager acts as this "automated health checklist."
Compliance Score
This shows how well the organization currently meets regulatory requirements as a number between 0 and 100. A higher score means lower risk and better compliance posture. When an executive asks "How is our company's security standing?", this single number provides a simple answer.
Assessments
An assessment lets you choose which regulation you want to be scored against. For example, creating a "GDPR Assessment" automatically analyzes how well the organization meets each GDPR requirement item by item. A company that handles medical information can also run a HIPAA Assessment at the same time.
Improvement Actions
This provides a concrete to-do list of what needs to be done to raise the score. For example, "Enabling multi-factor authentication (MFA) for all admin accounts = +15 points" — showing both the score impact and prioritization at a glance. Importantly, improvement actions fall into two categories:
Microsoft-managed actions: Items Microsoft handles automatically (e.g., physical security of data centers) Customer-managed actions: Items the organization must configure itself (e.g., enabling MFA, setting retention policies)
Information Protection — Identify and Safeguard Sensitive Data
If you don't know what's in your company's warehouse or how much of it there is, theft is hard to prevent. Data is no different. Knowing where sensitive data lives and what kind it is is the first step toward protecting it.
Data Classification — Know What's Where
In a company with tens of thousands of employees, how can you know where social security numbers, credit card numbers, and confidential contracts are stored? Microsoft Purview's data classification tools automatically scan and tell you.
Content Explorer
Content Explorer finds items containing sensitive information across the organization's SharePoint, OneDrive, Exchange, and more, and displays them as a list. For example, you can instantly see "how many files containing credit card numbers exist across the entire system and which folders they're stored in."
Activity Explorer
If Content Explorer shows "what exists," Activity Explorer shows "what happened to that data." It tracks activity logs such as when a sensitive file was opened, who copied it, and whether it was sent as an email to the outside.
Sensitivity Labels — Assigning Protection Levels to Data
Official documents are stamped with classifications like "Confidential," "Top Secret," or "Public." Microsoft Purview's Sensitivity Labels apply this kind of protection classification to digital documents.
For example, applying a "Top Secret" label to a document automatically enforces the following:
Encryption: Only authorized individuals can open it Watermark: A "Top Secret — Unauthorized reproduction prohibited" stamp is automatically inserted External forwarding blocked: Cannot be emailed outside the organization Print restriction: Cannot be printed
Sensitivity labels can be applied to Office documents (Word, Excel, PowerPoint), emails, Teams chats, and SharePoint sites. Users can select labels manually, or labels can be applied automatically when sensitive information is detected in the content.
DLP — Preventing Sensitive Data from Leaving
Imagine a bank employee accidentally trying to send a customer's account number to an external email address, and the system stops them with the message: "This email contains personal financial information. External sending requires approval." Wouldn't that be great? DLP (Data Loss Prevention) is exactly what does this.
DLP policies activate automatically when specific types of sensitive information (credit card numbers, social security numbers, medical records, etc.) are detected.
Block: Prevent external sending entirely Warn: Alert the user to the risk and let them decide Encrypt: Allow sending but automatically encrypt the content Notify: Inform the security team that the event occurred
Policy Tips are warning messages displayed on screen when a user attempts a policy-violating action. They provide real-time guidance such as: "This document contains personal information and sharing it externally violates policy."
DLP applies across a variety of channels: Exchange email, SharePoint, OneDrive, Teams messages, and endpoints (file copying on a PC).
Data Lifecycle Management — Retain and Delete
For paper documents, there are clear rules like "retain for 5 years, then shred." Digital data likewise needs a policy for how long to keep it and when to delete it. Retaining data too long creates personal information risk; deleting it too early can destroy legal evidence.
Retention Policies
These rules define how long data should be kept and what to do with it. They operate in three modes:
Retain: Even if a user tries to delete data during the retention period, it is actually preserved Delete: Data is automatically deleted after the period expires Retain then delete: Data is retained for a set period and then automatically deleted
For example, a financial company can apply a "retain transaction records for 7 years, then auto-delete" policy simultaneously to Exchange, SharePoint, and Teams.
Records Management
Documents like contracts, litigation-related materials, and legally required records need more than simple retention policies. Records Management declares such documents as "records" and protects them more strictly.
Items declared as records are restricted from modification or deletion. When the retention period ends, an automatic disposition review process begins. An authorized reviewer must approve the deletion before it actually occurs. This is important for proving "we managed this document according to regulations" in the event of a legal dispute.
Exam Key Points
"Evaluate compliance status as a score" -- Compliance Manager (Compliance Score)
"Specific actions to raise the score" -- Improvement Actions
"Apply protection level to documents (encryption/watermark)" -- Sensitivity Labels
"Prevent sensitive data from leaking externally" -- DLP
"Auto-delete data after a set period" -- Retention Policies
"Restrict document modification/deletion for legal requirements" -- Records Management
"Identify items containing sensitive data" -- Content Explorer
"Track activities related to sensitive data" -- Activity Explorer
Compliance Score = higher is better, DLP = block leakage