Compliance
Purview
Microsoft Purview
Microsoft Purview is Microsoft's unified family of data governance, risk, and compliance tools, covering the Microsoft 365 estate, Azure data services, and, increasingly, third-party and multicloud sources through its data map and connector framework.
Why Purview matters in a Microsoft estate
Purview matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How Purview shows up in practice
It was brought together under a single portal and licensing structure after Microsoft consolidated what were previously separate compliance centre and Azure Purview products into one brand. Under that umbrella sit a set of distinct capabilities that are often referred to individually and are frequently the actual point of interest rather than "Purview" as a whole: sensitivity labels for classifying and protecting content based on data type and business impact, retention labels and policies for keeping or disposing of content in line with legal and regulatory requirements, eDiscovery for identifying and collecting content relevant to legal matters and investigations, insider risk management for detecting potentially risky user activity, Data Loss Prevention (DLP) for stopping sensitive information leaving through email, chat, or file sharing, audit for capturing and searching the activity log across Microsoft 365 workloads, and information barriers for restricting communication between defined groups of users.
This breadth is also the source of the most common practical confusion: Purview features are split across Microsoft 365 E3, E5, A5, and standalone add-on SKUs, so a specific capability, such as Premium eDiscovery, advanced audit with longer retention and higher-bandwidth access to the Management Activity API, or automatic sensitivity label classification, may not actually be available or fully functional in a given tenant's current licensing even though the Purview portal itself is visible to every administrator.
For organisations working towards ISO/IEC 27001, ISO 22301, SOC 2, or UK GDPR-driven data protection obligations, Purview is frequently the operational engine behind the paper policy: retention labels implement the documented records retention schedule, sensitivity labels implement the data classification policy, DLP policies implement the acceptable use and data handling controls, and audit and eDiscovery together provide the evidence trail an auditor or regulator will ask to see. The practical risk in Purview deployments is less about the tools' capability and more about governance discipline: label taxonomies that grow uncontrolled, retention policies that conflict with each other across overlapping scopes, or DLP rules tuned so loosely they generate alert fatigue and get ignored. All of these point to the same underlying lesson that Purview is a policy enforcement engine, not a substitute for the organisation actually deciding, documenting, and periodically reviewing what its data governance rules should be.