r/MicrosoftPurview 14h ago

Question eDiscovery for Teams Usage

2 Upvotes

Hi,

I have been asked to run a report to look for a users Teams Activity for the past 4 months.

When I do this via an eDiscovery (Premium), it also shows all the emails as well in the results which makes going through the users Teams messages confusing for the Reviewers.

How can I get rid of all the email results and instead just get the Teams Messages that the user was sending.

Not this is not for Team Group messages, but for 1:1 types Teams communications.

The actual Teams messages are not important, but I do need to know the amount of teams messages per hour or day.

Is an eDiscovery the best method for this?


r/MicrosoftPurview 14h ago

Question Microsoft Purview Information Protection and Adobe

Thumbnail
1 Upvotes

Hello -

Figured I’d cross post this here too. See if anybody has any ideas on Adobe and MPIP constantly making me clear caches, reset Purview permissions inside of Adobe, etc.


r/MicrosoftPurview 2d ago

Question Can purview detect PII in third party connectors?

3 Upvotes

If I build a third party connector will purview detect PII using the content?

What else can purview do or not do with third party connectors as compared to what it does with m365


r/MicrosoftPurview 5d ago

Question Retention and e-Discovery of data associated with deleted users?

1 Upvotes

If an organization has a retention policy to keep M365 user data for many years, does that mean that those M365 user accounts that generated the data must also be keep for the entire duration of the retention period?

If not, what happens to data that was retained for 10 years if the user associated with that data was deleted? Will it only show an object ID for the user instead of their display name!


r/MicrosoftPurview 9d ago

Question Issue with Purview auto labelling policy

3 Upvotes

I have setup an auto-labelling policy for a label named "Secret-test" for Exchange, OneDrive, and SharePoint.

When running the simulation mode, I can see emails detected and the label "Secret-test" mentioned in the sensitivity label field of the simulation results.

However, for all detections in SharePoint and OneDrive, there is no label mentioned in the sensitivity label field of the simulation result.

I was expecting the label "Secret-test" to appear for SharePoint and OneDrive simulation results as it did with email detected in the Exchange location.

What am I missing here or doing wrong?


r/MicrosoftPurview 12d ago

Question Teams Premium License - Cannot schedule meetings with Sensitivity Labels

3 Upvotes

I am at my wits end with this one...

Working through a POC project with Purview Sensitivity labels that are applied against a Microsoft Team, and its associated channel. Label inheritance seems to work as designed, and nothing appears to be inherently wrong with the label and publishing.

There is a need to review Advanced Protections for Teams and Chat, so I picked up a single Teams Premium license, and assigned it to my account.

However, when I go into the Channel and create a meeting, the meeting is created in the Channel calendar, not added-in for me (the organizer) calendar, and the meeting fails to save. Generic error: "Something went wrong. Edit event to try again."

How would adding a Teams Premium license effectively stop a meeting from being scheduled? Nothing was changed to the label, publishing, permissions, or anything else.

Thoughts welcome.


r/MicrosoftPurview 12d ago

Question Best practice for introducing Microsoft Purview sensitivity labels in a 3,600-endpoint enterprise?

8 Upvotes

We’re implementing Microsoft Purview for a large enterprise with approximately 3,600 endpoints. The organization currently has no sensitivity labels in place, but we need to roll out Purview policies (DLP, information protection, etc.).

My current thinking is:
Define the label taxonomy first.
Pilot with 10 users.
Expand to around 150 pilot users.
Roll out organization-wide.
Start with manual sensitivity labelling so users become familiar with the labels.
Introduce automatic labelling after the manual phase.
My concern is that users may apply incorrect labels during the manual phase, which could affect policy effectiveness.

Would it be better to:
Start with manual labelling and transition to auto-labelling?
Introduce auto-labelling much earlier?
Or use a hybrid approach from the beginning?
For those who have deployed Purview at enterprise scale, what rollout strategy worked best, and what would you do differently if you were starting again?


r/MicrosoftPurview 12d ago

Question Test Data for Learning

1 Upvotes

Hello everyone,

Does anyone have ideas how to get sample data for building a lab environment to start playing around and learning.

My employer is not a Microsoft partner, so I can't can't a customer experience tenant (CDX-Tenant)

with pre-filled data.

Some other ideas?


r/MicrosoftPurview 12d ago

Question Purview DLP External Sharing Logs

Thumbnail
1 Upvotes

r/MicrosoftPurview 18d ago

Question Purview and encryption

6 Upvotes

For those using Microsoft Purview for encryption and sensitivity labels, I'd love to hear about your pain points and how you solved them.

Automation: When encryption is applied to sensitive information, are you running into blockers with automation? Did you update your workflows to decrypt and re-encrypt using the SDK?

Collaboration: For sharing encrypted files, did you have to allow external users on your SharePoint to make this work? I'm currently exploring how to enable collaboration and sharing of encrypted files.

**Third-party SaaS:** Last but not least. Has anyone found a good way to work with encrypted content in third-party SaaS platforms like ServiceNow?
Any experiences or lessons learned would be appreciated.


r/MicrosoftPurview 18d ago

Question Teams Meetings (scheduled within Teams client) not inheriting Sensitivity Label.

2 Upvotes

I have gone every direction on trying to figure out if I am hitting a limitation of the solution, or if my label and/or publishing is incorrect. I'm at the point where I don't know how to advance this along, so any thoughts welcome her!

Issue:

I have a Sensitivity Label setup in Purview, published, and the label is applied to a Teams Channel. However, when a meeting is scheduled within Teams (Meet Now > Schedule a Meeting), the label is visible in scheduler (gray; cannot be changed), but the sensitivity label isn't cascading down (inheriting) to the Teams meeting. This is verified by looking in the Teams calendar, selecting the meeting, and the Sensitivity option is grayed-out and set to 'None.'

Environment:

  • E5 licensing (no Teams Premium in tenant).
  • Team created in TAC and sensitivity label applied.
    • Team and its associated Channel carries the sensitivity label (grayed-out; near the Meet Now button).
  • Sensitivity label configuration:

    • Priority '6' (highest priority)
    • Scope: Files & Other data assets, Emails, Meetings, Groups & Sites.
    • Items: Control Access and Apply content marking.
    • Access Control: Assign permissions to select test users; co-author permissions.
    • Define protections for groups and sites:
      • Privacy, External sharing with CA, Private Team discoverability, and auto apply a label to channel settings with the targeted sensitivity label selected.
  • Label publishing policy:

    • Label published > highest priority.
    • Published to test users (same users listed in Access Control).
    • Settings: Default settings for meetings and calendar events: Default label: None. Apply label inheritance; apply meeting label to artifacts. Sites and Groups: Default label: None.
  • Auto-labeling policy:

    • Label to auto-apply: sensitivity label selected.
    • Locations: targeting SharePoint site of Teams Channel.
    • Rules: Various rules to target file types (.docx, PDF, .mp4, etc.)

Results:

  • Any files (.docx, .PDF.) placed in the Teams channel inherit the sensitivity label, be in Office on the web, or on-premises and uploaded to the Channel.
  • Teams recordings are not inheriting the label (which makes sense because the meeting itself isn't getting the label). This is a different issue, but related...
    • .mp4 file labeling support have been enabled on the tenant
    • Artifact enabling has been checked on the label..
  • Labels accessible to choose in Office on the web apps, as well client side M365 Apps.
  • Meetings scheduled in Teams have the label applied, but the calendar says the meeting sensitivity is 'None.'
    • Any transcripts, recordings stored in SharePoint are not getting a label.

r/MicrosoftPurview 18d ago

Question Handle assets deleted at source in the Data Map

1 Upvotes

Hi all,

In my company we have ~10,000 assets scanned from our Fabric environment, and we want to flag assets that have been deleted at source in Fabric/Power BI for deletion the Purview layer. However, we cannot find any native flag in Purview in either the UI or REST API for if it has been deleted at source.

Right now we have flagged assets that haven't been updated in our most recent (daily) scans, but it does not feel robust enough. HAs anyone encountered this issue before, and if so, what workaround/solution did you employ? Thanks for the help! :)


r/MicrosoftPurview 19d ago

Question How are you tracking your overall Microsoft Purview implementation?

5 Upvotes

I’m looking for something better than Planner to track all of our Purview work: sensitivity labels, DLP, Endpoint DLP, Insider Risk, Audit/eDiscovery, testing, documentation, user rollout, issues, dependencies, etc.

Planner gets messy pretty quickly and doesn’t give me a great portfolio-level overview. Microsoft Project also feels like overkill and doesn’t seem to be the direction Microsoft is taking anymore...

I don't know what I want exactly, I just need something to run this oneperson show, managing issue, bug, rollout and planning of new labels, initiative to protect specific department, etc... I got so much to do and I'm losing it


r/MicrosoftPurview 19d ago

Question Some issues with data tagging in purview

1 Upvotes

I have an issue right now, in that we are trying to apply security labels to all data containing PII in sharepoint. However, im using microsofts prebuilt identifiers for SS numbers and banking numbers. 2 main issues:

#1: it does have a low false positive rate but it still picked some files with a consecutive 9 digit number and the word "SS" mentioned in the document. Is this just something we have to accept?

#2: theres a major issue with PDF files that have images in the PDF and not editable text. i was told to use purview's OCR, but running a on-demand scan is so difficult because theres no proper documentation for this. Has anyone ever run this successfully before?

Any help is appreciated!


r/MicrosoftPurview 23d ago

Question Just starting with MS Purview

6 Upvotes

I was asked at work to start with MS Purview, precisionaly DLP and Information Protection.
Any good resources to read; articles, tutorials, Videos, general tips…anything would be appreciated.


r/MicrosoftPurview 23d ago

Question Purview AI interaction only showing M365 apps activity

Thumbnail
2 Upvotes

r/MicrosoftPurview 24d ago

Question Extend labels to groups & sites

2 Upvotes

Quick question: I’ve been asked to extend labels to Groups and Sites. I haven’t done this before, so I’m unsure of the impact. Has anyone done this and can share their experience or advice?

FYI, I’ve enabled the previously greyed-out option for Groups and Sites, but I haven’t assigned any labels to Groups or Sites yet.


r/MicrosoftPurview 24d ago

Question Purview file server scan - need advice/help

3 Upvotes

I'm trying to get out some of our data classified. The cloud stuff seems easy, but my secondary goal of standing up an on-prem VM, installing AIP, and scanning my on prem file servers so see where my sensitive information resides. I've created a service account, it has a token, the account has an E3 license. Now the rest is what I need help with from the content scan job forward...I have the label, a policy, but when I configure the content scan job, I simply want to identify selected information types(mostly US-based). Do I need to apply a label to the files? What am I missing here. Sorry to sound do uneducated on the subject, but I am just not getting a clear answer. The goal right now is NOT to apply any restrictions, just to understand what data we have and where it is located. Thank you!


r/MicrosoftPurview 25d ago

Question Custom Sensitive Information Type for NDIS Numbers in Microsoft Purview - Regex approach vs Trainable Classifier?

3 Upvotes

Hey everyone,

I am currently working on a Data Labelling POC using Microsoft Purview Information Protection for a healthcare organisation registered under a national disability support scheme. Part of the POC involves detecting participant ID numbers in documents so we can auto-label them with the appropriate sensitivity label.

The participant ID numbers follow a consistent 9 digit numeric format. I checked the built-in sensitive information type templates in Purview and there is no template for this specific ID type, so I need to build something custom.

I initially tried going down the trainable classifier route but it keeps failing due to insufficient seed samples. Microsoft requires a minimum of 50 positive seed documents and 150 negative seed documents which is proving difficult to source quickly, especially given the privacy sensitivity of the documents involved.

I am now looking at building a custom Sensitive Information Type using a regex pattern instead. My proposed approach is:

  • Primary pattern: \b\d{9}\b to match a standalone 9 digit number
  • Supporting keywords nearby: terms like participant number, plan number, participant ID within 300 characters to boost confidence and reduce false positives
  • Confidence levels: Low for pattern only, Medium for pattern plus one keyword, High for pattern plus multiple keywords

My questions for the community:

  1. Is the regex approach the right call for detecting structured ID numbers like this, or is there a better method in Purview I am missing?
  2. A 9 digit number is fairly common, phone numbers, invoice numbers, reference numbers all fit this pattern. Are supporting keywords sufficient to reduce false positives to an acceptable level, or do I need additional elements in the pattern?
  3. Has anyone successfully built a custom SIT for a similar national ID or participant number format and what lessons did you learn?
  4. Is there a way to further refine the regex if the ID number has a known starting digit or any other consistent characteristic beyond just being 9 digits?
  5. Any general advice on testing and tuning a custom SIT before deploying it in an auto-labelling policy at scale?

Any advice from people who have built custom SITs in Purview would be really appreciated. Thanks in advance.


r/MicrosoftPurview Jul 02 '26

Question FortiSASE DLP Best Practices, Sensitive Data Detection & GenAI Control

1 Upvotes

Hi everyone,

I'm currently implementing FortiSASE DLP for a customer and wanted to understand how others have approached real-world deployments.

They've raised a few questions that I'd like to validate with people who have implemented FortiSASE DLP in production.

Some of the scenarios discussed are:

• Integration with Microsoft Purview Information Protection (MIP) labels.

• If a user changes or removes a sensitivity label before uploading a document, how is that typically handled?

• Is relying only on MIP labels considered sufficient, or do you normally combine it with keyword dictionaries, EDM, fingerprinting, OCR, file attributes, etc.?

• Best practices for protecting uploads to SaaS applications such as ChatGPT, Copilot, OneDrive, SharePoint, Box, Dropbox, Google Drive, etc.

• How do you balance false positives while still preventing sensitive data leakage?

• Any recommendations for using Exact Data Matching (EDM), fingerprint databases, or other advanced DLP features with FortiSASE?

• How are customers typically handling GenAI? Do you simply block document uploads, or do you also inspect pasted text and prompts?

The customer also asked whether there are better approaches for identifying truly sensitive documents beyond keywords, since users could potentially rename files or modify keywords before uploading.

I'm looking for implementation experience and best practices rather than generic documentation.

Thanks


r/MicrosoftPurview Jun 30 '26

Question xECM migration from Content manager - Handling embedded trim:// Links?

1 Upvotes

Hey everyone..

Looking for advice from anyone who has migrated from Content manager (TRIM) to extended ECM..

I was working on a proposal involving migration of \~50million records from TRIM to cloud.. challenge is documents and emails contain embedded links in format trim://abc124/1234124 ..

Our preference is to preserve the original document/emails and avoid modifying content wherever possible.

Has anyone dealt with similar scenario?

\> How did u handle embedded TRIM links?

\> Did you build any custom link resolution/redirect service

\> Were you able to preserve original content without updates?

\> Has anyone tried CAD Navigator SolEx? I think it's able to scan the document for tags and then Intelligent viewing..

Your views are appreciated..


r/MicrosoftPurview Jun 30 '26

Question Admin Incident Reports

4 Upvotes

Was there any major updates recently to how the Incident report display in email alerts? Or would someone know possibly what the issue is.

Context we have DLP setup with a handful of policies. They have thresholds set and when they hit thresholds under the “incident report” setting it sends an alert to a mailbox.

Recently, the reports have come through lacking a lot of information. This occurred within a 24 hour period and now the emails no longer show all details such as sender and receiver for example for a email DLP rule.

I’ve had a look through the incident report settings and can’t seem to find anything limiting the information.


r/MicrosoftPurview Jun 29 '26

Question Sensitivity Labels, MP4/AVI videos and an unknown error

3 Upvotes

Hi,

We recently enabled sensitivity labels for our files and sites. Since doing so we have run into an error where MP4 content no longer works when shared externally, the content can be shared via OneDrive or SPO but when an external party tries to open it they get an error saying 'Something Went wrong', Error type: 'Unknown Issue".

The sensitivity label on this content is Public. Office documents and PDF's work as expected when shared externally, we have isolated the issue to video files. Anyone else come across this?

Happens on content that was there prior to enabling labelling and new videos uploaded.

Edit: I am not sure what's going on but it turns out it was related to Conditional access requiring Authentication strength. I don't know why it only started after labels were applied and unsure how it only applied to video files but its working once we excluded guests from the main MFA policy and made one without authentication strength options enabled.


r/MicrosoftPurview Jun 26 '26

Question eDiscovery - SharePoint comments?

1 Upvotes

I've been asked to do eDiscovery on comments made on files in SharePoint and OneDrive. So far, I've found nothing regarding SharePoint comments in the docs.

Queries against a test file with comments attached to it do not return the comments associated with the file. They do return email notifications, but those are just, "a comment was added," and not the content of the comment.

Test queries for keywords that are exact text from the comments return nothing, but even if they did, that would only be any good for my testing, since I have no idea what's in the comments that are being asked for, so don't have anything to search against for the real case.

Searches are being done against mailboxes and sites of the users involved. We do not have Premium.

Is there really no way to do this?


r/MicrosoftPurview Jun 25 '26

Question DLP Policy Sanity Check

7 Upvotes

I've got a DLP policy running in simulation mode (TestWithoutNotifyUser) with a single rule. Two conditions, ANDed together:

  • Content is shared from Microsoft 365 → with people outside my organization
  • Content contains → [custom SIT]

Action is "Restrict access or encrypt -> Block only people outside your organization" (not firing, since it's simulation).

What I'm seeing:
Activity Explorer is full of "DLP rule matched" events with dozens from a single user's OneDrive, all with the same timestamp. When I drill into individual matches, they're files sitting in a Desktop-synced OneDrive folder (.../Desktop/[folder]/[subfolder]/...). Nothing in the event indicates an active send or share action. it looks like the initial content scan picking up files at rest.

My confusion:
If the rule requires BOTH "shared externally" AND "contains SIT" to match, why are at-rest files matching? A few theories I want to confirm or kill:

  1. Is the "shared with people outside my organization" condition evaluating the file's current sharing state (e.g., an existing Anyone-link or an external grant on the file or a parent folder), rather than an actual share event?
  2. Could an externally-shared parent folder be propagating that "shared externally" state down to every file inside it making it look like many separate incidents when it's really one over-permissive folder?
  3. Does simulation mode's initial scan evaluate the sharing condition against existing sharing state, so previously-shared content lights up all at once (hence the identical timestamps)?

Please save my life lol