Solutions / Purview compliance
Microsoft Purview compliance: labels and DLP moved from test to enforcement.
Sensitivity labels are published. DLP rules are drafted. Both are still in test mode because nobody wants to be responsible for the day enforcement flips on and a legitimate business workflow breaks. Identra runs the staged rollout so DLP actually enforces, false-positive rates stay under 2%, and the legal team gets the audit reporting the compliance framework asks for.
- Focus
- Microsoft Purview (labels, DLP, audit, eDiscovery)
- Baseline licence
- Microsoft 365 E5 or Compliance E5
- Typical duration
- 6 to 10 weeks
- Pricing model
- Fixed scope, fixed price per phase
01 / What we configure
Four capability areas across the Purview surface.
- 01
Sensitivity label taxonomy
A short, defensible label set (Public, Internal, Confidential, Restricted) with encryption applied where it matters. Labels flow with the file across Office, SharePoint, OneDrive, Teams and endpoints. Auto-labelling policies classify PII, PHI, financial data and IP without waiting for users to remember.
PurviewEncryptionAuto-labelling - 02
DLP in enforcement
DLP rules for regulated data (payment cards, SSN, PHI, source code) covering Exchange, SharePoint, Teams, endpoints and third-party cloud apps via Defender for Cloud Apps. Rules graduate from audit to warn to block through a staged rollout with false-positive tuning at each stage.
DLPExchangeSharePointTeamsEndpoint - 03
Audit and eDiscovery
Audit log retention set to the required window (up to 10 years on E5), Advanced Audit enabled for administrator activities, eDiscovery cases and holds configured for the legal team, and search speed benchmarked against realistic query volumes.
AuditeDiscoveryRetentionLegal hold - 04
Insider risk and communication compliance
Insider Risk policies tuned for departing users, IP theft indicators and privacy leaks. Communication compliance monitors regulated conversations for harassment, tip-offs and market abuse where required. Both tuned to avoid privacy overreach while catching the material events.
Insider riskComms compliance
02 / Where Purview lands
Three engagements that started stuck in test mode.
Every one of these had a Purview licence, published labels, and DLP rules that had never been enforced. Same starting point, three different graduations.
General Counsel, US pharmaceutical company
Situation. Labels published a year ago; DLP still in test mode because IT is worried about blocking legitimate business. Legal team has been asked for tighter controls around FDA correspondence.
Outcome. DLP rules for FDA-marked communications moved to enforcement in a staged rollout. False-positive rate below 2% before enforcement flipped. Legal team now has a per-case audit report.
DPO at a UK-headquartered financial services firm
Situation. GDPR data-subject requests take three weeks each because eDiscovery search is untuned and pulls back too much irrelevant content.
Outcome. eDiscovery configured with pre-built templates for GDPR SARs. Search filtered by label and by mailbox scope. Typical SAR now closes in two days.
CISO at a US law firm
Situation. Recent internal review found no matter policy applied to confidential client work: partners moving client files to personal OneDrive before departure.
Outcome. Sensitivity label with encryption on all matter-tagged content. DLP rule blocks moving labelled content out of tenant. Insider Risk policy on departing users triggers HR review.
03 / Related solutions