Identra

Solutions / Purview compliance

Microsoft Purview compliance: labels and DLP moved from test to enforcement.

Sensitivity labels are published. DLP rules are drafted. Both are still in test mode because nobody wants to be responsible for the day enforcement flips on and a legitimate business workflow breaks. Identra runs the staged rollout so DLP actually enforces, false-positive rates stay under 2%, and the legal team gets the audit reporting the compliance framework asks for.

Focus
Microsoft Purview (labels, DLP, audit, eDiscovery)
Baseline licence
Microsoft 365 E5 or Compliance E5
Typical duration
6 to 10 weeks
Pricing model
Fixed scope, fixed price per phase

01 / What we configure

Four capability areas across the Purview surface.

  • 01

    Sensitivity label taxonomy

    A short, defensible label set (Public, Internal, Confidential, Restricted) with encryption applied where it matters. Labels flow with the file across Office, SharePoint, OneDrive, Teams and endpoints. Auto-labelling policies classify PII, PHI, financial data and IP without waiting for users to remember.

    PurviewEncryptionAuto-labelling
  • 02

    DLP in enforcement

    DLP rules for regulated data (payment cards, SSN, PHI, source code) covering Exchange, SharePoint, Teams, endpoints and third-party cloud apps via Defender for Cloud Apps. Rules graduate from audit to warn to block through a staged rollout with false-positive tuning at each stage.

    DLPExchangeSharePointTeamsEndpoint
  • 03

    Audit and eDiscovery

    Audit log retention set to the required window (up to 10 years on E5), Advanced Audit enabled for administrator activities, eDiscovery cases and holds configured for the legal team, and search speed benchmarked against realistic query volumes.

    AuditeDiscoveryRetentionLegal hold
  • 04

    Insider risk and communication compliance

    Insider Risk policies tuned for departing users, IP theft indicators and privacy leaks. Communication compliance monitors regulated conversations for harassment, tip-offs and market abuse where required. Both tuned to avoid privacy overreach while catching the material events.

    Insider riskComms compliance

02 / Where Purview lands

Three engagements that started stuck in test mode.

Every one of these had a Purview licence, published labels, and DLP rules that had never been enforced. Same starting point, three different graduations.

General Counsel, US pharmaceutical company

Situation. Labels published a year ago; DLP still in test mode because IT is worried about blocking legitimate business. Legal team has been asked for tighter controls around FDA correspondence.

Outcome. DLP rules for FDA-marked communications moved to enforcement in a staged rollout. False-positive rate below 2% before enforcement flipped. Legal team now has a per-case audit report.

DPO at a UK-headquartered financial services firm

Situation. GDPR data-subject requests take three weeks each because eDiscovery search is untuned and pulls back too much irrelevant content.

Outcome. eDiscovery configured with pre-built templates for GDPR SARs. Search filtered by label and by mailbox scope. Typical SAR now closes in two days.

CISO at a US law firm

Situation. Recent internal review found no matter policy applied to confidential client work: partners moving client files to personal OneDrive before departure.

Outcome. Sensitivity label with encryption on all matter-tagged content. DLP rule blocks moving labelled content out of tenant. Insider Risk policy on departing users triggers HR review.

Next step

Book a scoping call for your Purview engagement.

Thirty minutes on your current label taxonomy, DLP rule set and audit posture. We will send a written scoping note within two business days.