Smooth Google migration

Migrate from Google Drive to M365 the right way

Learn more
No items found.

Master Hacks: Migrate like a pro

Check out our video series to help you turn migration projects into masterpieces!

Watch now

Table of contents

TL;DR: A tour of what the Purview portal actually does day to day: DLP, sensitivity labels, retention, eDiscovery, auditing, and how to set automated guardrails instead of policing policies by hand. The part worth your time is DSPM and the unified audit log now covering Copilot and AI agent activity.

The Microsoft Purview portal is Microsoft's unified home for data security, data governance, and risk and compliance solutions. It replaced the earlier Microsoft 365 compliance center and the separate Microsoft Purview compliance portal, bringing everything IT admins need into one consistent experience.

It gives IT admins a single place to manage data loss prevention (DLP), sensitivity labels, retention, eDiscovery, auditing, and more, without switching between separate consoles. Let's look at what the Microsoft Purview portal covers and why it matters for today's IT admins.

What is the Microsoft Purview portal?

Compliance and data security requirements span nearly every Microsoft 365 service, so having one centralized place to manage them all makes it far easier for IT admins to keep track of what's happening and act on it. That's what the Microsoft Purview portal is built for.

The portal organizes its capabilities into three areas: Data Security, Data Governance, and Risk & Compliance. Here's what each covers:

1. Data security: Covers data loss prevention (DLP), Information Protection with sensitivity labels, Insider Risk Management, and Data Security Posture Management (DSPM), which gives you a single view of where sensitive data lives and how exposed it is.

2. Data governance: Covers Data Lifecycle Management and Records Management, so you can set retention policies and labels and automatically dispose of content that no longer has business value.

3. Risk & compliance: Covers Compliance Manager, Communication Compliance, eDiscovery, and Audit, helping you track your compliance posture, investigate conduct issues, place legal holds for eDiscovery cases, and respond to legal or regulatory requests.

5 top features of the Microsoft Purview portal

A handful of capabilities tend to matter most day-to-day for admins managing security and compliance in Microsoft 365. Here's a quick look:

1. Data Security Posture Management (DSPM): DSPM gives you a single dashboard for sensitive data risk across your organization. It pulls together signals from DLP, Insider Risk Management, Information Protection, and Data Security Investigations, and includes AI observability views for how sensitive data is used in Microsoft 365 Copilot, agents, and supported AI apps. Availability and depth of coverage depend on licensing, configuration, region support, and required prerequisites.

2. Data Loss Prevention (DLP): DLP policies detect sensitive information, such as personally identifiable information (PII), financial data, or intellectual property, and stop it from being shared, copied, or leaked in ways that violate your policies.

3. eDiscovery: eDiscovery in the Microsoft Purview portal is now a single, unified experience (the older separate Content Search, eDiscovery (Standard), and eDiscovery (Premium) tools were retired at the end of August 2025). It lets you search, hold, and export content across Exchange, SharePoint, OneDrive, and Teams for legal or regulatory purposes, with Premium features such as custodian management and review sets available depending on your license.

4. Auditing and reporting: The unified audit log records activity across Microsoft 365, including Copilot and AI interactions. Audit (Standard) retains records for 180 days by default; Audit (Premium) extends that to one year for core workloads, with add-on licensing available for up to 10 years.

5. Licensing and prerequisites: Microsoft Purview capabilities vary by subscription, add-on licensing, permissions, tenant configuration, and region availability. Features such as Audit Premium, eDiscovery Premium capabilities, DSPM, AI observability, and third-party AI protections may require additional setup before admins see meaningful data or can enforce policies.

What are cloud security guardrails?

Cloud security guardrails are the automated policies and controls that keep data safe by default, rather than relying on people to follow the rules manually. They're a practical way to make governance proactive instead of reactive, and they're worth building into your overall security approach.

Here's how automated guardrails help:

  1. They catch problems early. Continuous monitoring, such as the recommendations surfaced by DSPM, flags suspicious or risky activity as it happens, rather than after the fact.
  1. They let you tailor policies to your organization. You can scope DLP, retention, and access policies to specific roles or teams, so people who handle sensitive data get the right controls without over-restricting everyone else.
  1. They connect to your broader cloud security posture. Purview's data security controls work alongside Microsoft Defender for Cloud and Microsoft Entra to cover both the data layer and the infrastructure layer.
  1. They help you plan ahead. Knowing where your risk actually sits, thanks to DSPM's reporting, makes it much easier to prioritize which controls to invest in next.

How to build effective guardrails

1. Have a Zero-Trust policy in place

A Zero-Trust security policy works on the principle of "never trust, always verify." In practice, that means making sure people only have access to the data and resources they actually need for their role.

2. Map your industry's specific requirements

Compliance requirements vary a lot by sector. Regulated industries like finance, healthcare, and government typically need more monitoring and stricter retention than others, so it's worth confirming what Compliance Manager's assessment templates cover for your industry and which templates are included in your licensing agreement before assuming a one-size-fits-all policy will do.

3. Get identity management right

Strong identity controls, such as Microsoft Entra Conditional Access and alerting on unusual sign-ins, are the first line of defense against unauthorized access to company resources.

4. Use Microsoft Defender for Cloud

Microsoft Defender for Cloud (previously known as Azure Security Center) gives you visibility and recommendations for securing your cloud infrastructure, which complements the data-level controls in Purview.

5. Let DSPM do the ongoing monitoring

Rather than manually reviewing policies on a schedule, DSPM can continuously scan your environment and surface prioritized recommendations once the required licensing, permissions, analytics, and setup tasks are in place. That makes monitoring more continuous, while still depending on the data sources and AI apps your organization has configured. An automated Microsoft 365 governance tool like ShareGate Protect can also help with this.

Manage your data estate with the Microsoft Purview portal

The Microsoft Purview portal gives you one place to manage your organization's data security, governance, and compliance needs. Here's what that looks like in practice:

  • Managing your data estate: Discover and browse data assets across Microsoft 365, Azure, Fabric, and connected third-party sources through Unified Catalog and Data Map. These governance experiences work primarily with metadata about data assets, such as schema, lineage, classifications, descriptions, and ownership, rather than moving or storing the underlying business data itself.
  • Managing sensitive content: Classifiers, formerly surfaced as Classification in the older portal experience, help identify sensitive information so policies such as sensitivity labels, DLP, and retention can act on it.
  • Managing regulations: Compliance Manager provides ready-to-use regulatory templates for over 360 industry and regional regulations, with a risk-based compliance score to help you prioritize. Which templates are available by default depends on your licensing agreement.
  • Managing AI and Copilot risk: DSPM and AI observability views help you see how Copilot experiences, agents, enterprise AI apps, and supported third-party AI apps interact with your data. Communication Compliance can also review supported AI prompts and responses for policy violations, and Copilot activity is captured in the unified audit log. These protections depend on prerequisites such as auditing, relevant Copilot or Purview licenses, Edge configuration, endpoint onboarding, supported integrations, and in some scenarios pay-as-you-go billing.

Microsoft Purview portal best practices

A few habits go a long way toward getting real value out of the Microsoft Purview portal, whatever your industry or size:

Understand your compliance requirements

Start by mapping what your organization is actually required to do. Requirements vary a lot by industry, and Compliance Manager's assessment templates are a good starting point for figuring out what applies to you.

Monitor your posture regularly

Regular monitoring, using the Compliance posture status card on the Purview portal home page and DSPM's data security objectives, helps you catch drift and address gaps before they become incidents.

Use automation and role-based access

DSPM's recommendations can turn a data risk directly into a DLP or Insider Risk Management policy, cutting out a lot of manual policy design. Pairing that with role-based access control means end users can handle routine requests themselves, without waiting on IT for every permission change.

The Microsoft Purview portal brings data security, governance, and compliance into one place for IT admins, and it keeps expanding to cover new ground, including how your organization uses AI and Copilot. Getting familiar with its structure now makes it much easier to stay ahead of what's coming next.