Information protection
- Data classification: determine protection needs and translate them into built-in or custom sensitive information types
- Custom types, document fingerprinting, exact data match (EDM), trainable classifiers, OCR support
- Track the use of classification and labels via the data and content explorers
- Sensitivity labels in Microsoft Purview: roles and permissions, labels for items and containers, protection settings and content marking, publishing and auto-labelling policies
- Labels for Teams, Microsoft 365 groups, Power BI and SharePoint; applying them via Defender for Cloud Apps
- Information Protection client and scanner for Windows, file shares and on-premises data; Message Encryption and Advanced Message Encryption
Data loss prevention and retention
- Design and manage DLP policies, roles and permissions, understand policy and rule precedence
- DLP for Adaptive Protection, file policies in Defender for Cloud Apps
- Endpoint DLP: device requirements, advanced rules, settings, just-in-time protection, monitoring endpoint activity
- Retention: retention labels and policies, adaptive policy scopes, auto-apply, checking precedence with Policy Lookup, recovering retained content
Risks, alerts and activities
- Insider Risk Management: roles, connectors, integration with Defender for Endpoint, policy indicators and templates, forensic evidence, risk levels for Adaptive Protection, working with alerts and cases
- Microsoft Purview Audit: licensing, investigations, retention policies; analysis in Activity Explorer
- Responding to DLP and Purview alerts, including in Defender XDR; searching with eDiscovery
- Protect data in AI services: controls in Purview and in the Microsoft 365 workloads, prerequisites and policies for Data Security Posture Management for AI, monitoring activity