You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/2-translate-compliance-requirements-security-solution.yml
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/3-address-compliance-requirements-microsoft-purview.yml
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ title: Design a solution to address compliance requirements by using Microsoft P
4
4
metadata:
5
5
title: Design a solution to address compliance requirements by using Microsoft Purview
6
6
description: "SC-100 preparatory unit on the topic: Design a solution to address compliance requirements by using Microsoft Purview."
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/4-address-privacy-requirements-microsoft-priva.yml
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -4,10 +4,10 @@ title: Address privacy requirements with Microsoft Priva
4
4
metadata:
5
5
title: Address privacy requirements with Microsoft Priva
6
6
description: "SC-100 preparatory unit on topic: address privacy requirements with Microsoft Priva."
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/6-evaluate-infrastructure-compliance-defender-cloud.yml
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ title: Evaluate and validate alignment with regulatory standards and benchmarks
4
4
metadata:
5
5
title: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
6
6
description: "SC-100 preparatory unit on the topic: Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud."
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/design-solutions-regulatory-compliance/includes/3-address-compliance-requirements-microsoft-purview.md
+23-13Lines changed: 23 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,13 +2,14 @@ Microsoft Purview provides a unified platform for data security, governance, and
Microsoft Purview combines multiple solution areas to address compliance requirements across your organization's data estate:
6
7
7
8
| Solution Area | Purpose | Key Solutions |
8
9
|--------------|---------|---------------|
9
-
|**Data security**| Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management |
10
+
|**Data security**| Protect sensitive data across its lifecycle | Information Protection, Data Loss Prevention, Insider Risk Management, Information Barriers, Privileged Access Management, Data Security Investigations|
10
11
|**Data governance**| Manage and catalog data across your estate | Data Map, Unified Catalog |
11
-
|**Data compliance**| Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, eDiscovery, Records Management |
12
+
|**Data compliance**| Meet regulatory requirements and prepare for audits | Compliance Manager, Audit, Communication Compliance, eDiscovery, Data Lifecycle Management, Records Management |
12
13
13
14
Understanding how these solutions map to specific compliance requirements helps you design an integrated architecture rather than deploying isolated tools.
14
15
@@ -17,6 +18,7 @@ Understanding how these solutions map to specific compliance requirements helps
Most compliance frameworks require organizations to identify, classify, and protect sensitive data. Purview Information Protection provides the foundation for these requirements.
21
23
22
24
**Sensitive information types** identify regulated data like payment card numbers, health records, or personal identifiers using built-in patterns or custom definitions. **Trainable classifiers** extend this capability by learning to recognize sensitive content based on examples you provide—useful for organization-specific data like internal financial reports or proprietary designs.
@@ -36,12 +38,13 @@ When designing your labeling strategy, consider:
Regulations often require controls to prevent unauthorized disclosure of sensitive information. **Microsoft Purview Data Loss Prevention (DLP)** monitors and controls how sensitive data is shared across Microsoft 365 services, endpoints, and cloud apps.
40
43
41
44
Design your DLP policies to address specific regulatory requirements:
42
45
43
46
-**Policy conditions** - Define what sensitive data to protect based on sensitive information types, labels, or content patterns
44
-
-**Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, endpoints, Defender for Cloud Apps)
47
+
-**Policy locations** - Specify where monitoring occurs (Exchange, SharePoint, OneDrive, Teams, devices, non-Microsoft cloud apps, on-premises repositories, Fabric and Power BI, and Microsoft 365 Copilot)
45
48
-**Policy actions** - Configure responses from audit-only monitoring to blocking with user override to complete restriction
46
49
47
50
DLP integrates with your sensitivity labels, so protection can follow content based on its classification. This integration is particularly valuable for requirements that mandate different handling based on data sensitivity levels.
@@ -50,22 +53,26 @@ DLP integrates with your sensitivity labels, so protection can follow content ba
50
53
51
54
Compliance frameworks require organizations to maintain audit trails and respond to legal or regulatory inquiries. Purview provides several solutions for these requirements:
52
55
53
-
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Design your audit strategy to:
**Microsoft Purview Audit** captures user and admin activities across Microsoft 365 services. Audit is available in two tiers—Audit (Standard) provides 180-day retention with basic search and export, while Audit (Premium) adds custom retention policies (up to 10 years with an add-on license), intelligent insights for forensic investigations, and higher API bandwidth. Design your audit strategy to:
54
58
55
-
-Enable appropriate audit logging levels based on regulatory requirements
56
-
- Configure retention periods that meet legal hold obligations
59
+
-Select the appropriate audit tier based on regulatory retention and investigation requirements
60
+
- Configure retention policies that meet legal hold obligations
57
61
- Establish processes for searching and exporting audit data for investigations
**Microsoft Purview eDiscovery** helps you identify, preserve, collect, and export content for legal matters. For compliance purposes, design workflows that:
60
65
61
66
- Create legal holds to preserve relevant content
62
67
- Define search criteria that capture required data without over-collection
63
68
- Export content in formats suitable for regulatory review
**Microsoft Purview Records Management** applies retention and deletion policies to meet recordkeeping requirements. Consider how file plans, retention labels, and disposition reviews align with your regulatory obligations.
Some regulations require controls to detect and respond to insider threats. **Microsoft Purview Insider Risk Management** uses signals from across Microsoft 365 and third-party systems to identify risky user activities.
70
77
71
78
Design your insider risk program to:
@@ -76,24 +83,27 @@ Design your insider risk program to:
76
83
77
84
## Addressing AI compliance requirements
78
85
79
-
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Purview provides capabilities specifically designed for AI scenarios:
86
+
As discussed in the AI compliance considerations unit, organizations deploying AI face specific regulatory requirements around data protection, transparency, and governance. Multiple Purview solutions extend their capabilities to AI scenarios:
80
87
81
-
**Data Security Posture Management (DSPM)** provides visibility and control for both traditional applications and AI apps. Use DSPM to:
**Data Security Posture Management (DSPM) (preview)** provides visibility and control for both traditional applications and AI apps and agents. Use DSPM to:
82
90
83
91
- Discover sensitive data that may be exposed to AI applications
84
-
- Monitor how AI apps access and process organizational data
92
+
- Monitor how AI apps access and process organizational data through data security insights and trend analysis
85
93
- Identify and remediate data security risks before they become compliance issues
86
94
87
-
**Microsoft Purview for AI** extends data security protections to generative AI experiences:
Existing Purview data security capabilities extend to generative AI apps, including Microsoft 365 Copilot, Copilot Studio, and third-party AI applications:
88
97
89
-
-Protect data used by Copilot experiences and custom AI agents
90
-
-Apply sensitivity labels to AI-generated content
91
-
-Prevent sensitive data from being shared inappropriately through AI interactions
98
+
-**Sensitivity labels** protect data referenced by AI apps—users must have appropriate usage rights (VIEW and EXTRACT) for AI apps to return encrypted content
99
+
-**Data Loss Prevention** monitors AI interactions and can block sensitive data sharing with unmanaged AI apps through endpoint and inline web traffic policies
100
+
-**Insider Risk Management** detects risky AI usage, including prompt injection attacks and unauthorized access to protected materials, through the Risky AI usage policy template
92
101
93
102
For organizations subject to AI-specific regulations like the EU AI Act or ISO 42001, **Compliance Manager** provides assessment templates that map Purview controls to these requirements.
Compliance Manager serves as the orchestration layer that brings together compliance data from across your environment. It integrates with Microsoft Defender for Cloud to assess compliance across Azure, AWS, and GCP.
98
108
99
109
When designing your Compliance Manager implementation:
0 commit comments