0800 458 4545 Login Get in touch
Data 4 min read

Microsoft Purview Is More Than Sensitivity Labels

By Vicki Holman, Pre-Sales Solution Architect at ANS

I don’t actually care about sensitivity labels! (shock face emoji)

There, that got your attention. I do care a bit about sensitivity labels, but not actually as a check box exercise in isolation which is how so many organisations are approaching Sensitivity labels and other solution areas within Purview, and that’s not the right way to go about it.

Nobody wakes up in the morning thinking about how much they want sensitivity labels, actually what they want is data visibility and security, however, I think partly because Purview is such a huge platform with so many components it becomes very confusing and therefore there’s a tendency to focus in on sensitivity labels as that’s something that is often asked about in audits and readiness assessments.

What can happen when sensitivity labels are part of a check box exercise rather than a meaningful deployment is that you can end up with labels that mean nothing to your organisation and are potentially not applying any additional protections. I get it, we all want AI, AI is exciting and full of possibility, and the business are pushing us to show value, we want to do the absolute minimum we can do to start showing the efficiencies, money savings, improved work/life balance etc.

Instead, we need to take a step back and look at the bigger picture. This is a programme, not a discreet project.

Don’t try and eat the whole elephant at once, break it down into manageable chunks.

1) Know your data
2) Protect your data
3) Prevent data loss
4) Govern your data
5) Optimise your governance

Before you even start out in Purview, check your SharePoint sharing defaults and where there might be some over permissive sharing going on. There are a lot of great reports available within SharePoint Advanced Management to give you visibility of potential issues across your estate.

Five essential data security steps.

1. Know your data.

What data is critical to you? (the answer is not all of it) There are built in sensitive information types available to you in Purview, such as Passport number, or credit card number, but engage with the business to understand where custom sensitive information types and trainable classifiers can be created to help you identify data relevant to you.

2. Protect your data.

Ok labels. Design a label taxonomy that is meaningful to your business and trial it on a  test group first. You may want to get people used to labelling without adding label specific access controls, however, these should very much be on the road map, especially for your more sensitive labels. It’s almost worse to label an item as confidential and apply no protections, it’s like you’re signposting it.

3. Prevent data loss.

You can use DLP policies across so many locations in your M365 estate, you can protect data with DLP based on sensitivity labels, sensitive info types and trainable classifiers, so this early foundational work is really coming in to play now.

4. Govern your data.

This is where you prevent data from loitering where and when it shouldn’t. You absolutely do not want someone sending in a subject access request and you having to return Teams chats from that person from 3 years ago. Equally, you don’t want to have Copilot returning stale out of date information as the truth.

5. Optimise your governance.

When we have all the foundational steps in places, we can start auto applying labelling and using adaptive risk controls in our policies.

This isn’t the end of your journey, as regulations and business requirements change, Purview settings and policies need to be revisited to make it work for the business.  This does take longer and require more effort than just rolling out some labels, however, AI accelerates data interactions, AI allows us to find data that was otherwise hidden. The organisations making a success out of AI are the ones who are protecting their data in a meaningful way.