Skip to main content

Which Microsoft Purview Solution Should You Use?

Choose the business outcome before choosing a Purview solution. Start with the data, risk, obligation, and accountable owner; then select the smallest set of controls that addresses that need.

Quick Answer

Use:

  • Data Map and Unified Catalog to discover, describe, curate, and improve trust in data assets across the data estate;
  • Information Protection, DLP, and DSPM to classify sensitive information, protect it, prevent risky handling, and understand data security posture;
  • Data Lifecycle Management and Records Management to retain, delete, declare, review, and dispose of information;
  • Audit, eDiscovery, Compliance Manager, and investigation tools for evidence, cases, regulatory assessments, and data incidents;
  • Insider Risk Management, Communication Compliance, Information Barriers, and Privileged Access Management for defined risks involving behavior, communication, separation, or privileged tasks;
  • DSPM plus the applicable controls above to manage supported AI interactions.

Purview solutions often work together. That does not mean every scenario needs all of them.

Decision Flow

Choose By The Problem

Business problemPurview solutionRecommended ownersFirst validation
We need an inventory, lineage, business meaning, ownership, or quality for data across analytics, SaaS, hybrid, or multicloud sourcesData Map and Unified CatalogData office, data owners, data stewards, and ITSelect one governed domain and confirm supported sources, ownership, metadata, quality, and billing
People need to recognize and protect confidential documents and emailsInformation Protection and sensitivity labelsInformation owner, security, compliance, and ITDefine a small, understandable classification scheme and test protection in the apps and sharing routes people use
We need to warn, audit, restrict, or block risky handling of sensitive dataData Loss PreventionSecurity, compliance, workload owners, and supportStart in simulation or audit mode where supported, review matches and false positives, and define overrides before blocking
We need a combined view of sensitive-data risk or deeper analysis of data affected by an incidentData Security Posture Management and Data Security InvestigationsSecurity operations, data security, privacy, and incident ownersReview permissions, data scope, integrations, preview dependencies, and capacity or pay-as-you-go costs before investigation
We must keep or delete information consistently, or manage high-value records and their dispositionData Lifecycle Management and Records ManagementRecords, legal, compliance, information owners, and ITDocument the authority, trigger, period, outcome, exceptions, and approver before creating policies or labels
We need activity evidence, a legal or regulatory case, or an assessment of compliance obligationsAudit, eDiscovery, and Compliance ManagerLegal, compliance, audit, security, and privacyDefine the case or requirement, custodians and scope, least-privilege roles, evidence handling, and required license level
We must address risky behavior, inappropriate communications, conflicts of interest, or standing privileged accessInsider Risk Management, Communication Compliance, Information Barriers, and Privileged Access ManagementSecurity, compliance, privacy, legal, HR, and ITConfirm the legitimate purpose, proportionality, privacy controls, reviewers, escalation route, and supported workloads before enabling monitoring or restrictions
We need to reduce oversharing, leakage, or compliance gaps in Copilots, agents, or other generative AI appsPurview data security and compliance for generative AIAI service owner, security, compliance, data owners, and ITInventory the exact AI apps and agents, then verify the support matrix, licenses, billing, permissions, and policies for each one

Understand The Control Layers

These controls answer different questions and can apply to the same item:

ControlQuestion it answersPractical effect
PermissionsWho can open or change this content here?Grants or denies access in the current service or workspace; permissions are not a Purview replacement for classification or lifecycle
Sensitivity labelHow sensitive is this, and which protection should travel with it?Classifies supported content and can apply markings, encryption, or other protection settings
DLP policyWhich sensitive activity should be audited, warned about, restricted, or blocked?Evaluates configured content, context, locations, and actions while people or processes handle data
Retention policyWhich broad locations or populations need the same keep or delete rule?Applies retention settings to supported workloads without asking users to label each item
Retention labelWhich item or document category needs a specific lifecycle?Applies item-level retention or deletion and can be published, defaulted, or automatically applied when supported
Record declarationDoes this high-value item need stronger record controls and disposition evidence?Uses Records Management capabilities such as record declaration, file plans, and disposition review
AuditWhat supported user or administrator activity occurred?Provides searchable activity records for security, forensic, compliance, or operational investigation
eDiscoveryWhich electronic information must be identified, preserved, reviewed, or exported for a case?Organizes legal or regulatory work around cases, holds, searches, review, and export

A document can therefore have permissions, a sensitivity label, and a retention label at the same time. DLP can evaluate how it is handled, Audit can record supported activity, and eDiscovery can preserve or collect it for a case.

Controls Do Not Create Policy

Do not translate a vague instruction such as “keep everything” or “block confidential data” directly into a tenant-wide policy. Confirm the purpose, legal or policy authority, owner, scope, user impact, exceptions, and end-of-life action first.

Use Sensitive Risk Tools Proportionately

Insider Risk Management, Communication Compliance, eDiscovery, and investigation tools can expose sensitive information about people and their work. Define privacy, legal, HR, reviewer, segregation-of-duties, and escalation safeguards before use.

Treat AI As A Cross-Cutting Scenario

Do not assume that buying or enabling one “AI security” feature covers every Copilot or agent. Start with the same foundations used for other data: correct access, known owners, useful classification, appropriate DLP, audit, retention, and investigation processes. Then verify which controls support each AI app or agent.

As of July 21, 2026, Microsoft marks some DSPM integrations and proactive AI insights that use Data Security Investigations as preview. Keep a stable monitoring or investigation route available and recheck preview status before making it part of an operational dependency.

  1. Describe one concrete risk, obligation, or data-governance outcome.
  2. Name the business or data owner and the security, records, legal, privacy, or compliance decision owner.
  3. Inventory the data, locations, users, processes, and AI apps in scope.
  4. Confirm roles, supported workloads, licensing, billing, and technical prerequisites.
  5. Pilot with representative data and users; use simulation, audit, or limited scope where the solution supports it.
  6. Prepare user guidance, help-desk answers, exception handling, alert ownership, and escalation before enforcement.
  7. Measure false positives, uncovered data, policy outcomes, user friction, and unresolved cases; then tune or expand.
Check Licensing Before Design Becomes A Promise

Feature rights can differ by policy type, application method, location, and benefiting user. Use the official Microsoft Purview service description as the authoritative starting point. The M365 Maps Purview Suite diagram and feature matrix can help visualize plan overlap but are not official licensing terms.

Official Microsoft Documentation