Microsoft Purview Overview & Compliance Portal
SC-400 Exam Alignment
SC-400
Skill: Implement information protection in Microsoft Purview — Understand the Microsoft Purview compliance portal, navigate Compliance Manager, interpret the Compliance Score, identify the data map and data catalog, and assign compliance roles.
- Know that the compliance portal is at compliance.microsoft.com and requires an E3 or E5 licence (features vary by licence)
- Understand that Compliance Manager provides pre-built assessments mapped to regulations (ISO 27001, GDPR, NIST, etc.) and tracks improvement actions
- Know the difference between Compliance Score (posture metric) and the individual control statuses within an assessment
- Understand that the Microsoft-managed controls are always “Passed” — only your organisation’s controls affect your score
🗂️ What Is Microsoft Purview?
| Solution Area | What It Covers | Primary Portal |
|---|---|---|
| Microsoft Purview (M365 Compliance) | Data classification, sensitivity labels, DLP, retention, eDiscovery, audit, insider risk, communication compliance — for Microsoft 365 data | compliance.microsoft.com |
| Microsoft Purview (Data Governance) | Enterprise data catalog, data map, data lineage, data scanning — for Azure and multi-cloud data assets | purview.azure.com (Microsoft Purview governance portal) |
💡 SC-400 Focus
The SC-400 certification focuses entirely on the M365 compliance side of Purview — everything in compliance.microsoft.com. When the exam says “Purview,” it means compliance.microsoft.com unless stated otherwise.
🖥️ The Microsoft Purview Compliance Portal
compliance.microsoft.com › Home
Key Portal Sections
| Section | What You Configure Here |
|---|---|
| Compliance Manager | Regulatory assessments (GDPR, ISO 27001, NIST, etc.), improvement actions, compliance score, testing evidence |
| Data classification | Sensitive information types, trainable classifiers, Content Explorer (view all classified content), Activity Explorer (view labelling and DLP events) |
| Information protection | Sensitivity labels and their settings; label policies (publish to users/groups); auto-labelling policies; label analytics |
| Data loss prevention | DLP policies for Exchange, SharePoint, OneDrive, Teams, Endpoint, and Power Platform; DLP alerts; Activity Explorer for DLP events |
| Data lifecycle management | Retention policies (automatic apply to all content in a location) and retention label policies (user-applied or auto-applied) |
| Records management | File plan, record labels, event-based retention, disposition review queue, regulatory records |
| eDiscovery | Content Search (quick ad-hoc), eDiscovery (Standard) cases, eDiscovery (Premium) cases with custodians and advanced analytics |
| Audit | Unified Audit Log search; audit retention policies (Premium); export audit events; user activity investigation |
| Insider risk management | Risk policies, indicators, cases, notices; integrates with HR connector, DLP alerts, and Entra ID signals |
| Communication compliance | Policies to detect inappropriate, sensitive, or regulatory-violating communications in Teams, Exchange, and Viva Engage |
📊 Compliance Manager
Compliance Manager provides pre-built regulatory assessments mapped to major global frameworks. It tracks your progress against each framework by measuring which controls are in place.
How Compliance Score Works
| Control Type | Who Manages It | Score Impact |
|---|---|---|
| Microsoft-managed controls | Microsoft (data centre physical security, platform availability, etc.) | Always “Passed” — points awarded automatically |
| Customer-managed controls | Your organisation must configure and evidence these | Points awarded when you mark as implemented and provide testing notes |
| Shared responsibility controls | Both Microsoft and your organisation have obligations | Partial points — Microsoft portion auto-passes, your portion needs action |
⚠️ Compliance Score ≠ Actual Compliance
The Compliance Score is a configuration posture metric, not a legal compliance certification. A high score means you have implemented the relevant controls — it does not mean your organisation is legally certified as GDPR-compliant or ISO 27001-certified. Formal certification requires third-party audit.
Key Built-in Assessments
| Framework | Coverage |
|---|---|
| Microsoft 365 Data Protection Baseline | Core Microsoft 365 security and compliance controls — good starting point for all tenants |
| GDPR | EU General Data Protection Regulation — personal data processing, rights of data subjects, breach notification |
| ISO 27001:2022 | Information security management system controls — globally recognised standard |
| NIST SP 800-53 | US federal information security controls — common for US government and defence contractors |
| SOC 2 | Service Organisation Control 2 — trust service criteria (security, availability, confidentiality) |
👑 Compliance Admin Roles
| Role | Permissions | Least Privilege For |
|---|---|---|
| Compliance Administrator | Full access to compliance portal — policies, assessments, alerts, reports | Compliance team lead, DPO |
| Compliance Data Administrator | Same as Compliance Administrator plus ability to manage data in Azure information protection | Information protection officer |
| Global Reader | Read-only access to all compliance settings — cannot create or modify policies | Auditors, external reviewers |
| Privacy Management Administrator | Manage privacy risk policies, privacy subject rights requests | Privacy officer |
| eDiscovery Manager | Create and manage eDiscovery cases, run content searches, export evidence | Legal team, eDiscovery analysts |
| Insider Risk Management | Configure insider risk policies, view cases and alerts | HR partners, security analysts |
🏆 Licence Requirements
| Feature | M365 E3 / Business Premium | M365 E5 / E5 Compliance |
|---|---|---|
| Sensitivity labels (manual) | ✅ Included | ✅ Included |
| DLP (Exchange, SharePoint, OneDrive) | ✅ Basic DLP included | ✅ Full DLP including Endpoint DLP |
| Retention policies | ✅ Included | ✅ Included |
| Audit (Standard) | ✅ 90-day retention | ✅ Up to 10-year retention (Audit Premium) |
| eDiscovery (Standard) | ✅ Content Search + Standard cases | ✅ Included |
| eDiscovery (Premium) | ❌ Not included | ✅ Full Premium with custodian management |
| Auto-labelling policies | ❌ Not included | ✅ Included |
| Insider Risk Management | ❌ Not included | ✅ Included |
| Communication Compliance | ❌ Not included | ✅ Included |
| Records Management | ❌ Not included | ✅ Included |
💡 Best Practices
- Start every new Purview deployment by configuring Compliance Manager first — it gives you a prioritised roadmap of what controls to implement based on your selected frameworks
- Use the principle of least privilege for compliance roles — assign the Compliance Data Administrator only to those who need to configure policies, and Global Reader for auditors who only need to review settings
- Enable the Microsoft 365 Data Protection Baseline assessment in Compliance Manager before adding framework-specific assessments — it establishes your baseline posture and the easiest quick wins
- Understand your licence tier before designing your compliance programme — features not in your licence will show greyed out in the portal with an upgrade prompt
🎓 Interview Q&A
A Compliance Administrator needs to evaluate the organisation’s adherence to ISO 27001. Which feature in the Microsoft Purview compliance portal should they use?
An organisation’s Compliance Score drops from 68% to 61% after a quarterly review. Which is the most likely explanation?
A legal team member needs to run eDiscovery searches and export evidence but must NOT be able to change DLP policies or sensitivity label configurations. Which role should they be assigned?
Which Microsoft 365 licence tier includes Insider Risk Management, Communication Compliance, and Audit Premium?
Where in the Microsoft Purview compliance portal would an administrator go to see ALL files and emails across the tenant that contain sensitive information — labelled or detected by a sensitive information type — in a single view?