Pinned Posts
Forum Widgets
Latest Discussions
Linking Data Fields to Glossary
A glossary has been uploaded into Purview which we can see under the unified catalogue. However, in the data map when we view/edit data assets - we would like to link glossary terms to some of the fields. However, the glossary column seems to linking to the old glossary list and not the new glossary which we see under unified catalogue... Has anyone else experienced this? And if so, is there a way around it (apart from loading the glossary in two different places and having to maintain two versions of the glossary on the same platform - which doesn't seem optimal). ThanksSolvedGaz31Sep 15, 2025Copper Contributor128Views1like3CommentsAccessing Content explorer data via SPN
Hi all, I am trying to get all the data from Content explorer for SITs matched files using https://learn.microsoft.com/en-us/powershell/module/exchange/export-contentexplorerdata?view=exchange-ps. I can run the command(Export-ContentExplorerData) when using User-Principle login but having issues while running it on SPN. For SPN Permissions, we followed the steps here https://learn.microsoft.com/en-us/powershell/exchange/app-only-auth-powershell-v2?view=exchange-ps assigned all the permissions on the page but still having issues when running the script. One of the permission for SPN that seems mandatory is Content Explorer Content viewer. Now in purview portal, we are not able to assign this permissions to SPN as it throws an errror "Adding SPN to purview role groups is not supported" Can we run this command(Export-ContentExplorerData) based on SPN(using application permission)? if yes what are the permission we need to assign to that SPN. Thanks in advanceSolvedmrityunjay6492Sep 12, 2025Copper Contributor145Views0likes3CommentsCopilot DLP Policy Licensing
Hi everyone We are currently preparing our tenant for a broader Microsoft 365 Copilot rollout and in preparation to that we were in the progress of hardening our SharePoint files to ensure that sensitive information stays protected. Our original idea was to launch sensitivity labels together with a Purview data loss prevention policy that excludes Copilot from accessing and using files that have confidential sensitivity labels. Some weeks ago when I did an initial setup, everything worked just fine and I was able to create the before mentioned custom DLP policy. However, when I checked the previously created DLP policy a few days back, the action to block Copilot was gone and the button to add a new action in the custom policy is greyed out. I assume that in between the initial setup and me checking the policy, Microsoft must have moved the feature out of our licensing plan (Microsoft 365 E3 & Copilot). Now my question is what the best licensing options would be on top of our existing E3 licences. For cost reasons, a switch to Microsoft 365 E5 is not an option as we have the E3 licences through benefits. Thanks!SolvedStefan19x9aSep 10, 2025Copper Contributor113Views0likes2CommentsAI Activity Explorer Not Showing Content
I am getting an error indicating "Additional permissions required. Your role can't view AI Visits or user risk levels. For permission, ask an administrator to change your role." I am currently an Entra Global Admin, Entra Compliance Admin, and Purview Compliance Admin, and have other roles. I do see based on the dashboard graph I should bee seeing data. What other roles may be necessary or what other configurations may be missing?MarcRohdeSep 09, 2025Iron Contributor502Views2likes3CommentsDLP Policy Blocking Invoices Containing Sensitive Info – Exception Not Working
Hello, I have implemented Microsoft Purview DLP policies in my organization to protect sensitive information such as Aadhaar Card, PAN Card, Driving License, and Credit Card numbers. The policies are working fine and successfully blocking sensitive data. However, I am facing an issue with invoices. When sending invoices internally or to clients, emails are getting blocked because they contain sensitive details like PAN or Aadhaar numbers. I tried adding an exception rule for invoices using the following regex in a Sensitive Info Type (SIT), and included this SIT in the NOT condition of the DLP policy: (?i)(invoice|bill|tax\s*invoice|gst\s*invoice|receipt)\s*(\b[0-9]{12}\b|[A-Z]{5}[0-9]{4}[A-Z]|[A-Z]{2}[0-9]{13}|\d{13,16}) Despite this, invoices are still getting blocked. Has anyone encountered this issue? What is the correct way to configure exceptions in DLP so that sensitive information detection continues to work but invoices containing sensitive info can still be sent? Any guidance or best practices would be greatly appreciated. Thanks in advance! DLP Policy configuration Screenshots.shreyabhurkuseSep 08, 2025Copper Contributor54Views1like1CommentPurview - Default Labelling Issue
There is a proposition to simplify the current sensitivity labelling architecture since we had too many labels that basically is going out of hand. We basically simplified by choosing the most used labels and copying them as new using the same set of permissions and encryption policies applied. We duplicated instead of using the existing one's since we do not want to use sub categories and simplified by just have a drop down list. Everything is looking fine during the test phase but the issue is that the default label is still pointing out to the old label instead of the new one for random users on the office client apps. And some users doesn't have any issue at all. For instance - I have no issues on my Office client apps or OWA on my laptop where as on the CPC, the default label is still pointing to the old label on Office client apps and not being applied at all on OWA. I have set the highest priority to the new labels and all that. Issue still persists. Any advice / help would be greatly appreciated.SolvedB2BSep 07, 2025Copper Contributor367Views0likes3CommentsDeletion of an SharePoint website with an adaptive scope
We are using a retention label "Keep forever" which we have published via a retention policy. In this policy, we have established an adaptive scope based on a KQL query which selects a large part (but not all) SharePoint websites in our tenant. Since there are several new sites created every day in our tenant automatically, adding sites manually to a static scope doesn’t make practical sense. This has worked well. Now we ran into the usecase that we would like to delete a number of (old and not used anymore) SharePoint websites. My first idea was to change the KQL statement and add a NOT Operator inside of the statement. This was fine. However, from studying the material on MS learn, this will trigger a 30 Grace Period for these sites that have been removed from the adaptive scope, although they are not part of retention policy anymore (visible by the policy lock up function). I read that there is a way to EXCLUDE sites from a retention policy (which doesn’t trigger the 30 Grace Period), however this option seems only to be available when using static scopes and not adaptive scopes. Does anyone know a way to retain the flexibility provided by the adaptive scope and not be affected by the Grace Period?SimonL2250Sep 02, 2025Copper Contributor75Views0likes3CommentsBring back old DLP actions
We're working to ensure best practice across clients and protect sensitive information from being shared in unencrypted messages, but rather than having to trust that users will remember to encrypt all of their emails that may contain sensitive data it would be nice to be able to set up a DLP policy to auto encrypt messages that breach DLP. We used to be able to, and it guaranteed moderate protection with minimal impact. Why was this option removed from DLP? Now the only action that we can take is to completely block the messages from being sent. How does that make sense? Many agencies have to communicate sensitive information back and forth, and it should be encrypted. The only current work around I see is to set up a mail flow rule to encrypt all messages, which would cause a larger potential impact on end users outside of the organization, leading to complaints to the company and potential loss of clients and/or profits. Which is not ideal. Microsoft, please stop rolling out half finished platforms and retiring in place and perfectly functional ones before you have a fully working replacement!Sam-C-8798Sep 02, 2025Copper Contributor96Views0likes4CommentsPurview Scanning on Oracle Databases not classifying data assets
We are scanning an Oracle database from our Purview account, and during the scan, approximately 60% of the identified assets are being classified as "Classified Assets." However, when we navigate to Data Estate Insights, each of these assets is displaying "No Match Found" under the Classification section. This seems contradictory and is causing concerns about the accuracy of our data classification. We have thoroughly reviewed and verified our classification rules within Purview, ensuring they are aligned with the data patterns in our Oracle database. The rules have been executed successfully, We have data reader rules on the Oracle database and tables so, we can view the tables too and the schemas generated from the scanned assets are also 100% correct. Please helppppppp. Ashishpurview PurviewFanatic Zmicrosoft azure DonNYC-Purview akamsPurviewHelp or anyone else please @RoopanshSep 02, 2025Copper Contributor854Views1like2Comments
Resources
Tags
- purview101 Topics
- microsoft purview48 Topics
- Sensitivity Labels13 Topics
- ediscovery12 Topics
- Azure Purview11 Topics
- Retention Policy11 Topics
- Retention Labels8 Topics
- endpoint dlp8 Topics
- Information Protection8 Topics
- labels7 Topics