SC-900 Exam Guide: What to Know About Microsoft Purview and Compliance

Domain 4 of the SC-900 certification exam covers Microsoft Purview and compliance, accounting for 15–20% of the total score. The domain is organized around five stages: classifying data, applying sensitivity labels, enforcing data loss prevention, managing retention, and governing through tools like eDiscovery and Compliance Manager. Sensitivity labels travel with files and enforce protections such as encryption and access restrictions, while retention labels govern how long content is kept or deleted at the item level. DLP policies monitor for sensitive information types across platforms including Exchange, SharePoint, Teams, and endpoints, triggering actions that range from user notifications to outright blocking. Tools like Insider Risk Management, Communication Compliance, and Compliance Manager round out the domain, helping organizations detect internal threats and measure adherence to standards such as GDPR and ISO 27001.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in