Microsoft Purview Information Protection Overview
Microsoft Purview Information Protection Overview
1
Agenda
• Microsoft Purview Security,
Governance and Compliance
• What’s new for Information
Protection
• Expanding beyond M365 to the
enterprise data estate
• Securing M365 Copilot
• Q&A
2
Meet the Microsoft Purview family
D ATA S E C U R I T Y D ATA G O V E R N A N C E D ATA C O M P L I A N C E
Secure data across its Govern data seamlessly to Manage critical risks and
lifecycle, wherever it lives empower your organization regulatory requirements
Compliance Manager
Data Loss Prevention Data Map
eDiscovery
Insider Risk Management Data Catalog
Audit
Information Protection Data Estate Insights
Communication Compliance
Data Lifecycle Management
Records Management
Unstructured & Structured data Traditional and AI generated data Microsoft 365 and Multi-cloud
3
The most urgent
data security
challenges
• Discover sensitive data,
whether structured or
unstructured,
on-premises or in the clouds
• Secure configuration to
prevent sophisticated attacks
• Detect how users are
interacting with data and
identify insider risks
• Ensure your data remains
secure from data leakage
and data exfiltration
activities
4
Data security incidents can happen anytime,
anywhere
Data at risk of misuse if organization has no visibility into their data
estate
1 2 3
User falls prey to phishing User copies file to a USB, then User negligently shares
attack, compromises user uploads to a personal Dropbox sensitive data in generative AI
credentials apps
5
Security concerns associated with AI usage
Insufficient visibility into the usage of AI applications can result in security and compliance
challenges.
1 2 3
Project x
COMPLIANT
6
Organizations need to…
7
Blue circle indicates data loss
prevention where the green
circle is integrating
Information
Discover and auto-classify data Protection
and prevent it from unauthorized
use across apps, services, and
devices
Understand the user intent and
context around sensitive data
to identify the most critical risks
Support for multi-cloud, hybrid, SaaS and all data | Partner ecosystem
8
Microsoft Purview Information Protection
XXXXXX Data classification Sensitivity Labels
service
Sensitive Info Defender
Desktop & for cloud
Types (SITs)
Mobile devices apps
Named
Entities Public
Fingerprin
Credentials
t ADLS SQL Azure
SITs
SITs DB Files
Files, Emails,
Data Types: Meetings
Power BI, Synapse,
*Transcripts,
ADLS, ADF, Relational S3 buckets
Recordings, Loop,
DB (SQL, Cosmos DB),
OneNote, Embedded
Power apps
images, Planner,
Microsoft 365Forms Azure (Fabric, SQL ADLS), Dataverse 3P
Workloads:
Sensitivity
labels span Public General Confidentia
l
Restricted
your entire
data estate
• They are a
representation of your Content labels Container labels
information taxonomy.
Applied To: Office apps, Power Applied To: SharePoint sites,
• They describe the BI reports, Azure Data Teams channels, Microsoft 365
priority assigned to your groups
Protections: Encryption and
categories of sensitive visual markings Protections: Access control,
information. privacy settings, conditional
Automation: Can be applied access
either manually by users or
automatically based on Automation: Can be applied
classification manually by site/Team or group
owners
12
Best-in-class classification technologies
Sensitive info Optical Character
Named entities Exact data match
types Recognition (OCR)
300+ out of the box info types 50+ entities covering person Provides a lookup to exactly Expanded OCR for EXO, SPO,
like SSN, CCN name, medical terms, and drug match content with unique ODB, Teams & endpoint
Clone, edit, or create your own names customer data devices
Supports regex, keywords, Best used in combination with Supports 100m rows and Supports over 150 languages
and dictionaries other sensitive info types multiple lookup fields Supports image files and
images embedded in PDFs
Trainable Context-based
Credentials SITs Fingerprint SITs
classifiers classification
35+ pre-trained 42 new SITs for digital Detect exact or partial ODSP default site label
ready-to-use trainable authentication credential types matching of sensitive Service-side auto-labeling
classifiers Use in auto-labeling and DLP intellectual property • File extension
Create your own classifier policies to detect sensitive Use in Exchange, SharePoint, • Document name contains word
based on business data credentials in files Teams and Devices • Document property is
• Document size greater than
• Document created by
Templates
Provide pre-defined policies
that use available classifiers
16
MIP and DLP Analytics Page
Policy simulation
1 2 3 4
Pick your scope Simulate in your Gain confidence in your Turn on protection
production environment protection policy policies after validating
simulation results
• Option 1: ALL – SharePoint • Simulation is fast – It • Review simulation results • Existing Office Files at rest
sites, OneDrive accounts normally takes a few (both aggregate and (Word, Excel, PowerPoint)
and Email users hours to run depending on sample files) in OneDrive & SharePoint
• Option 2: Subset of sites the size of • Iterate and experiment to are automatically
your tenant protected
or accounts – Can use improve accuracy
PowerShell for longer lists • Simulation is not intrusive • New files added after the
– No actions are applied policy is enforced are
• Simulation for EXO also protected
Supported in auto labeling
triggers in near real time • Emails in transit are
and DLM today, DLP by
on email activity (not automatically scanned for
Jun’23
emails at rest) sensitive information
• Simulation for ODSP and protected
triggers on files at rest • Cold data crawl: private
• Insights are best achieved preview coming in Q3’23
on real production data
Labeling data at scale – Guiding principles
Apply labels by Apply labels
Apply labels based on
default using automatically
context
Label Policy based on content
• When content is • By location, for sensitive • Client-side auto-
created or SPO libraries, site owners labeling for content
accessed, set a can set a default label per when files are in-use
default label for library and mails are
• Files • For documents at rest being composed
• Emails • Use service-side auto • Service side auto-
• Meetings labeling by file size, labeling policy for
extension, properties … files at-rest in SPO,
• PBI Reports
• Use SetLabel Graph API ODB and mails in-
• Containers transit
to label specific files
•… based on your criteria in Exchange
• For emails in motion
• Use service-side auto
labeling to trigger labels
based on predicates like
Roadmap
Pu
bl
ic
Pr
Expanding auto-labeling
ev
ie
w
–
Ap
r
1. New actions & workloads:
Configure auto-labeling policies for
Azure, ADLS, and AWS S3
individually.
ev
ie
w
–
Ap
1.S3
r
New workloads: Labeling and
classification available across Azure
SQL, ADLS, & AWS S3.
ev
ie
w
–
Ap
r
1. New Protection Policy actions:
As a result of applying labels,
admins can set MIP Protection
Policies for items in Fabric (Allow
read, Allow write).
Label
in
Extended
SharePoint site
g
-T
BD
SharePoint
Permissions with
Brings together permissions in
Henry is a member of the
SharePoint site
RMS
SharePoint Online and Microsoft
Purview Information Protection.
Admin removes Henry from the
site
ev
ie
w
-M
ay
• Label-Based Conditional Access combines familiar
sensitivity labeling-based protections with Entra ID
Conditional Access policies to give administrators Admin configures conditional access when defining a sensitivity
ev
ie
w
–
M
ar
• Dynamic watermarking provides
customers with the controls to
require virtualized watermarks on
labeled documents.
ev
ie
w
–
Q
inheritance
3
Labeled meetings will
automatically inherit the label
to meeting artifacts:
ev
ie
w
-J
ul
docsmeeting will
y
Protected
automatically label based
on the most sensitive
shared content:
1. Labeled documents
shared through chats or
windows share can
upgrade label on meeting
2. Labels can be
recommended or
automatically applied to
meeting from shared
documents
Pr
iv
at
e
Pr
Labeling in OneNote
ev
ie
w
–
Q
3
• Extending OneNote to support sensitivity labeling
and protection.
Embedded OCR
36
Sensitivity labels to protect Microsoft Teams
shared channels
Private Teams discoverability control
38
Configure policy tips as popups for labeled
emails and attachments
Configure DLP rules that display warnings in a popup
dialog before sending emails.
Generally
available in Office
version v2302
39
Double Key Encryption (DKE)
40
Tracking and Revocation
Native in Information Protection
41
Growing
ecosystem
200+ Purview and Priva
partners
75 MISA partners
AI
Copilot will honor access control restrictions on labeled
content
Only content from references where
the user has appropriate RMS
permission will be included in
responses.
automatically
labeled
Microsoft Purview provides
end-to-end data protection
that transitively protects
sensitive data across
application experiences.
Copilot generated
output is auto-
matically labeled
Use existing Microsoft Purview
auto-labeling rules and admin-
defined sensitive information
types to detect sensitive content
and automatically label the
files/emails.
How to get started
Establish labeling Allow your end users Classify based on Assist your end users Ensure data is
scheme with parent to start manually location. in labelling with protected with DLP
and sub-labels, user labelling. Classify based on file recommendations. policies.
descriptions, and extension, size, Protect your most Use content and
priority. custom properties. sensitive content at context triggers for
Classify based on rest with labels. DLP policies.
email predicates like
sender recipient,
domain.
Intelligent: Default labels & policies with simple one-click
turn on
Intelligent: Flexibility to further configure and learn more
Next steps/Learn more
• Blogs: https://aka.ms/ipgblog
• Interactive guide: aka.ms/InfoProtectionInteractiveGuide
• Mechanics videos: aka.ms/InfoProtectionMechanics
• Automatically Classify & Protect Documents & Data | Microsoft P
urview Information Protection
– YouTube
• AI-powered Data Classification | Microsoft Purview - YouTube
• Start a free trial aka.ms/PurviewTrial
• Licensing: https://aka.ms/compliancesd
Deploying Information Protection
• Deployment acceleration guide
• Service-side auto labeling playbook
• Protecting source code playbook
55
Other resources
Blogs: https://aka.ms/ipgblog
Online roadmap tool: https://aka.ms/mipc/roadmap
Interactive guide: aka.ms/
InfoProtectionInteractiveGuide
Mechanics video: aka.ms/InfoProtectionMechanics
Licensing: https://aka.ms/compliancesd
Microsoft Purview Information Protection SDK
information
• SDK documentation:
https://aka.ms/MIPSDKDocs
• SDK sample: https://aka.ms/MIPSDKSamples
• SDK blog: https://aka.ms/MIPDevelopers
Deploying Information Protection/DLP
• Deployment acceleration guide
• Service-side auto labeling playbook