Microsoft 365 Data protection Compliance Cybersecurity

Microsoft Purview: what it is, what you can do with it and what each licence includes

Quick summary

TL;DR (for those of us short on time)

The essentials before we get into it:

  • Purview is Microsoft's umbrella for security, compliance and data governance. It is not a product: it is about fifteen different solutions sharing one portal.
  • You are already paying for it. Almost every Microsoft 365 plan includes some Purview. The problem is rarely the licence, it is that nobody has configured it.
  • The line between «having it» and «being able to use it» sits at E5 or at the Purview Suite add-on: automatic labelling, endpoint DLP, insider risk management and intelligent retention all live there.
  • In smaller companies the jump is Business Premium. Basic and Standard bring next to no Purview beyond basic auditing.
  • Watch out for Office 365 E5: it is not the same as Microsoft 365 E5. They look alike, but important pieces are missing.
  • At the end there is a 90-day roadmap to get started without spending another euro.

And halfway through there is a simulator to see, plan by plan, what you have and what you are missing. 👇

Let's start with the problem, not the product

There is a conversation that repeats itself in almost every meeting with clients who are starting to put their security in order.

Someone asks where the organisation's sensitive data is. And an awkward silence follows.

Not because nobody knows, but because everybody knows a part of it. Finance knows its own. HR knows its own. IT knows where the servers are. Nobody has the full picture: what critical information exists, where it lives, who accesses it, where it goes and what would happen if one day it turned up somewhere it should not.

That gap is exactly what Microsoft Purview sets out to cover. And most organisations working with Microsoft 365 already have it without knowing.

What Microsoft Purview is (and what it is not)

Microsoft Purview is the brand under which Microsoft has grouped everything to do with data: discovering it, classifying it, protecting it, retaining it, auditing it and governing it.

Worth saying plainly from the start: Purview is not a tool, it is a catalogue of solutions. When someone says «let's roll out Purview», they are really saying something as vague as «let's roll out security». The useful question is always which part of Purview.

And there is a second, very common confusion worth clearing up right away: Purview has two faces that share a name but are bought differently.

Face 1

Compliance and data security in Microsoft 365

Sensitivity labels, data loss prevention, retention, eDiscovery, insider risk, auditing. This is what 90 % of this article is about, and it is probably what you care about.

Licensed through your Microsoft 365 plans
Face 2

Enterprise data governance

What used to be called Azure Purview: unified catalogue, data map, lineage, data quality. It covers databases, analytical stores and third-party sources.

Billed separately, by consumption in Azure

Mixing the two is the most expensive starting mistake I come across. The second one is not included in any Microsoft 365 plan. If a supplier hands you a «Purview» quote without separating them, ask for the breakdown.

What you can do with Purview: the pieces, one by one

Information Protection: sensitivity labels

This is the foundational piece and the one with the best return for the effort. It lets you classify documents and email —Public, Internal, Confidential, Restricted— and makes that label travel with the file, applying encryption, watermarks and usage restrictions.

The relevant part: protection persists outside your tenant. If a document labelled Restricted ends up on a USB stick or in someone's personal mailbox, it still cannot be opened.

It can be applied in three ways, and this is where licensing comes in: manually (the user picks), by default or mandatory (the organisation imposes a minimum label) and automatically (Purview inspects the content and labels it on its own). Automatic labelling is what actually scales, and it is the one that demands higher licensing.

Data Loss Prevention (DLP): keeping information in

Policies that detect sensitive information in motion and act on it: warn the user, block the send, raise an incident or ask for a justification.

There are three scopes, and they are not licensed the same way:

  • DLP for email and files (Exchange, SharePoint, OneDrive) — the most accessible one.
  • DLP for Teams chat — requires higher licensing.
  • Endpoint DLP — controls data on the device itself: copying to USB, printing, uploading to a non-corporate service, pasting into a generative AI. The most powerful one, and the most restricted by licence.
Keynote

The use case driving Purview adoption right now is not classic compliance, it is AI. Stopping someone from pasting the strategic plan or customer data into a public chatbot is an everyday request today, and Endpoint DLP is the technical answer.

Lifecycle and records management

Retention and deletion policies: how long each type of information is kept and what happens next. It sounds dull until an inspection, a lawsuit or a GDPR subject access request turns up.

There are tiers here too: manual retention (the user labels), by location (all of SharePoint, 7 years), automatic rule-based (if content matches X, retain Y) and machine-learning based (trainable classifiers that identify document types). And above that, Records Management, for files with evidential value, record declaration and formal disposition.

eDiscovery and auditing

Searching, preserving and exporting information for litigation, an internal investigation or a regulatory request.

  • eDiscovery (Standard): search, legal hold and export.
  • eDiscovery (Premium): analytics, deduplication, custodian management, review workflows.
  • Audit (Standard): activity logging with limited retention.
  • Audit (Premium): extended retention, high-value events and access to the activity API. During an incident, the difference between being able to reconstruct what happened and not being able to is usually exactly here.

Insider Risk Management and Communication Compliance

The part people least enjoy explaining and that matters most. Insider risk management detects behaviour patterns associated with data leakage, IP theft or sabotage: mass downloads before a resignation, exfiltration to personal services, unusual activity after a redundancy notice.

It builds on Adaptive Protection, which dynamically adjusts controls according to each user's risk level instead of applying the same policy to the whole workforce.

Communication Compliance reviews communications to detect harassment, inappropriate language or improper information sharing.

An important, non-technical warning: this has serious employment and data protection implications. None of these capabilities gets switched on without legal advice, informing employee representatives and a data protection impact assessment first. It can be done well and proportionately —user anonymisation is supported out of the box— but it is not a switch you flip on a Friday afternoon.

Compliance Manager

A dashboard that turns your actual configuration into a compliance score against specific frameworks: GDPR, ISO 27001, the Spanish ENS, NIS2, SOC 2. It tells you which actions are missing and how much each one is worth.

It does not replace an audit, and the score should not be confused with compliance. But as a tool to prioritise and to show progress to the board, it is one of the most useful things the platform ships with. And it is available in practically every plan.

DSPM and DSPM for AI

The most recent addition. Data Security Posture Management gives you a posture view: where the data risks are, which policies cover them and what is missing. Throughout 2026 Microsoft has rolled out a refreshed experience with guided flows, Security Copilot agents for triage and signals from third-party platforms.

DSPM for AI applies the same to AI usage: which tools your employees use, what data they are feeding them and with what exposure. If your organisation has adopted Copilot or any generative AI without visibility, this is where to start.

Check what you are missing with your plan

Before the tables, the practical part. Pick the plan you have and see which Purview capabilities it covers and which it does not. Nineteen capabilities, the same ones for every plan, so the comparison is fair.

Licence simulator

All of the calculation happens in your browser. Nothing is sent to any server, there is no sign-up and nothing is stored on your device.

of 19 capabilities

Pick a plan to see what it includes.

Information classification and protection

  • Manual and default sensitivity labels
  • Basic message encryption
  • Automatic labelling in Microsoft 365 apps
  • Automatic labelling in Exchange, SharePoint and OneDrive (AIP Plan 2)
  • Advanced message encryption and Customer Key

Data loss prevention

  • DLP for email and files
  • DLP in Teams chat
  • Endpoint DLP: USB, printing, uploads and generative AI

Lifecycle and records

  • Manual retention labels
  • Retention by location
  • Automatic rule-based retention
  • Machine-learning based retention
  • Records Management

Investigation, risk and governance

  • Audit (Standard)
  • Compliance Manager
  • eDiscovery (Standard) and legal hold
  • eDiscovery (Premium) and Audit (Premium)
  • Insider Risk Management and Adaptive Protection
  • Information barriers, Customer Lockbox and PAM

Frontline plans (F1 and F3) are left out of the simulator because their split works differently; they are explained further down. And since Microsoft changes plan contents often, always check with your partner before deciding.

What each licence includes: small and medium business

Microsoft 365 Business plans are capped at 300 users. This is the real split of Purview capabilities:

Capability Business Basic Business Standard Business Premium + Purview Suite
Compliance Manager
Audit (Standard)
Teams message retention
Manual and default sensitivity labels
Basic message encryption
DLP for email and files
Manual retention labels
Basic retention by location
eDiscovery (Standard) and legal hold
Automatic labelling in Microsoft 365 apps
Automatic labelling in Exchange, SharePoint and OneDrive
Labels based on advanced classifiers (EDM, named entities)
Advanced message encryption and Customer Key
DLP in Teams chat
Endpoint DLP
Automatic retention by rules and by machine learning
Records Management
eDiscovery (Premium) and Audit (Premium)
Insider Risk Management and Adaptive Protection
Information barriers, Customer Lockbox and PAM

What to read out of this table

Basic and Standard are, for Purview purposes, almost the same thing: nothing. Basic auditing, Teams retention and Compliance Manager. If your company is on Business Standard and somebody has sold you the idea that you have data protection, you do not. It is a frequent and unpleasant surprise.

The real jump is Business Premium. That is where the essentials appear: labels, DLP for email and files, eDiscovery, retention. For a smaller company doing things reasonably well, this covers most of the journey. The price difference against Standard is justified on this alone, without counting the Defender and Intune parts it also brings.

The Purview Suite for Business Premium add-on is the interesting news. Until recently, a smaller company that wanted Endpoint DLP or insider risk management had to jump to an Enterprise plan. Now it can be added on top of Business Premium, with a reference price around 10 USD per user per month (about 15 USD when combined with the Defender Suite). It can only be added on top of Premium: on Basic or Standard it is not available.

About prices

Prices are indicative list prices. The real price depends on channel, currency, commitment and agreement. Always confirm with your partner or CSP.

What each licence includes: Enterprise

The map is bigger here, and there is a trap that costs money. Let's take it in parts.

Capability M365 E3 M365 E5 O365 E3 O365 E5 E3 + Purview Suite
Audit (Standard)
DLP for email and files
Manual and container labels
Basic message encryption
Manual retention and retention by location
eDiscovery (Standard) and legal hold
Automatic labelling in Microsoft 365 apps
Advanced message encryption and Customer Key
DLP in Teams chat
Endpoint DLP
AIP Plan 2
Automatic rule-based retention
Machine-learning based retention
Records Management
eDiscovery (Premium) and Audit (Premium)
Communication Compliance
Information barriers, Customer Lockbox and PAM
Insider Risk Management (full solution)
Adaptive Protection

The trap: Office 365 E5 is not Microsoft 365 E5

The names are so similar that the confusion is constant, and it is one of the expensive ones. Office 365 E5 covers a fair amount of Purview, but it is missing pieces many people take for granted:

  • It does not include Endpoint DLP. All data protection at the workstation is left out.
  • It does not include Azure Information Protection Plan 2, that is, full automatic labelling outside the Office apps.
  • It does not include the full Insider Risk Management solution. It brings the value of Communication Compliance, information barriers, Customer Lockbox and Privileged Access Management, but not insider risk management as such, nor Adaptive Protection.
  • It does not include machine-learning based retention.

If your organisation has Office 365 E5 and someone has planned a workstation data protection project assuming that «E5 covers it», it is worth reviewing before signing anything.

Microsoft 365 E3: the honest baseline

E3 brings the fundamentals and is not badly served: DLP for email and files, manual labels, retention by location, standard eDiscovery, standard auditing. An organisation that configures just this properly is already ahead of most.

What it does not bring is automation. Anything along the lines of «let the system do it on its own» —labelling, classifying, retaining by content— belongs to the next tier. And that is exactly the difference between a policy that works at 200 users and one that works at 5,000.

The Purview Suite add-on: the middle road

This is what used to be called E5 Compliance. It is added on top of a Microsoft 365 E3 base (or Office 365 E3 + Enterprise Mobility + Security E3) and brings practically all of E5's Purview capabilities without paying for the full jump to E5.

It is the sensible option when the reason to move to E5 is compliance and data protection, and you do not need the telephony, advanced analytics or the rest of the bundle. It is worth doing the maths: in mid-sized organisations the annual difference is considerable.

There is also Microsoft 365 E7, which consolidates above E5, and standalone add-ons —E5 Insider Risk Management, E5 eDiscovery and Audit, Forensic evidence, Premium Assessments for Compliance Manager— that let you buy only the missing piece instead of a whole bundle. Few people know about them and they sometimes solve the problem for a fraction of the cost.

Frontline (F1 and F3)

Frontline worker plans cover the basics: standard auditing, manual retention labels, AIP Plan 1 and, in F3, container labelling and encryption of personal data. There are specific Purview Suite FLW add-ons to raise these profiles without paying for a full licence. If you have a large workforce in stores, on the shop floor or in the field, this detail matters a lot on the invoice.

The four mistakes I come across most

Mistake 01

Buying the licence and configuring nothing

By far the most expensive one. Organisations paying for E5 for years with Purview untouched. Licences do not protect; well-designed policies do. Before proposing a plan upgrade, the right question is what is being used of what is already paid for.

Mistake 02

Starting with the label taxonomy

Three-hour meetings arguing whether there should be four levels or five, whether Confidential covers HR material, whether a sub-level is needed. Meanwhile, zero protection deployed. Four simple labels working today are worth more than fifteen perfect ones in six months.

Mistake 03

Turning DLP on in blocking mode from day one

A straight road to mutiny. Every policy should start in audit mode, measure weeks of real traffic, tune the false positives and only then start blocking. And with warning first.

Mistake 04

Treating it as an IT project

Purview decides what information is confidential, how long it is kept and which behaviours are monitored. That is business, legal and HR. IT executes, but should not decide alone. Deployments that fail almost always fail here.

A 90-day roadmap

Without buying anything new, with what you probably already have:

The first 90 days, phase by phase
  1. Days 1–15

    Know what you have

    A real per-user licence inventory. Open Compliance Manager and note the starting score. Review the data classifiers and the sensitive content reports: Purview has been detecting things for a while even if nobody has looked. The first time that report is opened there are usually surprises.

  2. Days 16–45

    Classify and observe

    Define three or four labels, not one more. Publish them to a pilot group with a default label. Turn on the predefined DLP policies in audit mode, without blocking. Configure basic retention by location.

  3. Days 46–75

    Tune

    Analyse the DLP incidents: how many are real and how many are noise. Refine. Extend labelling to the rest of the organisation with short training —fifteen well-delivered minutes save months of resistance—. Start blocking only the clear, defensible scenarios.

  4. Days 76–90

    Measure and decide

    Compare the Compliance Manager score against the starting one. Document what has been covered of GDPR, ENS, ISO 27001 or NIS2. And now yes, with real data on the table, decide whether the licence jump is worth it and for what exactly.

Keynote

First you exhaust what you already pay for, then you buy. The other way round hardly ever works out.

How to know whether upgrading is worth it

Three questions that settle the decision better than any comparison table:

Do you hold information whose leak would cause you serious harm? Intellectual property, health data, financial information, data about minors. If the answer is yes, Endpoint DLP and automatic labelling stop being a luxury.

How many people do you have to protect? Below 100 users, manual policies still hold up. Above 500, automation stops being optional: no human team keeps classification up to date.

Is anyone going to ask you for evidence? A large customer, an audit, a public tender, NIS2, a sector regulator. If the answer is yes, eDiscovery Premium and Audit Premium pay for themselves the day you need them. And that day always arrives in a hurry.

In summary

Microsoft Purview is not a product you buy, it is a capability you build. And a good part of it is already paid for on the Microsoft 365 invoice of almost any organisation.

The useful conversation is not which licence do I need. It is what information do I hold, what can happen to it and what of what I already pay for helps me prevent that. The licence is the last question, not the first.


By the way, if what worries you is the regulatory side, this connects directly with what I wrote about what NIS2 already requires of you in Spain: a good part of the article 21 measures are covered by pieces you already have in your licence and nobody has switched on.

Any questions, I am here. No smoke.

To connect these controls with identities, applications, data and exceptions, read the Microsoft 365 security assessment guide. It explains which evidence to review and how to prioritise improvements.

← All articles

Keep reading

Microsoft ecosystem

I am a Microsoft enthusiast, and it shows in how I work

Purview, Defender, Entra ID, Intune: I have spent years inside this ecosystem and I enjoy getting the most out of it. I help companies roll it out in an organised way, in a clear order: first what information needs protecting, then what of the licence you already pay for covers it, and only at the end what is left to buy. No switching modules on at random to see what happens.

If you suspect your organisation is paying for capabilities nobody has switched on, tell me where you stand. I reply personally, no smoke and no strings attached.

Let's talk about your case