StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 2: Respond to security incidents

Microsoft Purview: DLP and insider risk alerts in the Defender portal; Purview Audit (unified audit log) searches

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Microsoft Purview is Microsoft's data security and compliance family. Two of its products produce alerts that security operations center (SOC) analysts handle in the Defender portal, and one of its tools, Audit, is a key source of evidence in almost every Microsoft 365 investigation. Knowing where each alert comes from and who is allowed to see its contents matters, because these alerts often involve sensitive data and people inside the organization. Data loss prevention (DLP) policies detect sensitive information, such as credit card numbers or files with a sensitivity label, being shared, emailed, uploaded or copied in ways the policy forbids. They can apply to Exchange, SharePoint, OneDrive, Teams, endpoints and more. When a policy match generates an alert, the alert appears on the Purview DLP alerts page and also in the Defender XDR incident queue, where it can be correlated with other alerts. For example, a DLP alert for mass upload of customer data can join an incident with an impossible travel alert for the same user. Analysts need the right Purview roles to view DLP alert content, because it may contain the sensitive data itself.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan