Microsoft Purview is Microsoft's data security and compliance family. Two of its products produce alerts that security operations center (SOC) analysts handle in the Defender portal, and one of its tools, Audit, is a key source of evidence in almost every Microsoft 365 investigation. Knowing where each alert comes from and who is allowed to see its contents matters, because these alerts often involve sensitive data and people inside the organization. Data loss prevention (DLP) policies detect sensitive information, such as credit card numbers or files with a sensitivity label, being shared, emailed, uploaded or copied in ways the policy forbids. They can apply to Exchange, SharePoint, OneDrive, Teams, endpoints and more. When a policy match generates an alert, the alert appears on the Purview DLP alerts page and also in the Defender XDR incident queue, where it can be correlated with other alerts. For example, a DLP alert for mass upload of customer data can join an incident with an impossible travel alert for the same user. Analysts need the right Purview roles to view DLP alert content, because it may contain the sensitive data itself.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.