> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/purview.md).

# Purview

Purview brings three Microsoft Purview data governance tools — **Data Loss Prevention (DLP)**, **Retention**, and **Sensitivity Labels** — into the same cross-tenant, template-and-deploy workflow you already use for Conditional Access, Intune, and Defender. Instead of opening the Microsoft Purview portal for every client, you build a policy or label once in Augmentt and push it to one tenant or many.

{% hint style="warning" %}
Purview is a separately licensed add-on, not part of the base Secure module. If a client isn't authorized for it, every tab shows a message directing you to contact **<sales@augmentt.com>** instead of the usual controls.
{% endhint %}

You'll find it at **Secure > Purview**, split into three tools, each with its own tab set:

* **DLP** — **Policies** and **Templates**
* **Retention** — **Retention policies**, **Labels**, and **Templates**
* **Sensitivity Labels** — **Labels** and **Templates**

{% hint style="info" %}
This page is a first-pass overview. Some capabilities described below (noted inline) are still partial — Augmentt can display or manage them only up to a point, and the rest is done in the Microsoft Purview portal.
{% endhint %}

## Background: what these three tools actually are

Since Purview terminology gets confused easily, here's the short version of each concept before getting into Augmentt's UI:

* **DLP (Data Loss Prevention)** — policies that detect sensitive information (credit card numbers, health records, custom patterns, and so on) in motion or at rest and take action: block sharing, show the user a policy tip, notify an admin, or just log a match. A DLP policy is made of one or more **rules**, and rules are evaluated in **priority** order.
* **Retention** — policies that keep or delete content automatically. Microsoft splits this into two distinct things:
  * A **retention policy** is container-level: it targets locations (mailboxes, SharePoint sites, OneDrive accounts, Teams chats/channels) and inherits down to the content in them.
  * A **retention label** is item-level: a tag applied to an individual email, document, or record with its own retention behavior, independent of where that item lives.
* **Sensitivity labels** — classifications (like *Confidential* or *Highly Confidential*) that users or automation apply to files, emails, and containers (Teams/groups/sites) to trigger protection: encryption, access restrictions, content marking (headers/footers/watermarks), and container-level controls like external sharing and guest access. A sensitivity label is a reusable definition. A separate object, a **label policy**, is what actually publishes a set of labels to specific users or groups and decides who sees which labels and whether labeling is mandatory — the label and the policy that distributes it are not the same thing.

## DLP

**Secure > Purview > DLP > Policies** lists every DLP policy on the selected tenant, with its **Priority**, **Mode**, sync status with Microsoft, and last-changed timestamp. Priority is editable directly from the list (move up/down, or move to top/bottom) since Microsoft evaluates DLP rules in priority order. Selecting a policy opens a detail view with its full rule set and location scope, matching what you'd see in the Purview portal.

**Mode** reflects Microsoft's DLP lifecycle:

* **On** — the policy is enforcing its actions.
* **In simulation (with or without notifications)** — Microsoft evaluates matches without taking action, so you can see what the policy *would* have caught before turning it on. Augmentt shows simulation progress and how many items matched.
* **Off** — the policy exists but isn't evaluated.

### Creating and deploying a DLP policy

1. From **Templates**, either build a new template or convert an existing live policy on a tenant into a reusable one.
2. From **Policies**, deploy a template to the selected tenant, or use the **baseline** deploy option to push it to a group of tenants at once.
3. At deploy time you choose the **mode** to start in — leave it off, run it in simulation first, or turn it on immediately — and configure locations (Exchange, SharePoint, OneDrive, Teams, endpoint devices, Power BI, and more, depending on the template) plus per-location inclusions and exclusions.
4. Augmentt validates policy and rule names against what already exists on the target tenant before deploying, since Microsoft requires DLP rule names to be unique across all policies in a tenant and will reject a deployment that collides.

Deployed policies and their rules can be edited and deleted from Augmentt afterward; deleting a policy queues the corresponding removal in Microsoft Purview.

## Retention

**Secure > Purview > Retention** separates **Retention policies** (container-level) from **Labels** (item-level, called retention labels) — matching Microsoft's own model — plus a **Templates** tab for both.

### Retention policies

The **Retention policies** list shows each policy's **Status** (Active / Not active — retention policies don't have DLP's Test/Enforce concept), **Scope** (entire tenant, static targeting, or an adaptive scope shown read-only), included/excluded locations per workload, **Duration**, and the **Action at end of period** (retain only, retain then delete, or delete only). Selecting a policy shows the full field-level detail, including admin units and sync status.

{% hint style="warning" %}
After a create, edit, or delete, a policy can show **Pending Propagation** while Microsoft finishes applying the change — Microsoft Purview can take up to a week to fully propagate a retention policy. Editing stays unavailable until sync completes.
{% endhint %}

Creating and deploying a retention policy works the same template → deploy pattern as DLP: pick a duration, an end-of-period action, when the retention clock starts (from creation or last modification), and the locations and scope (entire tenant or selected groups — Augmentt never defaults this, you choose every time). One Microsoft constraint carries through to the UI: a single static retention policy can't mix Teams locations with Exchange/SharePoint/OneDrive, so Teams retention uses its own policy type.

### Retention labels

The **Labels** tab manages retention labels directly — their label type (Retain, Record, or Regulatory record), what happens during and after the retention period (just label items, retain them, or retain-then-enforce an action), and when the clock starts (creation, last modification, labeling, or a defined event). As with Microsoft's own portal, a label's **name** can't be changed once created — only its description and settings.

## Sensitivity Labels

**Secure > Purview > Sensitivity Labels** is the most fully built-out of the three tools. The **Labels** tab lists every sensitivity label on the tenant with its **Priority** (editable, same pattern as DLP — higher processes first), **Scope Content Type**, parent/sublabel relationship, and status.

Creating or editing a label covers essentially the full Purview label surface:

* **Scope** — which content types the label applies to (files, emails, groups & sites, meetings, Purview assets, other schematized data).
* **Label color** and a **tooltip** shown to users when choosing it.
* **Protection settings** — content marking (header, footer, and/or watermark, each with its own text), encryption/**access control** (assign permissions to specific users, groups, or domains, or let users decide when they apply the label — this requires Azure Rights Management to be active on the tenant), and content-expiration or offline-access limits.
* **Groups & sites settings** (when the label's scope includes containers) — privacy level, external sharing, guest access, unmanaged-device access via Conditional Access, and private-team/shared-channel discoverability. These require sensitivity labels for containers to already be enabled in the Microsoft Purview portal; Augmentt surfaces a clear prompt if it isn't.

{% hint style="info" %}
A handful of label configurations are edit-only in Microsoft Purview itself: parent label groups, and labels using a scope Augmentt doesn't yet support editing. Augmentt shows why editing is disabled in those cases rather than silently failing.
{% endhint %}

{% hint style="warning" %}
Augmentt manages the labels themselves — not **label policies** (the separate Microsoft object that publishes labels to specific users/groups and controls things like a mandatory default label). Publishing labels to users is still done from the Microsoft Purview compliance portal.
{% endhint %}

## Fleet view

Switching to **All Companies** on the Retention Policies, Retention Labels, or Sensitivity Labels tabs (DLP fleet view follows the same pattern) shows every connected tenant with a simple status per tenant — loading, a count of policies/labels, empty, or an integration error — so you can scan for gaps across your whole client base before drilling into any one tenant. Because Microsoft has no single cross-tenant Purview API, this is always one request per connected tenant rather than a single combined call, so a slow or failing tenant never blocks the others from loading.

## How deployment actually works

Everything you create or change in Augmentt's Purview tools is applied to the customer's tenant through Microsoft's **Security & Compliance PowerShell** cmdlets (the same plane behind the Purview compliance portal) — not the Microsoft Graph API. Augmentt queues the change as a background task against the tenant and polls it to completion, the same task-based pattern used elsewhere in Secure. This is also why a change can take time to fully reflect in Purview: Augmentt is waiting on the same Microsoft-side propagation any admin would see making the change by hand.

## What Purview does not do yet

To keep this page honest about scope:

* There's no dedicated Purview entry in **Compliance Audit** today — Purview policies aren't currently checked against a compliance assessment or scored the way Conditional Access and other Secure settings are.
* Sensitivity **label policies** (publishing labels to users, setting a mandatory or default label) aren't manageable from Augmentt — only the labels themselves are.
* Retention labels are managed directly (no template/deploy layer of their own yet); retention **policy** templates currently convert from a live Exchange Online policy — SharePoint, OneDrive, and Teams retention templating/deployment are expected in a future release.

## In this section

* [DLP](/modules/secure/purview/dlp.md)
* [Retention](/modules/secure/purview/retention.md)
* [Sensitivity Labels](/modules/secure/purview/sensitivity-labels.md)

Each page covers that tool's full configuration surface and an honest note on default templates (Purview ships none) and posture-check coverage (none today).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/purview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
