Module 7 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: why protection should travel with the data, sensitivity labels and what they enforce, a three-label taxonomy for small businesses, DLP policies for Australian sensitive information, and a simulation-first rollout in the Purview portal.
Data Protection with Microsoft Purview
Protection that travels with the file
Everything in this pathway so far has been about guarding the building: who can sign in, which devices get through the door, where files are allowed to be shared from. That matters, and you have done the hard yards. But there is a catch. The moment a file leaves the building, all of those controls stay behind.
Someone attaches the client spreadsheet to an email. Someone copies the payroll file to a personal OneDrive to finish it over the weekend. None of it malicious, all of it perfectly ordinary, and every folder permission you set so carefully now protects an empty shelf.
This final module flips the model. Instead of protecting the place a file lives, Microsoft Purview lets you attach the protection to the file itself, so it travels wherever the file goes. Two tools do the work: sensitivity labels, which classify and protect the data, and data loss prevention (DLP), which watches for sensitive information heading out the door and steps in.
A locked filing cabinet is wonderful security right up until someone photocopies the file and posts it. A sensitivity label is more like sealing the document in an envelope only the right people can open. Copy it, email it, lose the laptop it sits on, and the envelope is still sealed.