A law firm must preserve matter-related email while letting staff collaborate on draft documents. At the same time, it wants to prevent confidential client files from leaving managed systems and respond to legitimate deletion requests. These obligations are related but not identical. Retention, sensitivity labels, data loss prevention, auditing and eDiscovery operate for different purposes, and a simplistic ‘keep everything secure’ instruction can create conflicts between them.
Microsoft MS-102 includes Microsoft Purview compliance capabilities within the Microsoft 365 administrator role. The exam is scheduled to retire on November 30, 2026; candidates testing before then should use Microsoft’s April 2026 study guide and check the current schedule. In practice, Purview design is an exercise in translating legal and information-governance requirements into enforceable, testable policies across Microsoft 365 workloads. Licensing, location, user behavior and the lifecycle of each record all affect what a policy can actually accomplish.
Classify information before applying blanket controls
Data classification should identify why information matters, who needs it and what harm would follow inappropriate use. Client case files, public marketing materials, employee medical records and ordinary operational documents require different treatment. Labels can express sensitivity and influence protection behavior, but the scheme must be understandable to users. Too many near-identical labels encourage guesswork; a single ‘confidential’ label may be too broad to drive meaningful safeguards. Work with business owners to define categories, examples and consequences.
Test classification against real document workflows. A spreadsheet may contain personal information without an obvious filename clue; a Teams conversation might quote a fragment of a sensitive record; a PDF may carry classifications that automated inspection struggles to interpret. Auto-labeling and recommended labeling can help, but teams need a process for review, exceptions and mistaken matches. A label applied in one service should not be assumed to produce identical protection across every collaboration endpoint. Verify effective encryption, sharing and access behavior where the material is actually used.
Distinguish preservation from prevention
Retention policies and labels support keeping or disposing of content according to business and legal needs. Data loss prevention attempts to detect or limit risky handling and disclosure. Neither replaces the other. A file may need to remain preserved for an investigation while a DLP rule prevents an unauthorized external share. Similarly, a deletion request may be constrained by a legitimate legal hold. Document precedence and involve counsel when obligations conflict; a security administrator should not invent a legal answer from a portal setting.
Set retention periods according to record class, jurisdiction and business process rather than convenience. Extremely long retention can increase cost and breach exposure, while premature deletion can destroy required evidence. Record which workloads and locations a retention policy covers, how it treats edits, and how exceptions or holds affect disposition. Run controlled tests with sample records and retain evidence of results. Policy coverage must be revisited when the company adopts new storage locations or changes collaboration patterns.
Make DLP rules understandable and proportional
DLP should respond to recognizable data risk, not merely count sensitive strings. A rule detecting financial identifiers may create false positives when a document contains public sample values; a poorly scoped exception may allow an actual disclosure. Combine conditions, content context, locations, user groups and action severity. In some workflows warnings and justification prompts support legitimate business; in others blocking is necessary. Decide by consequence and documented risk appetite. Monitor repeated overrides and investigate whether the rule or business process needs redesign.
Endpoint DLP, Exchange and collaboration controls can have different enforcement paths and dependencies. Device onboarding, service configuration and license entitlements matter. Before declaring that a rule protects data ‘everywhere,’ test email attachments, browser uploads, synced folders, Teams sharing and unmanaged devices as appropriate. A blocked demonstration on one endpoint proves only that path. An effective test plan includes permitted use cases so security does not accidentally turn an ordinary client deliverable into a constant support issue.
Handle investigations with precise access controls
Audit and eDiscovery capabilities support responding to incidents and legal requests, but investigators should only obtain the authority needed for the matter. Separate policy administrators from reviewers when practical and log access to sensitive search results. Searches can gather information beyond the intended person or time period; define scope and preserve the rationale. Exporting content creates another controlled copy that requires security, retention and eventual disposition. A defensible investigation is traceable from request to search to export and action.
An audit event is not always immediate or complete for every workload. Understand service-specific coverage, retention and permissions before asserting that a negative search proves nothing occurred. Correlate activity with other operational evidence when stakes are high. Keep procedures for legal holds, case access, review and closure sufficiently clear that substitute staff can execute them. The correct protection is not maximum secrecy; it is accountable handling that preserves rights, evidence integrity and business continuity.
Govern external collaboration and the content lifecycle
Sensitive content rarely stays within one site. Teams links, SharePoint sharing, email forwarding and external guest collaboration create legitimate paths for work and opportunities for error. Combine identity permissions, sharing configuration, sensitivity protections and DLP where justified. The controls must recognize who is authorized to collaborate, not simply whether a recipient is outside the company. A contractual project might require restricted external participation, whereas a legal hold may require preservation regardless of whether a particular collaborator retains access.
Changes to user role or project ownership can leave old permissions in place. Review external links, orphaned sites, expired projects and copied data according to impact. The original classification may not follow every export or conversion, so document where the system of record remains authoritative. Information governance is a continuous lifecycle: creation, collaboration, modification, archival, disposition and investigation. Optimize for clear ownership at each stage rather than one central rule expected to solve every case.
A worked Purview policy conflict: retention meets deletion
A consultancy receives a request to delete a departed employee’s personal information while litigation counsel requires preservation of records related to a client dispute. Some relevant material is in email, some in Teams conversations and some in archived SharePoint libraries. A compliance administrator should not click a global deletion control or blanket hold without establishing which records and jurisdictions are involved. The team inventories record locations, legal obligations, data owners and the individuals authorized to approve preservation or disposition.
The legal hold applies to appropriately scoped matter records, with search and review privileges limited to the investigation team. Ordinary retained business documents continue to follow approved disposition schedules, while nonessential personal information is handled according to the legitimate deletion process. Sensitivity labels and DLP policies protect ongoing sharing, but they do not replace either hold or disposal rules. The administrator tests representative items in each workload and documents any delay or coverage limitation. A new Teams channel or copied export should not silently escape the policy map.
The case is closed only after counsel verifies required evidence is retained and privacy stakeholders confirm the disposition actions permitted by law and policy. Audit records show who changed holds, accessed searches and exported materials. Reviewers also check that shared links and privileged roles were removed when no longer needed. The lesson is not that every document should be retained forever. It is that preservation, prevention, investigation and disposal are separate capabilities whose interaction must be understood before an administrator automates a consequential action.
Make information-governance controls auditable
A policy implementation should include representative records, expected decisions and a way to verify the actual result. Test one document that must be retained, one eligible for disposition, one protected from external sharing and one legitimately shared with a partner. Follow each through the relevant Microsoft 365 services rather than assuming consistent behavior from identical names. Record policy scope, exclusions, inherited permissions and the licensing features on which enforcement depends. Auditors can then examine a real control rather than a screenshot of a configuration screen.
Governance teams also need a mechanism for ambiguity. Users may not know which label fits a draft proposal containing both public marketing text and confidential pricing assumptions. Give them examples and an accessible review path, and track recurring confusion to improve the classification scheme. When two obligations conflict, the administrator should preserve evidence and seek the appropriate decision from legal or privacy owners. Technical enforcement is strongest when its purpose can be explained in ordinary business language.
Test governance with scenarios that can fail
A useful acceptance exercise gives a designated user a labeled file, then asks them to complete allowed work and attempt a disallowed transfer. Observe whether controls protect the sensitive content, explain the restriction and generate the expected audit records. Repeat with a new device, an external guest and a file that only partly matches the detection pattern. The gaps may be in classification, identity, product coverage or workflow design. Treat them as engineering findings with owners and dates.
For MS-102 study, distinguish sensitivity labels from retention labels, retention from DLP, and investigation permissions from ordinary data access. The technologies overlap, but their purposes and enforcement layers differ. The exam will soon retire, yet these distinctions remain foundational for any Microsoft 365 environment that needs to protect information while still letting its users work.