Microsoft 365 FundamentalsDescribe security, compliance, privacy, and trust in Microsoft 365Medium

A global corporation needs to ensure that all data stored in Microsoft 365 services, regardless of its location, complies with the General Data Protection Regulation (GDPR). Which Microsoft 365 capability is primarily responsible for helping to identify, classify, and protect sensitive personal data to meet such regulatory requirements?

  1. AMicrosoft Purview eDiscovery
  2. BMicrosoft 365 Defender for Cloud Apps
  3. CAzure AD Identity Governance
  4. DMicrosoft Purview Information Protection (MPIP)
Show answer & explanation

Correct answer: D. Microsoft Purview Information Protection (MPIP)

Microsoft Purview Information Protection (MPIP) is designed to help organizations discover, classify, label, and protect sensitive information across their digital estate, which is crucial for meeting data protection regulations like GDPR.

Why the other options are wrong

  • A. eDiscovery focuses on finding data for legal requests, not continuous classification and protection.
  • B. Defender for Cloud Apps is a Cloud Access Security Broker (CASB) for monitoring and protecting cloud apps, not primarily for data classification and protection within Microsoft 365.
  • C. Azure AD Identity Governance focuses on managing user identities and access, not data classification and protection.

Microsoft Purview Information Protection (MPIP)

A unified data governance solution that helps organizations discover, classify, label, and protect sensitive information across clouds, apps, and devices.

  • Provides automatic and manual data classification.
  • Applies labels that enforce protection (encryption, access restrictions).
  • Helps comply with data privacy regulations like GDPR.

Memory trick: Protect your data with PURVIEW labels, from discover to secure.

More Describe security, compliance, privacy, and trust in Microsoft 365 questions