Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceHard

A global company needs to ensure that specific sensitive information types (SITs) are consistently detected and protected across all Microsoft 365 services, including Exchange, SharePoint, OneDrive, and Teams. They also require that these SITs are recognized in their custom line-of-business applications. Which method allows for the creation of custom sensitive information types that can be deployed across both Microsoft 365 and external applications?

  1. ALeveraging trainable classifiers for content identification
  2. BDeveloping custom sensitive information types with PowerShell and XML
  3. CCreating keyword dictionaries in Purview
  4. DUsing exact data match (EDM) sensitive information types
Show answer & explanation

Correct answer: B. Developing custom sensitive information types with PowerShell and XML

Custom sensitive information types (SITs) can be created using PowerShell and XML definitions. This method allows for highly specific pattern matching (regular expressions, keywords, proximity) and can be deployed across various Microsoft 365 services. More importantly, these custom SITs can also be used in conjunction with Microsoft Information Protection SDK to extend detection and protection to custom line-of-business applications, fulfilling the requirement for broad recognition.

Why the other options are wrong

  • A. Trainable classifiers are good for identifying content based on examples but are not for defining rule-based sensitive information types or deployment to external apps.
  • C. Keyword dictionaries are components of SITs but don't define the entire SIT or enable deployment to external apps independently.
  • D. EDM SITs are for detecting exact matches of structured data, not for defining new pattern-based SITs or deploying to custom apps directly.

Custom Sensitive Information Types (SITs)

User-defined patterns (regex, keywords, proximity) for identifying sensitive data that can be used across Microsoft 365 services and extended to external applications via the MIP SDK.

  • Created using PowerShell and XML definitions.
  • Allow for highly specific and complex pattern matching.
  • Used by DLP, sensitivity labels, and other Purview features.
  • Can be integrated with the Microsoft Information Protection SDK for custom apps.

Memory trick: Custom SITs: Your personal data bloodhound, even for external apps.

More Implement and manage Microsoft Purview compliance questions