Cost calculations, contracts, HR records and planning data are spread across SharePoint, Teams and mailboxes. Microsoft Purview makes sure this content is discovered, classified, protected and retained in line with regulations.
Purview does not replace SharePoint and Teams β it adds protection rules to them. The key difference to classic permissions: the protection is attached to the document itself and travels with it, regardless of where it is later stored or shared.
π― At a Glance
Purview acts as a shield that travels with the document β independent of its storage location.
A great deal is already included in Microsoft 365 E3: manual labels, encryption, site classification and DLP for Exchange, SharePoint and OneDrive.
Additional cost only arises with auto-labeling (Premium) and Teams and Endpoint DLP (E5) β and only for the users who benefit from them.
π‘ The basic idea: five questions Purview answers
Know β Where does sensitive data reside?
Classify β How protection-worthy is it?
Protect β Who may open and share it?
Monitor β Where is data at risk of leaking?
Retain β How long is it legally required?
Six functional areas cover the lifecycle of documents worth protecting β each shown here with a typical example from a construction environment:
| Functional area | What it covers | Construction example |
|---|---|---|
| Classify | Sensitivity labels for files, emails, sites and teams | Mark a cost calculation as "Confidential" |
| Protect | Encryption, access rules and visible marking | Contract openable by project management only |
| Prevent data loss | DLP detects and controls risky sharing | Do not share HR data externally |
| Retain | Retention policies and labels govern deadlines | Keep the contract file for the required period |
| Trace | Audit and activity logs show every action | Who approved the drawing? |
| Compliance & risk | Records management, eDiscovery and risk management | Locate documents in a legal case |
In practice the functions run in four steps that build on one another:
1. Discover β Purview finds sensitive content and its storage locations.
β HR data sits in a project library
2. Classify β a sensitivity label describes the protection class.
β Label "Highly confidential β HR"
3. Protect β encryption and rights secure the content.
β Only authorised HR users can open it
4. Govern β DLP and retention control sharing and storage periods.
β Block external sharing, keep the retention period
β οΈ Frequently misunderstood
A label on a site or a team is not automatically inherited by the files it contains. Containers and files are two separate layers and must be planned separately.
A large share of the Purview functions is already included in Microsoft 365 E3. Additional cost only arises with Premium and E5 functions:
| Function | Licence | Construction example |
|---|---|---|
| Manual sensitivity labels | E3 | Mark a calculation or contract as "Confidential" |
| Encryption & access protection | E3 | Contract openable by project management and purchasing only |
| Site and team classification | E3 | Secure a project area shared with external partners |
| DLP for Exchange, SharePoint & OneDrive | E3 | Warn or block external sharing of sensitive documents |
| Automatic classification (auto-labeling) | Premium | Detect HR and calculation data automatically |
| Default label per document library | Premium | Classify new contract documents automatically |
| Teams chat and channel DLP | E5 | Check account and personal data directly in the project chat |
| Endpoint DLP (USB, copy/paste, upload) | E5 | Control copying of confidential calculations to USB |
| Audit Premium & advanced records | E5 | Support formal construction files and investigations |
Note on the licence information
Microsoft adjusts licence models and feature scopes regularly. Verify the specific SKUs and the current feature scope with Microsoft before making a purchasing decision.
Microsoft's basic rule is: every user who benefits from a Purview function needs the matching licence. What counts is therefore the function and the circle of people benefiting β not the department alone.
| Protected location | Examples | Who needs the licence? |
|---|---|---|
| Personal locations | Exchange mailbox, OneDrive, Teams chat, device/endpoint | Every user who uses the function |
| Shared areas | SharePoint site, Microsoft 365 group, Teams channel | Owners and members of the protected area |
π‘ Example: HR records
If only HR mailboxes and files are protected, licensing for HR alone may be sufficient.
If the same protection sits on a shared site, its other members count as well.
β Visitors and read-only users do not need a licence.
Rather than a blanket full rollout, a three-stage approach is advisable β each stage only starts once the previous one has demonstrated a real need:
START HERE Stage 1 Β· E3 baseline Manual labels, encryption, site and team classification, DLP for Exchange, SharePoint and OneDrive, Audit Standard, basic retention. No additional licence cost, provided E3 is already in place. | Stage 2 Β· Targeted Premium Auto-labeling, default label per library and advanced information protection β targeted at HR, purchasing and particularly sensitive projects. Additional cost for a small number of users only. | Stage 3 Β· E5 / broad Premium Teams DLP, Endpoint DLP, Audit Premium as well as advanced records and compliance β where the need is proven. Additional cost for everyone who benefits. |
TeamswareOne provides the project structure, Purview provides the protection. The matching building blocks already exist in Teamsware Studio:
This allows protection rules to be rolled out directly when a project is created β instead of applying them manually to each site afterwards.
π― Teamsware recommendation
Start with what your existing E3 licence already provides. Most protection requirements in a construction environment can be covered with it β add Premium and E5 functions only once a concrete gap has been demonstrated.
π‘ Quick reminder
Permissions = who gets to the location
Purview label = what applies to the document, everywhere
DLP = what the document is allowed to leave with
Retention = how long it is kept
Teamsware GmbH Β· LeopoldstraΓe 31 Β· 80802 MΓΌnchen Β· www.teamsware.eu