We use Microsoft Purview to protect sensitive transactional data. We can control organizational policies such as who can monitor the system and how data is shared between managed apps and enrolled devices. We create the data loss prevention policy.
Microsoft architect at Kyndryl
Helps save us time, and cost, and improves our compliance
Pros and Cons
- "Purview helps mitigate risk and allows us to govern the information being shared among apps and devices."
- "I would like to have AI functionality on the dashboard to help me analyze and report on the data that we capture using Purview on a daily basis."
What is our primary use case?
How has it helped my organization?
Purview can deliver data protection across multi-cloud and multi-platform environments. For example, we can set up a multitenant environment across different vendors and control Purview through Azure. Our enterprise licensing allows us to extend the connectors and tokens to other vendors. Once the connectors are active, they streamline the same functionalities and policies across the data on the other clouds.
Purview can connect to iOS, Mac, Android devices, and other SaaS apps, provided that we have created enrollment profiles for the other devices in Microsoft Azure. We can then monitor those devices from a central Microsoft location.
Microsoft Purview's natively integrated compliance across Azure Dynamics 365 and Office 365 is important because all escalation auto breaches from Microsoft or our data loss prevention policy will be highlighted to our program manager and portfolio manager. Therefore, we must treat this as a service-level agreement breach. The most important thing is to ensure that we are alerted whenever sensitive data is sent across 18 servers, Microsoft Office 365, or by people using their hybrid environment to connect to Office 365.
It is important that Purview was built taking into account the critical regulations from around the world because one of the accounts I support is a financial institution from the UK with offices in Europe. As a result, we have new regulations to comply with. We had a different region-wide DLP setup for the UK and Europe, but we needed to ensure that it was within the new Purview system and that data could not move out of it. To achieve this, we have people in Europe working on certain governance and risk portfolios that we have created using Microsoft Azure and Purview. We also share this information with our audit team, which comes in from outside to verify it every quarter.
We have an in-house process for handling policy violations. Purview's DLP for remediating policy violations helps us. For certain categories of transactional and social ethics violations, we capture data on any copying of sensitive data. This is because sensitive data should not be shared. We capture this data using our exchange server. It is difficult to share sensitive data, but we can capture it. We then share this data with our ombudsman team. The ombudsman team will review the data, including the timestamps and users involved, and determine what action to take. In rare cases, the person responsible for the violation may be removed from the team or organization.
Awareness of mobile device monitoring must be shared across the organization, especially with end users who may not be aware that their actions are being monitored. Training should be provided to all users of enrolled devices, regardless of whether they use Intune or another endpoint server. There are three sets of training, End-user training, Admin training, and Global provider user training.
Over the past two years, we have improved our relationship with external auditors. In the first year, it was challenging to implement DLP policies. However, in the second and third years, we have had fewer than ten violations. These violations were typically due to users accidentally accessing sensitive data without their knowledge. We have been able to significantly reduce our policy violations in the past three years using Microsoft Purview.
Purview has helped us reduce the number of solutions we need to interact with each other. We used to have a lot of L1 tickets that came in earlier, where there was a policy change or configuration change being done. And then we didn't have a proper change process or control over the data that had been accessed, because it was in a shared model. This led to SharePoint violations. Now that this has been reduced, we have proper version control, and anyone accessing these resources must check IAM. As a result, those L1 tickets, which were more than a thousand in the first year, have been reduced to less than a hundred or so, in terms of SharePoint access violations. So, this is one area where we have seen a significant drop because the IAM and the user's profile now determine whether they have read and write access.
Our visibility into our estate has improved significantly with Purview. We started a pilot project, and the project manager who owns this portfolio is already running the show, even before the policy is set for the organization itself. This level of visibility was tested in a small pilot project, and now the project manager has full visibility.
Microsoft Purview allows us to demonstrate our compliance in real time. On the default dashboard, we can see the number of phones that have violated the DLP policy that we created. We can then determine which standard was breached, such as ISO or BIS. We use Purview for weekly compliance calls with the client as well.
Purview helped streamline our meetings with compliance regulators by making it easier to share data with them.
Microsoft Purview has helped us reduce our time to action on insider threats. Before Purview, we manually managed our insider threat detection process using a weekly Excel report with a macro. This meant that if a breach occurred on Monday, we would not review the report until the following Monday, resulting in a one-week time to action. With Purview, we can now take action as soon as Purview detects the violation.
Purview has saved our admin teams 99 percent of their time spent investigating violations. In terms of cost savings, Purview is included with our E5 license. The savings are significant.
Purview helps us maintain compliance. It gives us full control over our data, and when there is a violation, we can follow our established procedures to decide whether to call the ombudsman or if the process setup is sufficient.
What is most valuable?
Purview helps mitigate risk and allows us to govern the information being shared among apps and devices. Purview can restrict access from even the smallest threats, such as a mobile device trying to access and manage apps.
What needs improvement?
I would like to have AI functionality on the dashboard to help me analyze and report on the data that we capture using Purview on a daily basis.
Buyer's Guide
Microsoft Purview Data Governance
February 2025

Learn what your peers think about Microsoft Purview Data Governance. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Microsoft Purview for three years.
What do I think about the stability of the solution?
Purview is stable and always available because it is a SaaS service, which means we don't have to worry about the infrastructure.
What do I think about the scalability of the solution?
Purview is scalable depending on the number of transactions we want to monitor per day.
How are customer service and support?
Whenever we had an issue with Purview during the test phase of setting up DLP, we would call Microsoft Premium Support. They responded immediately and assigned a support engineer to our case right away. The support engineer would escalate the issue to their internal product group team, who would update Purview on the backend with a patch. The product group team would then let us know that our feedback on the product had been accepted and that they had worked on a solution, which would be released within the next week or quarter along with other updates. Overall, we were very pleased with their support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Microsoft Purview, we used a feature in Intune called data analytics to record what users access and the transactions they perform. However, this data was not meaningful, and there was no way to filter it to identify breaches. As a result, we had to manually review all of the transactions for all users in the organization to see if any were violations.
Microsoft Purview is able to capture breaches because we use tags to properly understand the data and identify violations. For example, we can tag all transactions involving credit card numbers. When we run the ETL tool, it uses the tags to identify transactions that may be violations.
How was the initial setup?
Initially, deployment will occur once the data is confirmed by the ETL team and properly ingested. This process typically takes a few weeks, depending on the volume of data. Once the initial deployment is complete, we will design and test the DLP and UAT systems. This process typically takes two weeks to a month.
Once it is deployed to production, any future changes or updates must be approved by a cabinet review board, and we must have a rollback plan in case anything affects production.
We have eight engineers who work at different levels to ensure that the data is furnished correctly, regardless of whether it is structured or unstructured, how it is being populated, or where the data loss prevention process runs daily. We also have a couple of managers and a scrum leader, as well as a portfolio manager.
What was our ROI?
When we implemented Purview, we were able to reduce our staff by 60 percent. We no longer need compliance officers to manually check spreadsheets for changes or breaches. In addition to the staff reduction, we have SLAs that require us to pay penalties to our clients if there is a violation. With Purview, the number of SLA breaches has been significantly reduced, saving our organization over one million dollars.
What's my experience with pricing, setup cost, and licensing?
Microsoft Purview requires a Microsoft 365 license and is included with an E5 license. The license is expensive, but it is worth the cost because of all the tools it includes.
What other advice do I have?
I would rate Microsoft Purview nine out of ten.
Purview is a cloud-based SaaS product. We keep our sensitive data on-premises, but we export a de-identified version (.NET) to the cloud in order to review reports for violations.
I recommend Microsoft Purview, especially for organizations that are already using Azure. Purview can be used to extend their risk governance capabilities in a seamless manner. There are other solutions available, but Purview is flexible and offers hybrid, cloud, and on-premises options with connectors for other vendors.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner

Vice President at Morgan Stanley
User friendly with good documentation but needs to cover more non-Microsoft use cases
Pros and Cons
- "The documentation is very exhaustive. Anyone can go ahead and try different use cases."
- "Non-Microsoft use cases are not very high. It's limited for now."
What is our primary use case?
The use cases for the solution include data governance, metadata management, creating business grocery, doing data lineage out of the data within the entire data stack and technology stack, and, at the same time, creating data stewardship using the policy procedures. We're implementing the policy procedures, and using workflows for automating the task.
How has it helped my organization?
The organization really doesn't have any security solution, however, they want to start their journey. It's an easier way to get started if they are already on the Microsoft side. It allows them to start with basic, common capabilities.
What is most valuable?
The inheritance feature is very good.
It is user-friendly. It’s cloud native and uses the Azure Stack which makes the deployment easy.
The documentation is very exhaustive. Anyone can go ahead and try different use cases.
Purview delivers data protection across multi-cloud and multi-platform environments, including AWS and GCP. Many organizations have a Windows operating system along with other Microsoft protection capabilities. The integration with risk and compliance is good. Microsoft has been across various areas of product expertise and covered everything under its umbrella.
It is important that Purview can connect to iOS, Mac, and Android devices, and data in other SaaS apps. It makes it easier to integrate everything. You don’t have to be specific to Microsoft products. It makes it more flexible.
It is important to us that Purview has taken into account critical regulations from around the world. They have captured most of the popular ones that are there. Many of the solutions still don't have this entire capability. When it comes to regulation and compliance, they have tried to get the most out of it and it’s included as part of PowerEdge.
We use the solution for data loss protection. For remediation. on a scale of one to five, it comes to around four. The security protection component was anyway there. They are just building on top of that and building above that.
Purview data loss protection is good at educating users on how best to handle sensitive data. There are learning and training modules available, which are helpful. It is still not there among the leaders as there are some organizations that are purely security solutions. Still, they have an edge over human identity governance. While they are not the leaders yet, they are trying to be there by trying to continuously improve and trying to provide the best of their capabilities.
Purview has helped us to reduce the number of solutions we need to interact with to some extent. Basically, it tries to solve some of the common problems raised with respect to governance.
The solution has helped improve visibility. It’s taking us to maturity level three by having the visibility aspects in place.
We haven’t used AI too much. The classification components are primarily being used. Other than that, it does have some features when it comes to text mining and identifying the EMEA site. To some extent, they have those AI capabilities and we'll try to leverage that more. We’ve been able to remove some manual activities. It was able to solve some of the problems based on the parameters and thresholds that had been defined.
It's helped provide us with a more precise, clear understanding of our data.
Purview enables us to handle our compliance in real time.
It does have regulation-specific templates that could be directly used to start with the journey of doing assessments identifying the maturity and then closing the gap as part of the gap assessment.
Purview helped to reduce the time to action on insider threats to some extent. We weren’t dependent on it much yet. We’ve used other vendors and technologies for that.
We went for an enterprise module. It helps us to start the journey. With it, we can start leveraging modules as part of the overall architectural stack. It does help with that. I’m not sure how much money has been saved just yet. However, there has been a fair bit of savings of both time and money.
To some extent, it has really helped us stay on top of compliance. Before, we had to do it manually. Having templates helps. It helps management understand whether we are compliant or not and can help work to close the gaps.
What needs improvement?
Non-Microsoft use cases are not very high. It's limited for now. They are continuously trying to evolve and trying to provide the latest right now. It is mature only on the more popular open source kind of applications or source tools. That is a limitation that it brings in. That said, if you already have a complete Microsoft stack then it will work really well.
They still need more coverage on Microsoft Dynamics 365. It's an area they are still working on.
The lineage data capabilities could be improved. They need data quality as a solution. They need to have that as part of their suite.
If I want to drive governance and adoption, when it comes to dashboarding and understanding maturity, it still needs work. There are other better, more competitive tools.
For how long have I used the solution?
I've been using the solution for the last five years.
What do I think about the stability of the solution?
The solution has been stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
We do have personnel in-house that take care of any technical issues for the most part. Technical support is good when we do need help. There is documentation, FAQs, and chats, et cetera. When we reach out, we get support within 24 to 48 hours. Sometimes to get to the answers takes some time.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I've used other solutions such as Informatica, Collibra, and One Trust, among others.
We had multiple use cases. Some organizations already had a strategic alignment with Microsoft Azure, and it made sense to go with Purview. Others felt it was a good option since it provides both governance and security. Many wanted to keep Microsoft as a strategic partner as well.
Purview is great in that it supports your stack, is cloud-native, and works directly with the Microsoft suite. Since it supports most options in an organization, it becomes easier to integrate so that we can gain that visibility.
How was the initial setup?
The deployment requires an Azure enterprise account and is taken care of by one person and an Azure administrator. It's very easy. You just need to follow the steps and work with the Azure administrator.
Once it's set up, you get your users set up and define your rules. You need to deploy policies, et cetera, and go through a series of steps to ensure everything is ready and users are onboarded correctly. There are multiple strategies you can take on later - for example, decentralized and piecemeal approaches.
We have different scenarios including production and development environments. We have different strategies to keep different environments in sync and do quarterly checkups where we identify certain areas and departments to add.
Maintenance is only needed for larger organizations that are more mature. There is no separate maintenance; it's all under the same license.
What was our ROI?
The ROI has been very high and can be measured in many ways. We measure ROI based on the organizational maturity and data-related use cases.
What's my experience with pricing, setup cost, and licensing?
The cost is completely based on the number of users and the subscriptions that it provides. Also, the technology stack and how much data you have or how many connectors you are using, et cetera. There are a lot of different types of factors to consider when calculating cost. Since we went for more of a pay-as-you-go model, it is based on consumption.
More complex organizations use more data and therefore the pricing will be different from smaller, less complex organizations.
What other advice do I have?
I have been a partner and implementor, however, right now, I am more of an end-user.
We are working with the SaaS version of the solution.
I'd advise others to take time and understand both this and competitor solutions. Consider the use case you are solving for.
I would rate the solution seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Microsoft Purview Data Governance
February 2025

Learn what your peers think about Microsoft Purview Data Governance. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Manager, Service Delivery & Solutions Architect at a computer software company with 1,001-5,000 employees
It helps us by reporting on and auditing leaks and breaches
Pros and Cons
- "One important feature is data security, which both end users and the organization seek."
- "Microsoft Purview offers data protection across a multi-cloud and multi-platform environment."
- "The standard support is acceptable, but sometimes it doesn't respond fast enough. Overall, it doesn't meet our expectations."
- "I rate Microsoft support six out of 10. The standard support is acceptable, but sometimes it doesn't respond fast enough. Overall, it doesn't meet our expectations."
What is our primary use case?
I use Microsoft Purview Data Governance for data governance and data loss prevention. Its main purpose is to protect the data from end users and provide data governance.
How has it helped my organization?
Microsoft Purview Data Governance helps us by reporting on and auditing data leaks and breaches.
What is most valuable?
One important feature is data security, which both end users and the organization seek. Microsoft Purview offers data protection across a multi-cloud and multi-platform environment.
It's critical that Purview connects to iOS, Mac, and Android. We could only secure some of our data if it only covered Windows. It provides a comprehensive view of the entire ecosystem's threats and compliance in real time. It's very easy to use.
Purview's compliance features are crucial. We have to match some cases in other countries to our own to comply with the policies, procedures, and regulatory frameworks here.
What needs improvement?
Although there is currently nothing that I feel needs immediate improvement, I appreciate the announcements for new features. A watermark feature or similar tools to help enhance security for end users could be added.
For how long have I used the solution?
I have been using Microsoft Purview Data Governance for around six to seven months.
What do I think about the stability of the solution?
Microsoft Purview Data Governance is stable.
What do I think about the scalability of the solution?
Scalability is good with Microsoft Purview Data Governance.
How are customer service and support?
I rate Microsoft support six out of 10. The standard support is acceptable, but sometimes it doesn't respond fast enough. Overall, it doesn't meet our expectations.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have not used a different solution before Microsoft Purview.
How was the initial setup?
The initial setup was not particularly easy, as it required maintaining the architecture to integrate user capabilities.
What about the implementation team?
I did not use an integrator, reseller, or consultant for the implementation.
What was our ROI?
One of the best offerings by Microsoft is providing multiple solutions with one vendor. This has allowed us to maintain various solutions efficiently.
Which other solutions did I evaluate?
I did not evaluate another solution before Microsoft Purview.
What other advice do I have?
I rate Microsoft Purview Data Governance nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Dec 18, 2024
Flag as inappropriateSecurity consultant at LTI Mindtree
We can use the MIP feature without the need for extra plugins, and we get good visibility, but the reporting functionality has room for improvement
Pros and Cons
- "MIP also provides strong information rights management settings, such as the ability to specify who has access to content and at what time."
- "While Purview's data connector platform can ingest information from non-Microsoft data sources, it is slow to do so and the information may become outdated."
What is our primary use case?
I am a system integrator for Microsoft Purview. I have assessed some customers who already have Microsoft Purview because of their E5 license. However, they are not aware of Purview's capabilities. Purview is a relatively new product that provides an end-to-end data security lifecycle solution. It allows us to review our data with a data governance solution, classify it, protect it, and prevent data breaches. I have worked on almost all aspects of Purview.
We have assessed some customers and provided them with use cases such as using Purview to protect confidential data recovery. This allows them to manage their own workflow for vendors on a contractual basis. We have multiple use cases for Purview.
How has it helped my organization?
Purview's natively integrated compliance across Azure Dynamics and Office 365 is important. Microsoft has the advantage of being able to connect other solutions in its suite more easily, and this makes Purview a very good choice. With the exception of OCR in Teams, Purview works very smoothly. If we want to protect something in an email, Purview will prompt us immediately if we have configured it to do so. This is very convenient, and Purview does not use more system resources than expected. Another advantage of using Purview is that it is Microsoft's own product, so Microsoft can customize it to its own needs and ensure that it does not impact system performance.
It is important that Purview was built taking into account critical regulations from around the world. Purview is important because businesses are increasingly operating globally, and data is moving between different regions and countries. Purview is up to date with respect to different regional, national, and state privacy laws. I have found Purview to be a great solution, but it is not yet operating as well as it could. Microsoft is working hard to address this issue, and they are publishing new privacy acts to Purview on a regular basis.
How we use Purview data loss protection to educate users on how to handle sensitive data is we deploy Purview in the organization, categorize the data by region or department, perform data flow analysis to understand how the data is used and shared, classify the data as low, medium, or high risk based on the daily digital annual loss, We protect the data using Microsoft DLP, We publish videos on SharePoint to educate users about data classification and labeling, and we enable users to self-educate by providing them with access to documentation and training resources.
Purview is valuable because it is the only end-to-end data lifecycle management solution that provides data governance, classification, and protection.
Purview helps to reduce the number of solutions we need to interact with.
The reduction of the number of solutions we now need to interact with has simplified our data governance.
I am satisfied with the visibility that Purview provides. Even without configuring anything, we can see many insights, but we do not get the exact details unless we configure Purview accordingly.
It provides a real-time compliance score for all our devices connected with Identity Access Management and Defender.
Purview helps us save time by publishing the policies quickly and collecting information in real time.
Purview helps us stay compliant. I have not encountered another solution that provides end-to-end licensing.
What is most valuable?
One of the valuable features of Microsoft Purview Information Protection, formerly known as Azure Information Protection or Microsoft Information Protection is data classification and data governance. MIP provides a unified labeling client that allows users to apply sensitivity labels to documents and emails in Microsoft Office files without the need for extra plugins or agents. MIP also provides strong information rights management settings, such as the ability to specify who has access to content and at what time.
What needs improvement?
Microsoft Purview's ability to deliver data protection across multi-cloud and multi-platform environments is important, but there are some limitations. For example, if we have our own cloud solution, Purview cannot currently protect it. However, we can integrate Purview with other OEMs, such as Forcepoint, McAfee, or Symantec, to provide DLP functionality for our CASB. Additionally, Purview cannot protect cloud platforms that are part of a shared domain, such as our own website, unless they are part of the public domain. Purview needs to add DLP support.
One of the things I would like to recommend is that Purview doesn't have the option to push policies or updates in real-time. Instead, it is based on the last five-bit communication. We cannot make any changes to this. It is based on the device when it is communicating with the server. If I want to do this forcefully from the server, if I want to send a wake-up call to all or selected agents throughout the organization, Purview does not have this capability in the GUI.
The reporting functionality needs to be improved. I have found that the solution is not satisfactory for reporting. We have to use Power BI to generate the overall profit, but this requires a lot of configuration. In another solution, we can easily achieve the same reporting functionality.
Purview does not have OCR functionality or network web. Therefore, OCR functionality is not included. OCR is available for Teams, but it does not work as expected. For example, it does not work well for systems that deliver to the recipient database, which could cause problems if it does not match our rules.
Purview has limitations connecting to Android devices and SaaS devices.
While Purview's data connector platform can ingest information from non-Microsoft data sources, it is slow to do so and the information may become outdated.
I would rate Purview's data loss prevention for remediating violations a six out of ten. The reason is that Purview does not have an option for endpoint discarding. In contrast, Forcepoint and Trellix are more mature DLP solutions that offer endpoint discarding. This allows us to scan endpoints for sensitive data, take a replica of that data, and store it in a safe location. We can also encrypt the data on the endpoint. Microsoft Purview DLP does not offer this functionality. It is only available for Teams and email.
For how long have I used the solution?
I have been using Microsoft Purview for one and a half years.
What do I think about the stability of the solution?
Some features of Purview are stable, while others are not. MIP is very stable. DLP is constantly being updated, so some of its options may be unstable. The only stable portion of DLP is the database checking management.
What do I think about the scalability of the solution?
Purview is in the cloud, so it is scalable. However, Microsoft sometimes makes it confusing by adding add-on features that we are forced to add and which will cost us to move. For example, there are options for endpoints four and six, but to use these, we have to add block storage, which will cost more. We should only have the option to configure everything in one console. This is because humans sometimes need to go to the Azure team and ask for access if they do not have Azure. Alternatively, the Azure admin team has to do this on their behalf. This is something that Microsoft can think about.
How are customer service and support?
The customer support is the worst. When we were raising the case, the support was literally asking us how to resolve the issue. So I was really confused about what kind of support this was. We were seeking support, and apparently so were they. One of the customer support people had just provided us with dates but was not working on resolving the issue. I don't know why.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have also used McAfee, Symantec, and Forcepoint for our data security. These solutions all offer endpoint discarding, which Purview does not. This gives us the option to replicate and save a copy in another place. Endpoint discarding is granular, and we can save reports in real time and connect to endpoints in real-time. We can also bypass the endpoint, which we cannot do with Purview. McAfee does not have to be built in, while Symantec does.
The pros of Purview are utilization and performance. It is a lightweight solution that does not impact system utilization. This is important. Microsoft is a one-stop shop for data classification and DLP, so we may not need to worry about integrating with different vendors. We have MIP, and then DLP if we have exposure from DLP. Of course, it is possible to integrate with the help of APIs, but there is a risk that Microsoft may decide not to integrate with Forcepoint or Symantec in the future. This is something customers should think about. In that case, for customers with an E5 license, Purview would be the best choice because they can utilize all the Microsoft products and save costs. This strategy will also improve their security posture.
How was the initial setup?
The initial setup is straightforward. Just plug in our internet credentials. That's it! No need to worry about the server, its utilization, configuration, or architecture. It's very easy to use, and we don't have to worry about disaster recovery or data centers. In a way, it's really helpful and cost-effective. Microsoft is taking care of everything on a pay-as-you-go basis.
The number of people required for deployment depends on the number of end users and departments. For example, an organization with 15,000 end users, 40 departments, and some generic requirements can deploy the solution using one L3, one L2, and two L1 people.
What was our ROI?
The fact that our organization continues to use Purview indicates that it provides some sort of return on investment.
What's my experience with pricing, setup cost, and licensing?
We pay $15,000 per end user for the E5 license.
What other advice do I have?
I would rate Microsoft Purview seven out of ten.
According to Gartner, Microsoft DLP is one of the top ten DLP solutions, but the top three are Trellix, Symantec, and Forcepoint. I prefer Forcepoint.
The maintenance is easy to complete.
I highly recommend that an organization use an E5 license if they are going with Microsoft because this will give them everything they need, including technical management, governance, and data management.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Integrator
Dex engineer at a tech vendor with 1,001-5,000 employees
Sensitivity labeling enables us to automate encryption and ensure proper data handling across the organization
Pros and Cons
- "The sensitivity labeling is the most valuable feature because it is the foundation for automating the encryption process and ensuring proper data handling across the organization."
- "The sensitivity labeling is the most valuable feature because it is the foundation for automating the encryption process and ensuring proper data handling across the organization."
- "We haven't really gotten too far into it to identify areas for improvement just yet."
What is our primary use case?
We are labeling our documents, and based on those labels, encryption is applied depending on how sensitive the data is. Documents that leave our organization are automatically encrypted.
We plan to use Purview for data loss protection, but we aren't there yet. That's the next phase of our rollout. We're setting up governance, identification, and classification before moving to DLP. We have started some pilot groups within Teams to test how it will block PHI personal health information that's transmitted via text or voice in a transcript. We've seen some success, but it also blocks a lot of things that it shouldn't. It's a matter of fine-tuning.
How has it helped my organization?
We're going to have the benefit of being able to roll out Copilot more securely, but we're not there quite yet.
What is most valuable?
The sensitivity labeling is the most valuable feature because it is the foundation for automating the encryption process and ensuring proper data handling across the organization.
It is helpful that Purview can connect to iOS, Mac, and Android devices because you need to be able to govern the ecosystem no matter where your data is. Purview's consideration of critical regulations from around the world is crucial because we operate globally, so we need to adjust how data is handled for our employees in other countries.
What needs improvement?
We haven't really gotten too far into it to identify areas for improvement just yet.
For how long have I used the solution?
We haven't been using it for long. We are currently in the pilot phase, gradually rolling it out. We've been building the policies, and the rollout to a pilot group started three weeks ago.
What do I think about the stability of the solution?
I couldn't really say about the stability so far, but I have confidence in it.
What do I think about the scalability of the solution?
It's definitely scalable. With automation, you can label five documents or 50,000 with the same amount of clicks. It handles all the data you can throw at it.
How are customer service and support?
I rate Microsoft customer service 10 out of 10. Support is a little slow, but it's very beneficial. They're skillful people who know what they're doing in their space. Some unforeseen speed bumps along the way have slowed things down. It's nor something that I would be mad about, but I wish the project would be done by now so we could get our Copilots all rolled up.
We have a good rapport with them and get along well. We can candidly talk to them about things and ask for help. They're always happy to do what they need to to get the answers we need.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used some built-in legacy permissions and tools for file management, along with Excel's advanced features, which are now part of Microsoft Purview.
How was the initial setup?
It's been a slow process. We're taking our time and working with a partner. It's been slow, but this is one of those cases where that's necessary.
What about the implementation team?
We worked with a consultant named Lighthouse. They've been very beneficial, skillful, and know their field well. Despite some unforeseen speed bumps slowing the project, their expertise has been valuable.
What was our ROI?
We're working with a Microsoft partner to carefully create labels and test all the features and policies behind the labels. We rolled it out to our first pilot group. We have a test SharePoint site that we're using alongside that. Once we have more data and and feedback from the pilot group, we'll expand that company-wide.
What's my experience with pricing, setup cost, and licensing?
The experience with pricing, setup costs, and licensing was smooth, as most Purview functionalities were included in the e5 licenses we migrated to for other reasons.
Which other solutions did I evaluate?
We did not evaluate any other solutions as we were acquiring an E5 license, which integrated Purview features without the need for exploring alternatives.
What other advice do I have?
I rate Microsoft Purview Data Governance eight out of 10. Once you start using it and see what it can do, it's really intuitive.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Dec 18, 2024
Flag as inappropriateSenior Manager Data Supply Chain at a tech services company with 10,001+ employees
Strengthens governance and provides visibility across variety of Data Sources and helps breaks Silos
Pros and Cons
- "It is critical that Purview delivers data protection across multi-cloud and multi-platform environments. That is the number one reason that people are adopting hybrid and best-of-the-breed approaches. Especially in banking, it is critical because people want to protect, govern, and secure their data. This is one of the first conversations that happens with security and the architecture group on the client side."
- "The API needs some improvement when connecting to non-Microsoft API sources. This is a limiting factor."
What is our primary use case?
We are using it for governance on the cloud data migration. When people want to see legacy application Hadoop to Azure, we use the solution to gain some governance aspects and integrate it with Synapse on the final layer, which is the transform layer of the data lake.
Purview was included at a single location in eastern Canada. There are close to 1,000 users.
How has it helped my organization?
It strengthens governance and provides visibility. It gives you better control and reports, then it integrates them with the Microsoft reporting solution. It integrates very well and helps provide visibility, but you need to do a lot of homework before you gain visibility. You need to understand the limitations in each of the data sets to gain visibility from a governance perspective.
For a tech organization, it gives them the ability to lower maintenance costs because it is natively integrated. So, it reduces the number of solutions that need to interact with each other. It is far easier for clients to operate and maintain that solution rather than be worried about a custom or hybrid solution, or even a best-of-breed. This solution makes it tougher because then you can hire people with different skill sets.
Depending on the pipeline, it enables us to show compliance in real-time. This has sped up the decision-making cycle, making clients more proactive. They can do more internally before responding to compliance requests. For the banks, it is very important for them to be compliant with the standards that they are expected to adopt, e.g., GDPR. This gives them more time to prepare and figure out what the root cause could be if there are gaps.
Because governance analysts have these reports and dashboards out-of-the-box from Purview, they now have more time. For example, in a 40-hour work week, they would gain back three to four hours. So, the decision-making is faster.
Purview gives you more visibility and has native integration. It gives you a heat map regarding your risks. For example, where could there be potential exposure? It can very quickly identify non-compliance. Since it is natively integrated, the catalog tracker can quickly scan it.
What is most valuable?
It natively integrates. It gives you a lot of controls, awareness, features, and best good practices, making conversations a lot easier with the clients. Features are pre-built. All you have to do is configure it properly, and you get the correct tables and names of the entities with data. This reduces effort and gains efficiency, both for the clients and for SIs (like us).
It is critical that Purview delivers data protection across multi-cloud and multi-platform environments. That is the number one reason that people are adopting hybrid and best-of-the-breed approaches. Especially in banking, it is critical because people want to protect, govern, and secure their data. This is one of the first conversations that happen with security and the architecture group on the client side.
It is a heterogeneous environment. That is a desire that the clients are asking for increasingly. So, the feature that provides data protection for iOS, Mac, Android, and data in other SaaS apps is pretty important.
Batch sources can connect well.
What needs improvement?
It works very well, but there are some limitations because it is a new product. For a lot of features, you need to wait until the time that Microsoft announces that they are generally available. Or, a lot of times, some features are not even available. Then, you need to go through their support channel. So, it's a mixed bag.
The API needs some improvement when connecting to non-Microsoft API sources. This is a limiting factor.
The integration with modern data warehouses needs a lot more traction. Because clients will not always adopt Microsoft Azure as their cloud, as they can choose to be in a heterogeneous environment. For example, I have three warehouses: Synapse, Snowflake, and Amazon Redshift. In this case, I would hesitate to adopt Purview, as it is not the best choice at this point in time.
For how long have I used the solution?
I have been using it since it was launched in 2021.
What do I think about the stability of the solution?
The reliability is very good, but the stability is evolving as Microsoft is trying to challenge the established leaders with new features.
It is middleweight from a maintenance perspective, as there are two people from the client side at one site maintaining this, technically and functionally. There is a lot of leg work needed on the functional side.
You need to keep an eye on it when applying a new patch or version from the cloud. You need to be very careful of how you upgrade that so it does not undo your customizations.
What do I think about the scalability of the solution?
It scales without issues. In terms of performance, it scales pretty well.
Out-of-the-box, it is fairly easy to use the features. The clients have been happy overall, but they struggled when they tried to extend it to other applications in the cloud. This is getting better, from what I understand, as they release more feature enhancements.
How are customer service and support?
The technical support is good. They respond quickly, though it depends on your license. If you have Premier Support, they will respond. On a scale of 1 to 10, I would rate them between eight and nine. They are trying to improve.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did previously use another solution.
We had a client who decided to move to a single platform in the cloud. Azure was chosen because of its native dataset and proximity, e.g., the platform closest to the existing state of affairs. That is why Azure was chosen and the major reason for Purview to get adopted.
How was the initial setup?
The initial setup is pretty complex. When you make it a private cloud, the security makes the setup complex. The public cloud is far easier. With a private cloud, you do the configuration to the right security standards and norms. You have to do the extra groundwork to make that happen. That took us a long time, but that is okay. Once it was done, it worked fine.
The first step is migration, making it visible and gaining efficiency. Then, you let it stabilize and clients get it. Phase two might be more automated, having some intelligence with AI for more decision-making.
What about the implementation team?
I did the implementation with a Purview team of eight to 10 people. This included a governance analyst, data analyst, Purview expert, SMA, developer, and functional analyst. I was the overall delivery lead overseeing the effort, then there was a lead on governance.
What was our ROI?
Clients are happy and seeing the benefits. However, it is too early to determine ROI.
Which other solutions did I evaluate?
We also evaluated Collibra and AWS.
We haven't explored data loss protection at this point in time because the client has a very specific, in-house utility tool that they wanted to retain for DLP.
What other advice do I have?
Make your case. Do your homework. Know your roadmap, which is critical with Microsoft and adopting Purview.
I would rate the solution somewhere between an eight and nine out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: MSP
IT security analyst at a financial services firm with 1,001-5,000 employees
Helps protect data across multi-platform environments, connects to a wide range of devices, and helps us stay compliant
Pros and Cons
- "The custom classifications are one of the most valuable features."
- "The custom data classification for the African region needs to be improved."
What is our primary use case?
We use Microsoft Purview for DLP capabilities and email encryption.
How has it helped my organization?
Ensuring data protection across multi-cloud and multi-platform environments through Purview is crucial for us. Currently operating on Azure and AWS, we plan to migrate a portion of our on-premises workloads to the cloud. To achieve this, we will leverage Purview for data loss prevention on our virtual machines and utilize Azure Arc for centralized management of all our platforms.
Purview's ability to connect to a wide range of devices, including iOS, Android, and others, enhances our visibility into BYOD devices deployed across our environments.
As a public organization, we are bound by policies and regulations. To ensure compliance across Azure Dynamics 365 and Office 365, both locally and internationally, we leverage the native compliance capabilities of Purview, which integrates seamlessly with both platforms.
The DLP for remediating policy violations works well. We can easily view the details and conduct investigations from a single dashboard.
We recently started using Purview for DLP on Mac OS devices.
Implementing Purview as our primary data loss prevention solution has yielded significant benefits. Our Microsoft E5 license provides enhanced protection across the organization, offering immense value through its comprehensive features. Consequently, we have been able to streamline our security posture by consolidating third-party solutions and focusing on Purview and other robust Microsoft applications.
Microsoft Purview has streamlined our workflow by consolidating diverse systems into a single, user-friendly dashboard. This one-stop shop simplifies access and management across our organization.
Microsoft Purview enables us to show our compliance in real-time. We are satisfied with the speed at which Purview provides alerts and details to us.
Microsoft Purview has significantly shortened the response time to insider threats by almost 70 percent. It can rapidly block unauthorized user access, leading to a reduction in required manpower.
Microsoft Purview has helped to save money by preventing the loss of data in our environment as well as around 60 percent of our admin user's time.
Purview helps us stay on top of compliance. We no longer have to review incidents manually, improving compliance by 80 percent.
What is most valuable?
The custom classifications are one of the most valuable features. For instance, if we want to block the transfer of card details, there are many pre-built samples for different countries that we can easily use in Purview, eliminating the need to create our classifications which makes the work easier.
What needs improvement?
Purview needs to improve its DLP capabilities for removable devices such as external drives and USB devices.
The custom data classification for the African region needs to be improved.
For how long have I used the solution?
I have been using Microsoft Purview for five years.
What do I think about the stability of the solution?
Microsoft Purview has been stable, with no incidents involving the Data Loss Prevention functionality. However, there have been a few instances where the admin portal has been unavailable.
What do I think about the scalability of the solution?
Microsoft Purview is extremely scalable.
How are customer service and support?
The support response time can be improved.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are currently using Forcepoint and Microsoft Purview, but with our E5 license, we're considering consolidating our security products under one umbrella and one dashboard, potentially phasing out Forcepoint.
How was the initial setup?
The initial deployment took a few hours. Five to six people were involved in the deployment.
What's my experience with pricing, setup cost, and licensing?
I would rate the cost of Microsoft Purview a six out of ten with ten being the most expensive.
What other advice do I have?
I would rate Microsoft Purview an eight out of ten.
We have a complex group-wide tenant that requires us to have different administrative units for each country. We have around 50,000 users worldwide.
Purview does not require any maintenance beyond regular checks in the admin portal to ensure everything is functioning correctly.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Cybersecurity Consultant at Cyberiage
Safeguards sensitive and confidential data, but frequent updates can make navigating the UI unpredictable
Pros and Cons
- "Microsoft Purview's primary benefit lies in safeguarding sensitive and confidential data, thereby mitigating the risk of internal data exfiltration."
- "Frequent daily updates from Microsoft can cause interface elements like buttons to appear and disappear, making navigation unpredictable."
What is our primary use case?
We have implemented Microsoft Purview as a comprehensive DLP solution for our clients across Europe, Africa, and the Middle East to protect their data and help them classify, identify, and investigate who and how the data is being accessed.
How has it helped my organization?
Microsoft is aiming to build favorable relationships with other cloud solution providers. On our end, if we have both AWS solutions and Microsoft's cloud solution, implementing the Microsoft Purview dashboard can be a good way to collect and classify our data across both platforms. This could be a strong selling point for Microsoft to explore partnerships with AWS and other public cloud players, allowing them to combine and leverage their global development, sales, and services.
Implementing Purview's integrated compliance across Azure Dynamics 365 and Office 365 is relatively straightforward thanks to available connectors and Microsoft's improved user interface.
Microsoft Purview includes a compliance manager, which simplifies meeting various standards and regulations through integration with companies like ISO, ISCE, and other risk solutions. This feature is an add-on for E5 and E3 licenses. It allows us to create assessments that generate reports with specific recommendations for implementing and configuring ISO 27001 or other standards within our Microsoft 365 environment. This makes compliance significantly easier and, according to Microsoft, can reduce the cost of implementing such measures by approximately 40 percent compared to using other solutions for ISO compliance or other critical regulations.
Given my role as a cybersecurity consultant, I previously created a DLP policy based on the client's needs. Since then, I haven't had further contact with the client. However, I'm now working on a new project for them next year. This project involves developing and implementing a DLP solution with a focus on information protection. My responsibilities include monitoring all user activity and reporting on it in a few months. Based on my observations, there's a significant amount of activity requiring governance. This includes areas like DLP policy enforcement, USB blocking, printer control, copy prevention, file transfer via secure FTP, and external user access restrictions. Purview's data loss protection is helpful for remediating policy violations.
I'm developing a short training guide, about four pages or more, on enabling information protection labeling and related topics. Some clients have suggested automation, but I believe the best approach is to guide users through manual labeling. For instance, we could have a "Sensitive" label for data like personal information, ID numbers, passports, names, passwords, and so on. Information protection can be implemented either by defining detection rules beforehand or by using the system's automated detection capabilities. If sensitive information is detected, the system can then recommend applying the "Non-Confidential" label or whichever equivalent label we prefer.
Microsoft has developed and launched Microsoft Defender for Endpoint for Mac. This agent for macOS is the same agent used for data loss prevention in Endpoint. However, if we don't require DLP for Endpoint, we can simply synchronize our Macs with Microsoft Intune. Intune, a combination of Microsoft Entra ID and an MDM solution, is not just for mobile devices; it's a device management platform for all company devices, including PCs, Macs, mobile devices, and servers. It allows us to synchronize settings and policies across all our devices, manage software deployments, and utilize various other features. Therefore, we have two options: either synchronize our Macs with Intune or install the Microsoft Defender for Endpoint agent to implement DLP for Endpoint. DLP for Endpoint is mandatory if we need to detect and control USB devices, printers, and other data transfer peripherals.
Microsoft Purview's primary benefit lies in safeguarding sensitive and confidential data, thereby mitigating the risk of internal data exfiltration.
Purview does help our customers reduce the number of solutions they interact with. From a cybersecurity engineer and information security expert perspective, consolidating and streamlining technology can be beneficial for IT departments, especially before implementation. Currently, Security Service Edge emerges as a promising solution due to its integration with zero-trust principles and protocols. For example, instead of deploying multiple endpoint detection and response solutions, a single, antivirus-free EDR like CrowdStrike can suffice. Similarly, Microsoft's Defender for Cloud Apps, combined with XDR and other security features, offers a comprehensive solution for Security Operations Centers. My goal is to create a unified MDR solution for clients, allowing for centralized data collection and log analysis. This unified platform, ideally with one or two dashboards, would enable efficient investigation and response, minimizing investigation time and cost. Combining various tools into one interface eliminates the need to jump between dashboards, improving analyst efficiency. Why rely on multiple vendors like CrowdStrike, Proofpoint, Minetest, and MISSP when a single solution can offer comprehensive visibility and data security? Microsoft's Image Security 365, coupled with best practices and anti-phishing strategies, can significantly enhance security. Furthermore, I recommend implementing a DMZ with two firewalls, one internal and one external. This layered security approach, while requiring two vendors, provides redundancy and prevents attackers from exploiting a single firewall and gaining access to the network. However, it's important to remember that cybersecurity solutions are not one-size-fits-all. Each client and scenario requires tailored strategies based on their unique needs and context. Consistency across the industry is crucial, but it's important to acknowledge the lack of standardized approaches in the current landscape.
The Microsoft Purview dashboard is primarily a data security solution, allowing us to implement various layers to safeguard our information. While it can be used for some Endpoint Detection and Response functionalities, its full potential in this area might not be realized without proper configuration and understanding of the underlying processes.
While Purview offers real-time compliance monitoring, it's an add-on feature functioning as a compliance manager. However, due to a lack of clear communication, not all companies fully understand its capabilities. Additionally, it's important to note that while compliance and standards often relate heavily to financial and banking sectors, the scope of regulations has broadened significantly in recent years, extending beyond these specific industries.
Purview helps us stay on top of compliance because Microsoft has tried to build Purview based on the ISC framework.
What is most valuable?
No single feature stands out as the best because the most effective approach involves combining multiple features. For example, when using information protection, labeling, and classification, a multi-step process is necessary. First, we must classify our data, which requires a thorough understanding of our environment and the nature of the data itself. Once classified, we can apply labels and establish rules governing data sharing through information protection measures. The final step involves implementing and configuring a Data Loss Prevention solution. It's crucial to remember that the goal isn't to find ideal individual features; rather, it's to leverage the synergy of multiple technologies to create a comprehensive and powerful data protection strategy.
What needs improvement?
I've been working closely with Microsoft support on issues with the Microsoft Purview Information Protection scanner's on-premises services. While it's a solid tool, there's still room for improvement in my opinion. I've submitted numerous recommendations, from solutions to address specific problems to the implementation of new features like bulk scanning across multiple servers, not just individual paths. I've also encountered a high number of false positives in the classifier and made suggestions for resolving them. Microsoft support is currently reviewing my input, and we're collaborating to refine the scanner and minimize false positives. It's important to remember that this is a new technology, and like any newborn business venture, it's prone to growing pains. Errors and mistakes are inevitable along the way, but they're also valuable learning opportunities.
Frequent daily updates from Microsoft can cause interface elements like buttons to appear and disappear, making navigation unpredictable. Additionally, Microsoft also generates new licenses that require investigation to identify each new license.
For how long have I used the solution?
I have been using Microsoft Purview for one and a half years.
What do I think about the scalability of the solution?
Microsoft Purview is scalable.
How are customer service and support?
Sometimes we have a communication gap or delay but most of the time the technical support is good.
How was the initial setup?
One person can deploy Microsoft Purview.
What about the implementation team?
We implement Purview for our clients.
Which other solutions did I evaluate?
We are a Microsoft Gold Partner and are currently satisfied with our existing solutions. Therefore, we do not prioritize evaluating other vendors at this time.
What other advice do I have?
I would rate Microsoft Purview a seven out of ten. Purview is a good solution but it takes time to master.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Microsoft Purview Data Governance Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Popular Comparisons
Informatica Intelligent Data Management Cloud (IDMC)
Varonis Platform
Collibra Governance
Alation Data Catalog
erwin Data Intelligence by Quest
Microsoft Purview Information Protection
Ataccama ONE Platform
SAS Data Management
Collibra Lineage
Microsoft Purview Compliance Manager
OneTrust DataGovernance
Protegrity’s Data Protection Platform
Buyer's Guide
Download our free Microsoft Purview Data Governance Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which Data Governance tool would you choose and why: Microsoft Azure Purview or IBM Data Governance?
- Which tool is better for data governance: Collibra or Azure Purview?
- What is the difference between Collibra Data Governance and Azure Purview?
- Looking for peer reviews on Microsoft Azure Purview
- Which is a better Data Governance tool: Collibra Governance or Microsoft Purview?
- Microsoft Purview vs Collibra. What do you prefer?
- What are the main differences between Varonis and Microsoft Purview?
- What are the main differences between Valora Technologies and Microsoft Purview?
- Which data catalog can provide support for BI data sources such as SAP BO and Tableau?
- What is the difference between master data management and data governance?