Skip to main content
In this lesson we focus on a crucial capability: identifying and responding to data risks before they become security incidents. Microsoft Purview’s Adaptive Protection combines context-aware detection, Insider Risk Management, and Data Loss Prevention (DLP) to apply risk-based controls that protect sensitive information while minimizing disruption to users.

What is Adaptive Protection?

Adaptive Protection in Microsoft Purview integrates two core services:
  • Insider Risk Management — continuously evaluates user activity to surface behavior that may indicate potential risk (for example: unusual downloads, excessive external sharing, or attempts to move sensitive information outside the organization). When elevated risk is detected, those signals can be shared with DLP policies so prevention controls behave differently for higher-risk users.
  • Data Loss Prevention (DLP) — applies controls dynamically based on a user’s assessed risk level, enabling stronger protections when necessary while reducing friction for low-risk users.
Together, these services enable an adaptive security model that balances protection and productivity. Purview’s context-aware detection uses machine learning to analyze multiple signals — user behavior patterns, interactions with sensitive content, and other telemetry — to distinguish normal activity from suspicious patterns. For example, downloading a file may be routine for one employee yet unusual for another; Purview evaluates historical behavior alongside the sensitivity of the data involved, scores the activity, and can flag elevated risk in real time so security teams can investigate before damage occurs. Imagine an employee suddenly downloading hundreds of confidential documents shortly before leaving the company — each download might seem legitimate by itself, but the combination of unusual activity, volume, and sensitivity triggers an alert.
A slide titled "Identifying and Responding to Data Risks With Microsoft Purview." It shows a flow where user behavior and sensitive content feed into machine learning, which produces a real-time risk flagged alert.
This context-driven approach reduces false positives while improving detection of genuine threats.

Graduated, risk-based responses

Not every risk requires the same response. Purview applies dynamic controls tuned to the severity of detected risk so enforcement is proportional and minimizes business impact.
  • Elevated risk: strict DLP controls — block sharing, restrict downloads, prevent sensitive data from leaving the organization.
  • Moderate risk: block risky actions but allow users to provide a business justification for an override when appropriate.
  • Minor risk: non‑intrusive policy tips or educational warnings without interrupting work.
A slide titled "Identifying and Responding to Data Risks With Microsoft Purview" showing three colored risk levels—Elevated (strict DLP, block sharing), Moderate (block but allow justified override), and Minor (non‑intrusive policy tips).
This graduated response protects sensitive information while avoiding unnecessary interruptions. For example, a low-risk employee who accidentally attempts to share a sensitive document might receive a non-intrusive warning, while a higher-risk user attempting the same action could be blocked immediately.

Automation and automated mitigation

Automation is a key benefit of Purview’s Adaptive Protection. Where investigations and mitigation were traditionally manual and slow, automated investigation and mitigation enforce predefined controls immediately when risky behavior is detected — neutralizing incidents faster and reducing operational overhead so security teams can focus on higher-value tasks. For example, if a high-risk user attempts to upload confidential files to
A presentation slide titled "Identifying and Responding to Data Risks With Microsoft Purview." It shows three colored panels under "Automated Mitigation" listing benefits: neutralizes security incidents instantly, minimizes organizational impact, and reduces administrative overhead.
an unauthorized location, Purview can automatically block the action without waiting for manual intervention. This delivers faster protection, reduced impact, and better security outcomes.
Automated blocking can affect business workflows. Always validate policies in report-only or audit mode and pilot policies with representative users before full enforcement.

Quick demo: Purview portal walkthrough

Below is a concise walkthrough showing where to find the Purview tools and how sensitivity labels and DLP policies interact.
  1. Sign in to the Microsoft Purview compliance portal.
  2. Go to Solutions to locate capabilities such as Data Lifecycle Management, Data Loss Prevention (DLP), and Information Protection.
  3. Use Information Protection to create and scope sensitivity labels (for example: Personal, Public, General, Confidential, Highly confidential). Labels can be scoped to the entire organization or to specific groups.
  4. Configure DLP policies under Solutions > Data Loss Prevention to inspect content and enforce actions across Exchange, SharePoint, OneDrive, and Teams.
A screenshot of the Microsoft Purview/Compliance dashboard with the Solutions menu expanded, showing items like Data Lifecycle Management, Data Loss Prevention, Information Protection, and more. The main pane displays a banner reading "Investigations is here" and tiles for various compliance tools.

Sensitivity labels in action

Users can apply sensitivity labels to documents and emails to explicitly mark content sensitivity. When composing an email, Outlook displays the sensitivity label at the top of the compose window; changing the label can require a justification if policy requires it.
A screenshot of the Outlook web mail interface showing an open compose window and the inbox sidebar. A modal dialog titled "Justification" prompts the user to select a reason for changing a classification label (e.g., "Previous label no longer applies").
A screenshot of the Outlook web interface showing the left-hand mailbox list and an open new-message compose pane. A sensitivity/classification dropdown is open with options like Personal, Public, General and recipient choices such as Anyone (unrestricted) and All Employees.

DLP policy example

A typical DLP policy inspects content for patterns (for example: credit card numbers, ABA routing numbers, or other regulated identifiers) and applies actions when a match occurs. Policies can be scoped to external sharing only or include internal sharing, depending on your requirements. Demo scenario:
  • Draft an email containing a credit card number and send it to an external recipient.
  • The DLP policy detects the pattern and enforces the configured action.
Common user-facing messages include:
  • “Your email conflicts with the organizational policy.”
  • “The message was not delivered to all recipients.”
  • Additional details explaining the reason (e.g., contains a credit card number and was sent externally).
A copy of the blocked message and policy details are sent to the user and to configured Purview administrators for review.
Test DLP policies in report-only or audit mode before enabling blocking to validate detections and reduce disruption.
This demo illustrates how Purview combines sensitivity labeling, contextual detection, and automated actions to prevent data leakage while enabling flexible, risk-based responses. Beyond Adaptive Protection, Microsoft Purview provides additional capabilities for enterprise data governance and compliance, including compliance management, eDiscovery, data lifecycle governance, and information governance. These tools help organizations manage risk across data stores and business processes. We will also explore compliance, eDiscovery, and governance capabilities that help organizations further manage and protect data across the enterprise.

Watch Video