We are a partner and work with different organizations. We go through a number of activity phases, such as initial discovery, understanding their data to see what is and is not sensitive, and then using Microsoft Purview.
We use Microsoft Purview to provide sensitive information in building out a roadmap in terms of classification, protection, and lifecycle management. We then determine what kind of use case is most common for other work we would look for and fill in the gaps with the customer. Microsoft Purview's vast features and capabilities really depend on what we learn in those workshops and where that organization is looking to go over a period of time. So if one of the key areas is the mitigation or prevention of data breaches, we can help with that.
We can also help protect content, especially when it is sensitive and involves individuals. We can also help businesses change their processes to help ensure users know what their preferences are and how to use the user tools.
Microsoft Purview's ability to deliver data protection across multi-cloud and multi-platform environments, including AWS and GCP, is very important. It helps organizations realize the investments they have already made and how they can further expand those investments to another remote type of Microsoft workflow. Microsoft Connect has been used to centralize these workflows, and the ability to import existing records management processes and policies into the file plan in Microsoft Purview allows organizations to bring compliance into a central location. This helps to manage costs and improve efficiency, as users can go to one area to leverage basic facilities without having to use separate tools.
It is important for our clients that Microsoft Purview can connect to iOS and Android devices. With many people now working from home and using their own devices, there is a need to manage these devices. Microsoft Purview's conditional access and endpoint management capabilities help organizations to protect their data, regardless of the device being used.
Purview's natively integrated compliance across Azure Dynamics 365 and Office 365 is important. However, it is also important to ensure data privacy with its data as a whole from a compliance perspective. This means ensuring that we can meet the requirements of 2701 controls and that people know the processes, technology, and relevant skills. CRM controls information about potential customers and opportunities, so it is important to ensure that we are compliant when handling this data. We also need to make sure that updates to Purview are made as needed and that our team is able to stay on Office 365. Having a strong compliance program is essential for any organization that handles sensitive data. By taking the necessary steps to ensure compliance, we can protect our data and our customers.
It is critical that Purview is built around global regulations. This is because we have different types of customers, some of whom operate slowly. There is a rack with some regulations, and we have the US. We also have a rack with different regulations that are up-to-date, but they are only safe in some areas. This means that we need to be able to control, face, or bank on system regulations. This is very important to me and the customer because they can be very tricky.
Purview's DLP can be used to remediate policy violations. A number of kinds of DLP rules can be leveraged, such as sensitivity labels, data classification, and sensitive information protection plans. This means that it is not enough to simply provide people with the technology, they also need to be trained on how to use it effectively. Through the use of an ERP system, a number of policies can be set up. This insight can then be used to make meaningful decisions about how to rate the data on the system. This will help to understand how the data is costing the organization. If the organization does not have the necessary internal controls in place, new protection and encryption measures may need to be implemented. This is primarily becoming step one in the process of working policies, understanding how the data is being used, making decisions about how to protect it, and then building a protection layer on top of that.
Data loss prevention education for users is important because it can help them to understand how to best protect sensitive data. This can be done by providing users with training on how to use DLP tools and policies, as well as by educating them about the risks of data loss. DLP tools can help to prevent data loss by monitoring user activity and blocking unauthorized access to sensitive data. DLP policies can help to define what constitutes sensitive data and how it should be protected. By educating users about DLP and the risks of data loss, organizations can help to create a culture of data security. This can help to prevent data breaches and protect the organization's data assets.
Purview helped reduce the number of solutions we need to interact with each other. I used the solution that crosses between Endpoint Data Loss Prevention, Microsoft Defender for Data, and Conditional Access to block specific types of information at different workloads. This made it easier to manage sensitive information. For example, if I have sensitive information today, I can easily block people from uploading it to Teams, SharePoint, or OneDrive.
The reduction in the number of solutions we need to interact with each other has had a significant impact on our pricing. In the past, we had to use a variety of different solutions to manage our portals, which was time-consuming and expensive. Now that everything is coming into Microsoft Purview, we are able to simplify our technical and environmental environment. This allowed us to reduce our costs and improve our efficiency. In addition, Microsoft Purview provides us with a central location to manage our data governance. This made it easier for us to comply with regulations and protect our data. Overall, Microsoft Purview has been a major asset to our organization.
Microsoft Purview expanded our visibility into our state by allowing us to see what is labeled, relabeled, and what is not classified. There are a number of different areas where Purview improved capability and overall cost. These are all different aspects of Purview, which is helpful for organizations. Purview has a point-in-time view, and it also has the ability to explore more granular data from the logs.
Purview helps to reduce the time it takes to take action on insider threats by around 50 percent. It requires planning and configuration, as well as two weeks of setup. The technical configuration is used to identify users and the types of activities they are performing. For example, users who sign into hundreds of documents within a few minutes of each other or delete large numbers of documents can be quickly identified and flagged. This allows security teams to send high-priority emails to the appropriate people in a timely manner.
Purview helps save our clients between 30 to 40 percent of time and money.
Microsoft Purview's most valuable feature is its ability to identify content across a number of prescribed regulatory frameworks, including Microsoft, GDPR, PII, and UCC Financial. It can also help organizations identify content that is important to them but not specifically regulated. This is done by creating trainable classifiers and sensitive information types. The protection controls components are based on the perspective of the device. Microsoft Purview has been growing in popularity over the past few years, and it offers a number of tools that can help organizations manage their data.
Purview's data loss prevention for macOS endpoints has some limitations, and the end-user experience of recovering from a failure is lacking.
I would like to be able to search for labels using Purview to see what items are affected and the time periods in which they will be active. This would allow us to export the results for specific business areas, which would make our lives a lot easier. We could also use this information to identify sensitive information types and reduce false positives.
The utility system format, the policy tips and user descriptions of sensitivity labels, and the overall policy tips that are shown in the loss prevention policy have room for improvement.
I have been using Microsoft Purview for three years.
The stability of Purview has been good. It takes a bit of time for someone to configure it, but once it is configured, it is responsive. However, there are sometimes delays due to the speed of users' devices and their home network connections. This can be especially true for mobile devices and when users are using multiple apps at the same time. Microsoft also sometimes experiences delays in processing requests, which can lead to further delays in Purview. Overall, Purview is a stable platform with good uptime and resilience.
In terms of scaling Microsoft Purview, there are two main challenges: network load and data ingestion. Network load can be a problem if there are too many requests coming into the system. This can be addressed by adding more servers to handle the load. Data ingestion can also be a challenge if the company is generating a lot of data. This can be addressed by using virtual machines to store and process the data. As the amount of data grows, the number of VMs can be increased to keep up.
Our clients vary in size from 100 all the way up to 6,000.
Each setup is different. We have thousands of workshops, configurations, and design agreements followed by a baseline to mitigate of about 30 percent which we build on top of. The deployments can take anywhere between a few hours to a few months. We need to understand each organization to ensure that they understand the type of people process that is in place. Then, depending on the technology, we need to make sure that they have access to 365. This is implemented as a baseline, and our target operating model is also needed to ensure that they have the necessary functions. This will allow me to deal with the environment. We need a team of people to manage the deployment.
We implement the solution for our clients. Microsoft Purview is managed in a single location.
Microsoft Purview does not require any maintenance.
Our client's have seen a 100 percent return on investment.
The pricing depends on the client's requirements and the number of applications.
I give Microsoft Purview an eight out of ten.
It is difficult to assess how much AI and automation affect our speed and accuracy of risk detection. This is because the effectiveness of AI and automation depends on how we train the system. There are a lot of sensitive information types that are prescribed by Microsoft. There are also a number of types that fit within another structure of sharing information. So potentially, we have a number of false positives, which means that we are relying solely on the information provided by the system. This is not something that I would push on an organization. Once we start updating the system, we need to make sure that we understand and compare the number of activities to identify and fine-tune the system. We need to do this a number of times before we can be really sure that the system knows our data. We also need to consider the AI side of things, which obviously allows for some risk. The identification of risk seems to be a matter of realizing confidence in the system's predictions.
It is difficult to assess how Microsoft Purview's AI and automation affect the quality of insights that we have. We have run this process effectively a number of times across different organizations, but this has raised some doubts. This is a bit of a shame, especially with the out-of-the-box solution from Microsoft. We are then asked to hold a number of workshops to review the results. This is because the system can operate with different accuracy levels and false positives. It is important to consider how we portray these insights and what the next steps will be. As a result, there are mixed reviews.
Currently, Purview does not enable us to view our compliance in real-time without some additional work to enable us to show compliance. This is because the visual displays rely on the time it takes to update the Microsoft SQL database, which can be delayed. We have seen cases where the displays do not reflect the actual data, and we have had to manually update the database to correct the issue. However, we can clearly see what data is due for disposition, deletion, and retention based on our policies. While it is not always easy to see this information, we have made improvements to make it easier. Overall, it is not a straightforward process, but we are working to improve it.
I recommend Microsoft Purview, but organizations should always conduct a proof of concept to ensure that their requirements can all be met before implementing the solution.