Domain 4 is 15–20% of SC-900 and most candidates under-study it because it sounds like paperwork. That's a mistake: the content is concrete, highly memorizable, and the questions are usually the least ambiguous in the whole exam.
Everything here lives in Microsoft Purview, the compliance portal.
New to the series? Start with Part 0 — how the exam works and how to build a free lab. Parts 1 to 3 cover the concepts, Microsoft Entra and the security solutions.
Objectives updated July 28, 2026. Purview has absorbed several older brands (Microsoft 365 compliance center, Azure Purview). Verify names on Microsoft Learn before your exam.
1. The data lifecycle in one picture
Everything in this domain fits into five stages:
- Know your data — data classification, sensitive information types, trainable classifiers, content explorer, activity explorer.
- Label — sensitivity labels, applied manually, automatically or recommended.
- Protect — encryption, content marking, and DLP policies that block risky sharing.
- Retain — retention labels and policies that keep or delete on a schedule.
- Govern and audit — insider risk management, eDiscovery, audit logs, Compliance Manager.
2. The two labels people confuse
This distinction is worth a guaranteed point:
| Sensitivity label | Retention label | |
|---|---|---|
| Question it answers | How sensitive is this and how do I protect it? | How long do I keep it and what happens then? |
| Typical actions | Encrypt, watermark, header/footer, restrict access | Keep, delete, keep-then-delete, trigger review |
| Travels with the file? | Yes — protection persists outside your tenant | No — it's a policy applied where the item lives |
| Example | "Confidential — Finance" | "Contracts — keep 7 years" |
Key properties of sensitivity labels: only one sensitivity label per item, they can be published to specific users/groups, and they can be applied automatically based on content (auto-labeling).
3. Data Loss Prevention (DLP)
DLP watches content against sensitive information types (credit card numbers, national IDs, health records, and custom ones) and enforces actions:
- Block the action entirely
- Block but allow the user to override with justification
- Just notify the user with a policy tip
- Generate an alert for the compliance team
DLP policies can apply to Exchange, SharePoint, OneDrive, Teams, and endpoints (Endpoint DLP), plus non-Microsoft cloud apps through Defender for Cloud Apps.
4. Retention and records management
- Retention policy — applies broadly to a location (all of SharePoint, all mailboxes).
- Retention label — applies to individual items, and can be applied by users or automatically.
- Records management — declaring an item a record makes it immutable: it can't be edited or deleted until the retention period ends. There's also regulatory record, which is even stricter.
- Disposition review — a human confirms deletion at the end of the period.
Principle to remember: when multiple retention settings conflict, retention wins over deletion, and the longest retention period applies.
5. Insider risk, eDiscovery and audit
- Insider Risk Management — detects risky internal activity: mass downloads before resignation, data leaks, policy violations. Works on signals and templates, with pseudonymization by default.
- Communication Compliance — detects inappropriate or non-compliant messages.
- eDiscovery — finds content relevant to a legal case. Standard does search, hold and export; Premium adds custodian management, review sets and analytics.
- Audit — records what happened. Standard audit for basic activity retention; Premium adds longer retention and critical events.
- Compliance Manager — assessments against standards (ISO 27001, GDPR, NIST) with improvement actions and a compliance score.
- Service Trust Portal — where Microsoft publishes its own audit reports, certifications and compliance documents. If a question asks "where do I download Microsoft's SOC 2 report?", that's the answer.
6. Privacy and trust
Microsoft's stated privacy principles are worth recognizing: control, transparency, security, strong legal protections, no content-based targeting, and benefits to you. Microsoft Priva is the privacy risk management product; the Trust Center is the public documentation hub.
🧪 Lab 1: build a DLP rule that blocks a credit card number
Time: 20 minutes. Needs: Microsoft 365 E5 trial.
- Go to purview.microsoft.com → Data loss prevention → Policies → Create policy.
- Choose the template Financial → Credit card number (or start from a custom policy).
- Scope it to Exchange email only, for your test users.
- In the rule, set the action to Block with override and enable the policy tip.
- Turn on Test mode with policy tips first.
- Send yourself an email containing a test credit card number (use a documented test value such as
4111 1111 1111 1111— never real data). - Watch the policy tip appear. Then check Activity explorer for the event.
Expected result: a screenshot of the policy tip firing. This is the most convincing artifact you can put in a portfolio for a compliance-adjacent role.
🧪 Lab 2: sensitivity label vs retention label
Time: 20 minutes.
-
Information protection → Labels → Create a label named
Confidential – Finance. Enable encryption and add a footer "Confidential". - Publish it to your test user.
- In Word online, apply the label to a document, then download the file and try to open it from an account without permission. It stays protected — that's the label travelling with the file.
- Now go to Data lifecycle management → Retention labels and create
Contracts – keep 7 years. - Apply it to a document in SharePoint and try to delete it.
Expected result: you experienced the difference between "protect the content" and "control the lifespan." You won't forget it in the exam.
Then check yourself
The "which control solves this?" exercise is on the interactive practice page, along with a second one that fixes the tool confusion in this domain — Service Trust Portal vs Compliance Manager vs Content Explorer vs Audit. Both grade themselves.
⚠️ Exam traps in this domain
- Sensitivity vs retention label — protection vs lifespan. Read the verb in the question: protect/encrypt → sensitivity; keep/delete → retention.
- Only one sensitivity label per item, but multiple retention settings can interact (longest retention wins).
- Service Trust Portal = Microsoft's own audit reports. Compliance Manager = your organization's posture and improvement actions.
- Insider Risk Management is about internal users; Defender products are about external threats.
- eDiscovery Standard vs Premium — Premium adds custodians, review sets, and analytics.
- Compliance score is not a guarantee of compliance, it's a measure of implemented improvement actions.
🎯 Now practise it: 12 questions + both labs
This domain rewards precision with words. "Protect it" and "keep it" sound similar in a meeting and mean two completely different products on the exam.
So the practice lives in an interactive page instead of a list you can scroll past:
👉 Take the Part 4 quiz and labs
What you get:
- 12 exam-style questions. Pick an answer and you immediately see why it's right — and why each of the other three is wrong. The distractors are the ones that actually catch people: sensitivity vs retention label, Service Trust Portal vs Compliance Manager, Content Explorer vs Activity Explorer, block vs block with override.
- Options shuffled on every attempt, so retaking it tests the concept instead of the position you memorized.
- Lab 7 — which control solves this? Six business requirements in plain English; you pick the Purview capability. This is how the exam phrases every question in the domain.
- Lab 8 — where do I go for this? The tool confusion, fixed in five minutes.
With this, the page now covers all four domains: 48 questions and 8 labs. Free, no sign-up.
Comment your score out of 12. If this domain gives you the least trouble of the four, that's normal — and it's exactly why skipping it is such an expensive mistake.
What's next
Part 5 is the finish line: a 30-question mock exam covering all four domains with full explanations, a one-page glossary of every product name in SC-900, and my exam-day strategy — including how to handle the multi-select questions that trip most people up.

Top comments (0)