4.1 Monitor Classification with Data Explorer and Content Explorer
Key Takeaways
- Data explorer and Content explorer (classic) show a current snapshot of items that already have a sensitivity label, retention label, sensitive information type (SIT) match, or trainable classifier match—not a 30-day activity log.
- Compliance administrator (and similar tab-level roles) do not grant item listing or file preview. List viewer shows locations; Content viewer is required to preview contents and to see item names that may contain sensitive data.
- Explorer counts can take up to seven days to update, and up to 14 days for SharePoint files. Encrypted sensitivity labels on SharePoint and OneDrive do not surface; encrypted document preview and download are disabled.
- Activity explorer, Purview Audit, and eDiscovery answer different questions (recent actions, longer audit trail, legal search/hold) and are not substitutes for classification inventory.
- Published licensing: Content Explorer and Activity Explorer analytics interfaces require E5-class plans (or Office 365 E5); E3-class tenants still receive Content Explorer data aggregation.
Monitor classification with Data explorer and Content explorer
Quick Answer: Data explorer and Content explorer (classic) show a current snapshot of items that already have a sensitivity label, a retention label, a sensitive information type (SIT) match, or a trainable classifier match. They are inventory tools. Activity explorer answers “what did someone do?” for about 30 days. Purview Audit is the longer audit trail. eDiscovery is how you search and hold items for a case (the July 28, 2026 SC-401 list uses eDiscovery, not the older Content search wording).
Microsoft Purview classifies content before you publish a DLP or auto-labeling policy. Microsoft calls that zero change management: the platform scans for built-in SITs, labels, and classifiers so you can see the blast radius of a future policy. The SC-401 bullet Monitor data classification and label usage by using Data explorer and Content explorer tests whether you know which explorer answers which question and whether you can assign the least-privilege roles that actually open item lists and previews.
Where the explorers live
In the Microsoft Purview portal, open Solutions > Information Protection > Explorers. You will see three related surfaces; only the first two are this skill:
- Data explorer — the current, consolidated view of classified and labeled items. Information Protection Reports (sensitivity label usage, SIT concentration, trainable classifier usage, data sources with sensitive info) link here when you leave a chart and inspect the underlying items.
- Content explorer (classic) — the older, location-based browse experience. Microsoft Learn still titles the product doc Get started with Content Explorer (classic). You can also reach it from Data Lifecycle Management > Explorers > Content explorer.
- Activity explorer — not an inventory. It is a transformed view of Microsoft 365 unified audit logs covering up to 30 days of actions on labeled and sensitive content. It belongs to Analyze Purview activities by using Activity explorer in the alerts-and-activities domain, not this classification-monitoring bullet.
Use Data explorer for most analysis. Use Content explorer (classic) when you need the older location-drill UI, saved views keyed to specific SITs and labels, or a procedure written against the classic tool. Microsoft Learn’s SC-401-aligned training is explicit: Data explorer is the unified interactive view; Content explorer (classic) remains for continuity and does not replace Data explorer’s report-linked investigation path.
What “monitor classification and label usage” actually means
Both explorers show a snapshot of items that are already classified or labeled, not a live catalog of every file in the tenant and not a who-did-what timeline.
| Signal | What the explorers show | Prerequisite that trips exam items |
|---|---|---|
| Sensitive information types | Items that matched a built-in or custom SIT (credit card, national ID, custom pattern, and so on) | The item must have been scanned; a SIT that exists but has never matched anything appears empty |
| Sensitivity labels | Items tagged with labels such as Confidential or Highly Confidential | You must enable sensitivity labels for files in SharePoint and OneDrive or those files never surface on the data classification page |
| Retention labels | Items with a retention or records label | Explorers snapshot labeled items; Activity explorer does not monitor Exchange retention activities |
| Trainable classifiers | Items the classifier identified from examples rather than a regex | Match / Not a match feedback is documented for SharePoint and OneDrive matched items |
Encrypted sensitivity labels do not surface in Content explorer for SharePoint and OneDrive. Document preview and download are disabled when a document is encrypted, so a Content viewer still cannot open the payload. That is a security control, not a misconfiguration.
When you update a SIT definition, existing files are not reclassified until someone modifies them. New files created after the change use the new definition. An item that says “I tightened the SIT but Content explorer still lists last month’s matches” is describing this behavior.
Counts are not real-time. Microsoft publishes that it can take up to seven days for counts to update in Data explorer and Content explorer, and up to 14 days for files in SharePoint. A labeled contract uploaded this morning that is missing from the count is usually latency, not a failed label policy.
Data explorer versus Content explorer
| Capability | Data explorer | Content explorer (classic) |
|---|---|---|
| Job | Unified snapshot of SITs, sensitivity labels, retention labels, and trainable classifiers | Same classified-item universe, browsed by location |
| How you work | Filter by label, classifier, or SIT, then drill Data source (Exchange, OneDrive, SharePoint, Teams, and connected sources such as Copilot in the current UI) | Expand a label or SIT, then drill All locations through the folder tree |
| Reports | Linked from Information Protection Reports for “explore applied labels / SITs” | Opened separately from reports |
| Saved views | Filter-centric investigation | You can save customized views (SITs, sensitivity labels, trainable classifiers, retention labels) and mark a default view |
| Export | Export writes a CSV of whatever the current pane is focused on | Same CSV export of the current pane |
Both tools let you double-click an item to open it natively in the explorer when you have Content viewer rights and the file is not encrypted. Neither tool places a hold, runs a case query, or builds a review set.
Filters you can actually search on
When you drill into a location, a Filter tool appears. Scope is whatever the locations pane is showing.
- Exchange or Teams: search on the full mailbox address, for example
user@contoso.com. Partial display names are the wrong mental model. - SharePoint or OneDrive: search on full site URL (
https://contoso.onmicrosoft.com/sites/sitename), file name (RES_Resume_1234.txt), the prefix before an underscore (RES), the token after an underscore (Resumeor1234), or the extension (txt).
Export is a listing of the current focus, not an automatic tenant-wide dump of every classified file. Filter first, then export.
Permissions: the exam’s favorite trap
Access is highly restricted because explorers can show the contents of scanned files. Those Purview roles supersede the SharePoint, OneDrive, or mailbox permissions on the item. A user who cannot open a file in OneDrive can still read it in Content explorer if you grant Content viewer. Treat that as a privileged investigation role, not a convenience add-on to Compliance administrator.
Microsoft documents two layers:
-
Reach the explorer tab. Entra ID / Microsoft 365 roles such as Compliance administrator, Security administrator, and Compliance data administrator (Data explorer’s tab list also includes Global administrator) get you onto the page. Information Protection Admin, Analyst, Investigator, and Reader roles, plus the matching Information Protection role groups, appear in the fine-tune list. Membership here does not let you see the item list or the file contents.
-
See items and contents. Independent role groups (you can also add the roles to a custom group):
| Role group | Underlying role | What it allows |
|---|---|---|
| Content Explorer List viewer / Data Explorer List viewer | data classification list viewer | Each item and its location in list view |
| Content Explorer Content viewer / Data Explorer Content viewer | data classification content viewer | Contents of each item. Also required to see item names in list view, because names themselves can be sensitive |
The two groups are not cumulative. List viewer alone never becomes a preview. If the account must both locate files and open them, assign both. Role Management holders in Purview assign these groups. Administrative units can further restrict list/content viewer members so they only see items in their AU.
Least privilege on SC-401: do not hand Global administrator to a classification analyst. Do not assume Compliance administrator can preview payment-card data in Content explorer. Microsoft recommends the role with the fewest permissions; Global administrator is documented as a last resort.
Accuracy feedback and previews
In Data explorer and Content explorer you can see how many matches a SIT or trainable classifier produced and mark Match or Not a match. That feedback is how you tune classifiers. Microsoft documents the contextual summary / feedback path for SharePoint and OneDrive matched items. Open the SIT link on a document to see which types matched and at what confidence, then use Contextual Summary to judge the hit.
Content explorer can preview Exchange email attachments without downloading the message for a published set of types (Office documents, PDF, text/CSV/HTML/XML/JSON/RTF, several source extensions, JPG/PNG/JPEG, and EML). Excel preview in Content explorer supports files up to 25 MB.
Licensing (published service description only)
The Microsoft Purview service description states that data classification analytics (the Content Explorer and Activity Explorer interfaces) requires Microsoft 365 E5/A5/G5, Microsoft 365 E5/A5/G5 Compliance, Microsoft 365 E5/A5/G5 Information Protection & Governance, or Office 365 E5. Content Explorer data aggregation still runs on Microsoft 365 E3/A3/G3 and Office 365 E3 so the platform can keep counting even when the full analytics UI is not licensed. Microsoft does not publish a separate SKU row labeled only “Data explorer” in that table; treat Data explorer as part of the same data-classification analytics family and verify the current service description rather than inventing a unique SKU.
Do not pick the wrong Microsoft 365 search surface
SC-401 mixes four tools that all “find sensitive stuff.” Only Data explorer and Content explorer are this chapter.
| Question | Correct surface | Why the others fail |
|---|---|---|
| How many items currently have label X or SIT Y, and where do they live? | Data explorer (aggregated usage and drill-down) and Content explorer (item list with access controls) | Activity explorer is actions, not inventory |
| Did someone downgrade a label, copy a file to USB, or hit a DLP rule? | Activity explorer (about 30 days from unified audit) or Purview Audit for a longer search | Explorers do not reconstruct who clicked what |
| Produce or hold mailbox/site content for a legal matter | eDiscovery | Explorers are not a case, hold, or review set |
| Confirm an activity that Activity explorer has not shown yet | Audit (core workloads often take 60–90 minutes to appear in Activity explorer; Activity explorer is not real-time) | Waiting on explorer counts will not surface an audit event |
A practical monitoring workflow that matches the exam:
- Open Information Protection Reports to see label coverage, top SITs, and where sensitive data concentrates.
- Pivot into Data explorer for the classifier or label that looks wrong (too many credit-card hits in a public site, too few Highly Confidential files in Finance).
- If you need the classic tree or a saved view of “only these 12 SITs,” open Content explorer.
- Assign List viewer to people who may know that a file exists; add Content viewer only for investigators who must read it.
- When the question is about a user action, leave this chapter’s tools and go to Activity explorer or Audit.
If you remember only three sentences: explorers are a snapshot of classified and labeled items, List viewer and Content viewer are independent and Content viewer is required for names and previews, and Activity explorer / Audit / eDiscovery are different jobs.
A classification investigator must open SharePoint files in Content explorer to confirm whether a Highly Confidential label was applied to the right documents. The account is already a Compliance administrator. Which additional assignment does Microsoft document as required to preview file contents and to see item names that may contain sensitive data?
A finance site owner applied a sensitivity label to SharePoint files this morning. Data explorer still shows yesterday’s counts. According to Microsoft’s explorer documentation, what latency should you expect before treating the missing count as a broken label?
Your CISO asks two questions: how many OneDrive items currently match the Credit Card Number SIT, and which users copied those files to a USB drive last week. Which pairing matches Microsoft’s tool design?