16.4 Monitoring Label Usage: Content & Activity Explorer

Key Takeaways

  • Content explorer shows items that match sensitive info types or carry sensitivity/retention labels, with access gated by the Content Explorer Content Viewer and List Viewer role groups
  • Activity explorer shows activities over time — label applied, changed, downgraded, files matched a SIT, protection changed — filterable by user, activity, label, and location
  • Label analytics and usage reports show how many items carry each label, label policy usage, and auto-label policy match summaries
  • The tools support audit and tuning: find unlabeled sensitive content, identify mislabeling, measure auto-label policy effectiveness, and prepare for DLP
  • Permissions and privacy are layered: lower-privilege tiers see de-identified matches, higher tiers see raw sensitive values, and access should be granted on a need-to-know basis
Last updated: August 2026

Quick Answer: Microsoft Purview offers three monitoring surfaces for information protection: Content explorer (where sensitive data lives and what labels it carries), Activity explorer (what users and the service are doing with that data and those labels over time), and label analytics / usage reports (aggregate counts of items per label and label policy effectiveness). Together they let you audit classification, find unlabeled sensitive content, and tune auto-labeling and DLP.

Content Explorer

Content explorer is found in the Purview compliance portal under Data classification > Content explorer. It lists items that match sensitive info types or that carry sensitivity or retention labels, organized by location (Exchange, SharePoint, OneDrive, Teams). For each item you can see the matching SIT, the label, and the item's location.

Content explorer is useful for answering the question "where does our sensitive data live?" and for finding content that should be labeled but is not. After you publish a sensitivity label policy, you can return to Content explorer to measure how much sensitive content remains unlabeled.

Access is gated by two role groups:

  • Content Explorer List Viewer — can see the list of items but not the sensitive values within them (de-identified view)
  • Content Explorer Content Viewer — can open items and see the raw sensitive values

Grant the Content Viewer role only to users with a clear need to see raw sensitive data (e.g., compliance investigators). Most auditors should get the List Viewer role.

Activity Explorer

Activity explorer is found under Data classification > Activity explorer. It shows activities over time, including:

  • Label applied — a sensitivity or retention label was applied to an item
  • Label changed — an existing label was replaced with another
  • Label downgraded — a higher-sensitivity label was replaced with a lower-sensitivity one
  • Label removed — a label was taken off an item
  • File matched a SIT — content matched a sensitive info type
  • Protection changed — encryption or content markings were added, changed, or removed

You can filter by user, activity type, label, location, and date range. Activity explorer is useful for monitoring labeling behavior (e.g., spikes in label downgrades may indicate users bypassing classification), for validating that auto-labeling policies are firing, and for feeding DLP investigations. Activity data is retained for a rolling period, after which it ages out.

Label Analytics and Usage Reports

Beyond the explorers, Purview provides label analytics under Information protection > Label usage and related reports. These reports show:

  • Items per label — how many files and emails carry each sensitivity or retention label, broken down by location.
  • Label policy usage — how often labels from a given policy are applied, and by whom.
  • Auto-label policy match summary — for service-side auto-labeling policies, how many items matched the conditions, how many were labeled, and how many are pending.
  • Trainable classifier retraining feedback — how many items users marked as match/no-match for a classifier, which feeds retraining.

These aggregate reports help you answer "is my labeling program working?" without needing to drill into individual items.

Using the Tools to Audit and Tune

A practical workflow combines the three surfaces:

  1. Find unlabeled sensitive content — In Content explorer, filter to items that match a SIT but have no sensitivity label. These are candidates for an auto-labeling policy.
  2. Identify mislabeling — In Activity explorer, look for label-downgrade spikes or patterns where users remove labels from content that still matches a SIT. Adjust the label policy (e.g., enable mandatory labeling or justification) to reduce this.
  3. Measure auto-label policy effectiveness — In the auto-label policy match summary, compare items matched to items labeled. A large gap suggests the conditions (SITs or classifiers) are too narrow or too broad; tune the conditions.
  4. Prepare for DLP — Use Content explorer to inventory where the most sensitive data lives before you author DLP policies. A DLP policy that targets a SIT in a location where no sensitive data exists is wasted configuration.

Permissions and Privacy Considerations

Because Content explorer and Activity explorer can expose sensitive data and user behavior, apply least-privilege access:

  • De-identification tiers — lower-privilege viewers see de-identified matches (the SIT is named, the matched value is masked); higher-privilege viewers see raw values. Use the lower tier for routine auditing.
  • Role groups — Content Explorer Content Viewer, Content Explorer List Viewer, and the Information Protection roles control what users can see and do. Avoid granting Global Reader to broad populations as a shortcut; it grants more than most audits need.
  • Audit logging — access to Content explorer and Activity explorer is itself logged in the Purview audit log, so you can detect when investigators viewed sensitive items.
  • Privacy regulation — when monitoring personal data under GDPR or CCPA, prefer the de-identified view and limit raw-value access to named compliance officers with a documented basis.

Exam Tip

The MS-102 exam expects you to know which tool answers which question: "where does sensitive data live?" → Content explorer; "what did users do with labels over time?" → Activity explorer; "how many items have each label?" → label usage analytics. Also know the two Content explorer role groups (List Viewer for de-identified, Content Viewer for raw values) and the four-step audit-and-tune workflow (find unlabeled, identify mislabeling, measure auto-label, prepare for DLP).

Test Your Knowledge

A compliance officer needs to see where the organization's credit card data is stored but should not view the raw card numbers. Which role group should you assign?

A
B
C
D
Test Your Knowledge

You want to verify that a new service-side auto-labeling policy is actually applying the Highly Confidential label to matching items in SharePoint. Which tool should you use?

A
B
C
D
Test Your Knowledge

Which report or tool shows how many files and emails carry each sensitivity label, broken down by location?

A
B
C
D