13.2 Microsoft Priva Capabilities and Benefits

Key Takeaways

  • Current official Learn positions Microsoft Priva as privacy-operations software; the GA solution to name is Priva Privacy Risk Management in the Microsoft Priva portal at purview.microsoft.com/priva
  • Priva uses Microsoft Purview data classifications and sensitive information types to find personal data in Exchange Online, SharePoint, OneDrive, and Teams inside the organization’s tenant — not in a user’s personal Microsoft account
  • Built-in Privacy Risk Management templates target overexposed personal data, transfers across departments or borders, and unused / minimized personal data, then help owners remediate
  • Benefits are visibility, risk identification, owner notification, and less manual privacy work; Priva can feed Microsoft Purview Compliance Manager assessments, but it is not DLP, not a sensitivity label, and not Microsoft Defender
  • Older MS-900 materials listed Priva Subject Rights Requests for data subject request automation; current Microsoft documentation routes GDPR Data Subject Requests to Microsoft Purview eDiscovery
Last updated: August 2026

Quick Answer: Microsoft Priva is Microsoft’s privacy-operations family. Current official Learn (updated 2026) centers on Priva Privacy Risk Management in the Microsoft Priva portal (purview.microsoft.com/priva). It uses Microsoft Purview classifications and sensitive information types (SITs) to find personal data in Exchange Online, SharePoint, OneDrive, and Teams, then helps you detect overexposed personal data, risky transfers, and unused personal data so owners can remediate. It is not data loss prevention, not a sensitivity label, and not Microsoft Defender. Older MS-900 study materials also listed Priva Subject Rights Requests; current Microsoft documentation routes Data Subject Requests to Microsoft Purview eDiscovery.

The April 30, 2025 MS-900 outline asks you to describe the capabilities and benefits of Microsoft Priva. This is a “which privacy tool?” skill. You will not be asked to author a custom SIT regex or click every policy wizard. You will be asked what Priva is for, which risks the built-in templates address, which workloads it evaluates, how it differs from Purview DLP and Defender, and what benefit you get versus doing privacy work only in spreadsheets.

MS-900 retired on March 31, 2026. Teach current Microsoft product names, then map older outline wording if a question still uses it. This section is not legal advice. Priva does not make the tenant GDPR-certified any more than buying Microsoft 365 did in the last section.

What Microsoft Priva is

Official overview: organizations need a privacy-by-default stance and ways to give people control over their data. Microsoft Priva supports privacy operations across an organization’s data landscape. Priva Privacy Risk Management, located in the Microsoft Priva portal, provides visibility into the organization’s data. Customizable policies help identify privacy risks and enable remediation.

The Microsoft Priva portal is designed to give streamlined access to Priva privacy protection and privacy risk management capabilities. Sign-in is typically https://purview.microsoft.com/priva. That URL sits next to the broader Microsoft Purview portal you met in Chapter 12. Managing users and licenses still happens in the Microsoft 365 admin center. Hunting malware still happens in the Microsoft Defender portal. Privacy-risk policies and personal-data insights start in Priva.

Official service description: Priva helps companies safeguard personal data and build a privacy-resilient workplace by proactively identifying and protecting against privacy risks such as data hoarding, data transfers, and data oversharing, and by empowering information workers to make smart data-handling decisions.

Priva is an add-on. The service description lists it for organizations that already have qualifying Office 365 or Microsoft 365 plans (the A/E/G 1/3/5 families). Features such as personal data minimization, overexposure, transfer monitoring, data-owner notification, admin alerting, personal data insights, and Compliance Manager integration require the Privacy Risk Management add-on. It is enabled at the tenant level; Microsoft recommends licensing users you intend to protect. Official setup guidance also notes that Priva is not available if the organization provisioned its tenant in certain local data centers listed on Learn — treat that as a deployment footnote, not a geography list to memorize.

Permissions use role-based access control in the Purview / Priva settings. Role groups such as Privacy Management Administrators, Analysts, Investigators, and Viewers separate who can create policies, who can see metadata, and who can open file content. MS-900 only needs the idea: privacy work is scoped. Do not make every investigator a Global Administrator.

How Priva finds personal data

Official definition: personal data is typically personal information related to a living person that can identify that person — a name, passport number, national identification number, or combinations of types. The legal definition varies by law; Microsoft tells you to understand the types you have obligations for.

Priva uses foundational Microsoft Purview capabilities: data classifications and sensitive information types (SITs). Organizations that create custom classifications and SITs can use them in Priva. SITs are pattern-based classifiers (credit cards, national IDs, and similar). Official example: if one item contains three credit-card numbers and one Social Security number, that item has two unique SITs and four instances.

Priva evaluates data stored in these Microsoft 365 services inside the tenant:

  • Exchange Online
  • SharePoint Online
  • OneDrive for Business
  • Microsoft Teams

It evaluates data only inside the organization’s Microsoft 365 environment. It does not access a user’s personal Microsoft 365 account. It can also evaluate data sources registered through Microsoft Purview data governance. Current Reports documentation also describes preview insights for some non-Microsoft 365 locations; MS-900 still scores the four Microsoft 365 workloads above.

The Reports experience visualizes personal data type instances, top locations with sensitivity labels, overexposed personal data trends, transfer trends, and unused personal data. Those reports are how a privacy team answers “where is the personal data, and is it rotting or overshared?” without opening every site by hand. Privacy Risk Management policies may also use Microsoft 365 audit log activity, so setup guidance tells you to confirm auditing is on.

Privacy Risk Management policies

Official Learn: policies are internal guides that help you:

  • Detect overexposed personal data so users can secure it
  • Spot and limit transfers of personal data across departments or regional borders
  • Help users identify and reduce unused personal data you store

Built-in templates cover those scenarios. You can start from a template or create a custom policy.

Data overexposure policies find personal data that is insufficiently secure — a site open to too many people, stale permissions, items shared too broadly, including content accessible to the public. Official remediation options include making items private, notifying content owners, or tagging items for further review.

Data transfer policies watch personal data moving outside the organization, between departments, or across regional borders. Unencrypted email to unauthorized recipients is the classic story. Matches can have regulatory impact or violate internal privacy practice. Corrective actions again include making items private or tagging them.

Unused personal data / minimization (service description: personal data minimization; overview: unused personal data you store) is the hoarding problem. Privacy principles such as GDPR’s storage-limitation idea expect you not to keep personal data longer than you need. Priva insights show how long content with personal data sits unused so owners can delete or secure it. That is not a retention label and not an eDiscovery hold.

When policies match, admins review alerts and can create issues so users take action. Data-owner notification inside the productivity suite is an official benefit: the person who owns the library gets a nudge instead of a privacy team opening hundreds of tickets by hand.

Loading diagram...
Priva Privacy Risk Management versus neighboring Microsoft 365 tools

Benefits you should be able to name

Memorize the benefit list, not the click path.

BenefitWhat Microsoft currently documents
VisibilityAutomate discovery of personal-data assets and see which types live where
Risk identificationOverexposure, transfers, unused / hoarded personal data
RemediationRecommended controls; make private; notify owners; tag for review
Worker engagementPrompt people inside Microsoft 365 instead of only emailing a privacy office
Less manual privacy workPolicies, alerts, and reports replace spreadsheet hunts
Compliance Manager integrationCompleting Priva actions can contribute to privacy-related assessments and compliance score

Microsoft Purview Compliance Manager remains the assessment engine — templates that correspond to regulations and industry standards, including privacy and data-protection assessments. Official Learn: taking steps in Priva to protect stored personal data can contribute to your privacy assessments in Compliance Manager and can help improve compliance score. Some improvement actions are auto-detected (for example, setting up a Privacy Risk Management policy). If a question says “build a GDPR assessment template,” that is Compliance Manager. If it says “find overshared national IDs in SharePoint,” that is Priva.

Microsoft Purview Data Loss Prevention (DLP) remains the product that helps prevent unintentional sharing of sensitive items outside the organization. Official Priva setup guidance: Priva can extend that protection with organization-specific insights and by letting users fix risks quickly. Extension is not replacement.

Priva versus Purview protection versus Defender versus eDiscovery

This matching table is the exam.

JobProduct familyWhy it is not the other product
Privacy operations: find overshared or unused personal data and coach ownersMicrosoft Priva Privacy Risk ManagementDLP blocks or warns on sharing; it does not run the privacy-risk program
Classify a file Confidential and encrypt itMicrosoft Purview sensitivity labelsLabels mark and protect content; they do not score unused personal data
Stop a credit-card number leaving by emailMicrosoft Purview data loss preventionDLP is information protection / oversharing prevention
Hunt phishing and ransomwareMicrosoft Defender XDRDefender is threat protection
Preserve and export content for a lawsuitMicrosoft Purview eDiscoveryLegal hold and electronically stored information
Find personal data to answer a GDPR Data Subject RequestCurrent Learn: Microsoft Purview eDiscovery (and in-app tools)See the naming note below

Sensitivity labels that already exist show up in Priva location reports; applying a label is still a Purview information-protection action. Insider Risk Management (Chapter 12) scores risky people. Priva scores risky personal-data handling. Do not swap those two Purview-adjacent names.

Naming note: Subject Rights Requests

The April 30, 2025 MS-900 outline was written when Microsoft marketed two headline Priva solutions: Privacy Risk Management and Subject Rights Requests (SRR) for automating data subject / data subject access requests. Current official pages (Learn, May 2026) describe Priva as Privacy Risk Management. The former Priva Subject Rights Requests documentation URL now redirects to Microsoft Purview eDiscovery. Microsoft’s Office 365 Data Subject Requests for the GDPR and CCPA guide tells administrators to use Purview eDiscovery (and native app tools) to discover, access, rectify, restrict, export, and delete personal data. The controller still replies to the person; Microsoft supplies the search and export machinery.

If a question still uses the older “Priva automates subject rights requests” wording, map it to the privacy-operations idea: Microsoft gives the controller tools so individuals can exercise rights. Score the current product name as Privacy Risk Management, and score today’s documented DSR search/export path as Purview eDiscovery. Do not invent a third live Priva SKU called Privacy Assessments — current Learn points assessment templates to Compliance Manager, which can credit Priva actions.

Realistic exam-style scenarios

Overshared employee IDs. HR finds a SharePoint site with national identification numbers shared to “everyone except external.” Priva data overexposure — not Defender, not Autopilot.

Cross-border payroll mail. Finance emails a payroll file to a partner in another region. A Priva data transfer policy is the privacy-risk view. A DLP policy may also block the send. If the stem says “prevent the send,” pick DLP. If it says “find and remediate personal-data transfer risk,” pick Priva.

Hoarded résumés. A team library is full of five-year-old résumés nobody has opened. Unused personal data / minimization. Not an eDiscovery hold and not a Defender incident.

An EU resident asks for a copy of everything the company stores about them. The customer (controller) must respond. Current Microsoft documentation: search with Purview eDiscovery. Do not say Defender will answer the DSR, and do not say buying Microsoft 365 auto-replied to the person.

Wrong portal. Privacy analysts are sent to security.microsoft.com or to Microsoft 365 usage reports. Threat incidents are Defender. Adoption numbers are the admin center. Personal-data risk is Priva.

Exam traps

  • Priva is privacy operations, not antivirus and not DLP.
  • Current official product to name is Priva Privacy Risk Management.
  • Workloads: Exchange, SharePoint, OneDrive, Teams — not a user’s personal Microsoft account.
  • Overexposure / transfer / unused are the three risk stories.
  • Compliance Manager assessments are not Priva, but they integrate.
  • Older Subject Rights Requests branding maps to eDiscovery in current Learn.
  • Buying Priva does not make the tenant GDPR-certified.
  • Do not study click-by-click policy creation. Describe the purpose and the benefit.

Official sources

Test Your Knowledge

What is Microsoft Priva primarily designed to do in current official Microsoft documentation?

A
B
C
D
Test Your Knowledge

A compliance team wants to stop employees from emailing credit-card numbers outside the company. Separately, they want a tool that finds already-stored personal data that is overshared on SharePoint. How should they match those jobs to current Microsoft products?

A
B
C
D
Test Your Knowledge

Which official benefit of Priva Privacy Risk Management matches Microsoft’s current Learn description?

A
B
C
D
Test Your Knowledge

An older practice question still says Microsoft Priva automates subject rights / data subject requests. How should you map that wording to current Microsoft documentation?

A
B
C
D