12.2 Purview Compliance: Insider Risk, Auditing, and eDiscovery

Key Takeaways

  • The Microsoft Purview portal at purview.microsoft.com is the unified place for data security, data governance, and risk and compliance; it replaces the retired Microsoft Purview compliance portal
  • Insider Risk Management detects, investigates, and acts on malicious or inadvertent insider risks such as data leaks and intellectual-property theft — it is a Purview compliance solution, not Microsoft Defender
  • The unified audit log records thousands of user and admin operations across Microsoft 365; Audit (Standard) keeps records 180 days by default, and Audit (Premium) adds longer retention and richer insights
  • Microsoft Purview eDiscovery identifies, holds, searches, reviews, and exports electronically stored information for investigations and legal cases
  • Current Learn describes one eDiscovery experience with premium features (review sets, advanced indexing, analytics) gated by E5-level licensing; older materials still say eDiscovery (Standard) and eDiscovery (Premium)
Last updated: August 2026

Quick Answer: Open compliance work in the Microsoft Purview portal (purview.microsoft.com). Insider Risk Management detects risky insider activity (malicious or accidental). Auditing is the unified audit log of user and admin actions. eDiscovery finds, holds, and exports electronically stored information for legal and investigation work. None of those three is Microsoft Defender, and none of them is a sensitivity label.

The April 30, 2025 MS-900 outline asks you to describe Microsoft Purview compliance solutions such as insider risk, auditing, and eDiscovery. This is a “which Purview tool matches the scenario?” skill. You will not be asked to click through creating an eDiscovery case, write a Keyword Query Language query, or configure an HR connector. You will be asked which solution alerts on a departing engineer downloading source code, which log shows who deleted a SharePoint file last month, and which capability places a mailbox on hold for a lawsuit.

The Microsoft Purview portal

Microsoft Purview is Microsoft’s portfolio for data governance, data security, and data compliance. The Microsoft Purview portal is the unified console. Official Learn: it is a single entry point for settings, search, and roles, covering data security, data governance, and risk and compliance wherever the data lives. The older Microsoft Purview compliance portal (and the classic governance portal) are retired or relocated into this experience.

Sign-in is typically purview.microsoft.com with a work account that has a Purview role. Managing users and licenses still happens in the Microsoft 365 admin center (Chapter 9). Hunting malware and endpoint alerts still happens in the Microsoft Defender portal (Chapter 11). If the stem is “where do compliance admins start for audit, insider risk, labels, DLP, and eDiscovery,” the answer is the Purview portal — not admin.microsoft.com and not security.microsoft.com.

Permissions are role groups in the portal (Roles and scopes). eDiscovery work uses eDiscovery Manager / Administrator style roles. Insider Risk uses its own role groups so investigators are not automatically Global Administrators. MS-900 only needs the idea: Purview access is scoped, not “make them Global Administrator so they can search mail.”

Insider Risk Management — not Defender

Microsoft Purview Insider Risk Management is a compliance solution. Official definition: it helps you detect, investigate, and act on malicious and inadvertent activities that create internal risk. Examples Microsoft lists include leaks of sensitive data, confidentiality violations, intellectual property (IP) theft, fraud, insider trading, and regulatory violations.

Two exam facts sit in that sentence.

First, insider risk includes accidents. An employee who emails a customer list to a personal Gmail “so I can work this weekend” is in scope even if they are not a spy. Policies and templates exist for data leaks, data theft by departing users, risky users, and (in preview / industry templates) things such as patient-data misuse.

Second, this is not Microsoft Defender. Defender XDR, Defender for Endpoint, and Defender for Office 365 hunt malware, phishing, and compromised identities — mostly external or endpoint threat protection. Insider Risk Management correlates Microsoft 365 and Graph signals about people inside the tenant doing risky things with data. Defender for Endpoint alerts can feed some insider-risk security-violation templates. That integration does not make Insider Risk “a Defender product.” If the stem says “which Purview compliance solution,” do not pick Defender.

Official design principles you can name without becoming an investigator:

  • Transparency / privacy by design. Users are pseudonymized by default. Role-based access and audit logs protect investigator access.
  • Configurable policies from templates (departing-user theft, data leaks, and others).
  • Integrated workflow with other Purview tools.
  • Actionable outcomes: notify the user, open a case, or escalate.

The workflow to remember is policy → alert → triage → investigate → action. Analysts can send a reminder notice, open a case, or escalate to eDiscovery when legal review is required. That escalation is the official bridge between insider risk and eDiscovery. Do not study forensic-evidence capture or every preview template for this exam.

Auditing and the unified audit log

Microsoft Purview auditing is how the tenant remembers what people and admins did. Official Learn: the unified audit log captures, records, and retains thousands of user and admin operations across dozens of Microsoft services. Security, IT, insider-risk, compliance, and legal teams search those records for forensic, internal, and regulatory investigations.

You search from the Purview portal, from the Search-UnifiedAuditLog cmdlet, from Microsoft Graph, or by pulling the Office 365 Management Activity API into a SIEM. MS-900 cares that one log covers Exchange, SharePoint, OneDrive, Teams, Microsoft Entra directory activity, and many other workloads — not that you memorize every activity name.

Microsoft still documents two capability levels:

CapabilityAudit (Standard)Audit (Premium)
Enabled by default when the subscription allows itYesYes (includes Standard)
Search in the Purview portal, export to CSV, API accessYesYes, with higher API bandwidth
Default retention180 days (logs from 17 October 2023 onward; older Standard logs were 90 days)180 days, plus 1-year default for Microsoft Entra ID, Exchange, OneDrive, and SharePoint workloads
Custom audit-log retention policiesNoYes, up to 1 year (and 10 years with a separate per-user add-on; not retroactive)
High-value “intelligent insights” (for example richer mail-access and search details)NoYes

Audit (Standard) is the default searchable history. Audit (Premium) is longer retention plus deeper events for investigations. Do not invent other retention numbers. Do not say the audit log places a legal hold — that is eDiscovery. Do not say it blocks a credit-card email — that is data loss prevention (next section).

Typical exam stem: “Who deleted this file, and when?” or “Show admin changes to a mailbox.” That is the unified audit log.

Loading diagram...
Purview compliance jobs: insider risk, audit, and eDiscovery

eDiscovery — legal hold and search, not a malware scanner

Electronic discovery (eDiscovery) is the process of identifying and delivering electronically stored information (ESI) that can be used as evidence in investigations and legal cases. Microsoft Purview eDiscovery does that job for Microsoft 365 content.

Official supported locations include Exchange Online, Microsoft Teams, Microsoft 365 Groups, OneDrive, SharePoint, and Viva Engage. You can search mailboxes and sites together, put locations on hold, and export results. A case is the container: it holds the people working the matter, the searches, the holds, and (when licensed) the review work.

A hold is the exam word for “do not let this evidence disappear.” Official Learn: holds secure ESI from inadvertent or intentional deletion during the investigation. Retention labels (next section) are a lifecycle setting for how long classes of content live. A hold is a legal/investigation preservation on specific locations in a case. Do not mix those two.

Current naming — do not invent SKUs

Microsoft has been consolidating the older split product names. The current eDiscovery overview (Learn, 2026) describes one eDiscovery experience in the Purview portal. Content Search is no longer a completely separate solution; its functions live inside eDiscovery (including a system Content Search case). Capability tables now say eDiscovery feature support versus premium eDiscovery feature support.

What you can say on MS-900 without inventing a catalog name:

  • Core eDiscovery (the classic “Standard” idea): search with keyword / KeyQL queries, statistics and samples, export, role-based permissions, case management, and holds. Office 365 / Microsoft 365 E3-style licensing historically covered this class of work.
  • Premium eDiscovery features require an Office 365 E5 or Microsoft 365 E5 subscription or a related E5 add-on. Official extras include advanced indexing, review sets (a secure Azure Storage copy you can filter, tag, and analyze), import of external data, cloud attachments and SharePoint versions, optical character recognition, conversation threading, decryption of labeled / encrypted items, analytics (near-duplicates, email threading, themes), and Security Copilot assistance.

Older Microsoft pages and many practice questions still say eDiscovery (Standard) and eDiscovery (Premium). Treat those as the previous product names for the same split: search/hold/export versus the richer legal-review workflow. Insider Risk documentation still says you can escalate a case to eDiscovery (Premium). If the exam uses the old names, map them. If it uses “premium eDiscovery features,” map them the same way. Do not invent a third SKU.

You do not need the click path to create a case, add a custodian, or export a PST. You need the job: legal hold + search + export of Microsoft 365 content.

How the three solutions work together

They answer different questions about the same tenant.

SolutionQuestion it answersNot for
Insider Risk ManagementIs this person showing risky insider behavior?Blocking a credit-card email in transit (that is DLP); hunting a ransomware family (that is Defender)
Unified audit logWho did what, when, in which service?Preserving a mailbox from deletion; classifying a file as Confidential
eDiscoveryWhat content must we find, freeze, review, and produce?Scoring departing-user risk in real time

A realistic chain: audit shows a spike of downloads; Insider Risk opens an alert on the departing user; legal escalates to eDiscovery, places OneDrive and the mailbox on hold, searches for project names, and exports. Each tool did one job.

Realistic exam-style scenarios

Departing engineer. HR says a developer resigned and copied repositories to a USB drive and a personal cloud. Insider Risk Management (data theft by departing users) is the Purview compliance answer. Defender may still be interesting for the endpoint, but the outline bullet is insider risk.

Who changed the sharing link? Compliance wants a history of a specific SharePoint file and the admin who altered a mailbox. Search the unified audit log. That is not an eDiscovery hold.

Lawsuit. Counsel needs every Teams chat and mailbox item about a contract, preserved so nobody deletes it, then exported for outside counsel. That is eDiscovery (case, hold, search, export). Premium features matter if they also need a review set and analytics. Do not pick Insider Risk as the legal-hold tool.

Wrong portal. A compliance analyst is sent to the Microsoft 365 admin center usage reports or to the Defender portal incident queue. Usage reports measure adoption. Defender incidents are threat protection. Audit, insider risk, and eDiscovery start in Purview.

Exam traps

  • Insider Risk Management is not Defender. One is Purview compliance for insider behavior. The other is threat protection.
  • Insider risk includes accidents. Malicious and inadvertent.
  • Audit records activity. eDiscovery preserves and produces content. “Who deleted the file?” is audit. “Hold this mailbox for the court case” is eDiscovery.
  • A hold is not a retention label. Hold is case-scoped preservation. Retention is lifecycle.
  • Do not invent eDiscovery edition names. Use core versus premium features, and map older Standard / Premium wording if the question still uses it.
  • Do not study click-by-click case creation. Describe the purpose.
  • Purview portal ≠ Microsoft 365 admin center ≠ Defender portal.

Official sources

Test Your Knowledge

A compliance team wants a Microsoft Purview solution that detects when employees — accidentally or on purpose — leak files or take intellectual property as they leave the company. Which solution matches that job?

A
B
C
D
Test Your Knowledge

An investigator needs to know which administrator deleted a SharePoint file last Tuesday and whether a user downloaded a mailbox item. Which Microsoft Purview capability is designed to answer that?

A
B
C
D
Test Your Knowledge

Outside counsel asks IT to preserve a set of mailboxes and Teams chats so nothing is deleted, then search and export items about a contract dispute. Which Purview solution is built for that legal workflow?

A
B
C
D
Test Your Knowledge

How should you treat the names eDiscovery (Standard) and eDiscovery (Premium) if they appear in a question?

A
B
C
D