QuestionQ8

Understand data protection and governance tasks for Microsoft 365 and Copilot

Your company uses Microsoft Purview data loss prevention (DLP) policies.

A user named User1 shares sensitive information to an external user by using Microsoft Teams.

You need to identify the sensitive content that was shared.

What should you use in the Microsoft Purview portal?

Explanation

Activity explorer collects DLP policy match events from workloads including Teams chat and channels, so an administrator can drill into the specific external-sharing incident to see who shared what, when, where, and which sensitive information type triggered the match. Content explorer instead shows a current snapshot of items already carrying a label or sensitive information type across data stores, rather than a record of a specific past sharing event.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!