Skip to main content
Valto — Keep ahead of tomorrow

Security

Microsoft Purview & data protection

Before you can control what your AI sees, you have to know what your data is. Valto configures Microsoft Purview: sensitivity labels that determine who can open a document and whether it can leave the organisation, data loss prevention policies that stop sensitive information being shared by accident, and retention and records management that enforce the schedule your organisation has decided on. We start by establishing what your licences already include and where your data actually sits.

Data and cloud
Microsoft Solutions Partner

TRUSTED BY ORGANISATIONS LIKE YOURS

Mind
Greene King
Grosvenor
City of London logo
Chester Zoo
ABM
Human Appeal
John Deere
UKTV
Astrazenica
Money Supermarket
Princes
Sony
Shell
BBC
Overview

Know what your data is, and where it is allowed to go

Most organisations can tell you their retention policy in principle and cannot tell you whether it is applied. Sensitive documents sit in general locations, nothing is labelled, sharing links have accumulated for years, and the only real control on what leaves the organisation is that people are careful. That was tolerable while the risk was theoretical. It is less tolerable now that an AI assistant will happily summarise whatever the signed-in user can technically reach, which is usually a great deal more than anyone intended. Valto establishes the position first: where your sensitive information actually sits, what is labelled and what is not, what your existing licences already entitle you to, and where the gap is between the retention position your organisation has decided on and the one currently configured. Most organisations find that decision was never written down. We then configure what is needed and no more. A classification scheme with four labels that people use is worth considerably more than one with fourteen that they ignore, and over-configured DLP is the fastest way to get a policy switched off after a fortnight of blocked emails.

What Purview actually covers, and what you already have

Purview is a set of capabilities rather than one product, and they are licensed in pieces. This is roughly what each one does and where it usually sits. Confirming your actual entitlement is the first thing we do.

Classify documents and emails by sensitivity, and attach protection to the classification: encryption, access restriction, watermarking, and rules about whether content can be shared externally. Basic labelling is broadly available; automatic labelling based on content, and labelling that follows a file wherever it goes, generally requires E5 or the information protection add-on.
Policies that detect sensitive information in transit, in email, in Teams, in SharePoint and on endpoints, and either warn the user or block the action. Basic DLP for Microsoft 365 locations is widely included; endpoint DLP and the more advanced conditions typically require E5.
Retention policies applied to whole locations, retention labels applied to individual items, and records management for content that must be declared and preserved. Basic retention is broadly available; automatic application of labels, event-based retention and records management usually require E5 or an add-on.
Detects risky behaviour by people inside the organisation, such as unusual volumes of data being downloaded or forwarded ahead of a resignation. E5 or add-on.
Monitors internal communications against policy, used in regulated sectors for conduct and market abuse obligations. E5 or add-on.
Search, hold and export content for litigation, regulatory request or investigation, and retain audit logs for long enough to be useful. Basic capability is broadly available; advanced eDiscovery and extended audit retention require E5 or add-ons.
If you are on Microsoft 365 Business Premium, you have basic labelling, basic DLP and basic retention, which is more than most Business Premium customers use and enough to make a real difference. If you are on Microsoft 365 E3, you have the foundations and not the automation. Automatic labelling, endpoint DLP and records management are the usual gaps, and closing them means either add-ons or E5. If you are on E5, you almost certainly hold capability that is switched off. In our experience this is the most common position and the one with the fastest return.

Our Purview services

Establish where your sensitive data actually is

We review what information you hold and where it sits, what is currently labelled, how content is being shared internally and externally, what your retention configuration actually does, and what your licences entitle you to. You get a prioritised findings report. Almost every assessment finds sensitive content in general locations and a retention configuration that does not match what anyone believed it was.

Expertise
Microsoft data protection specialists
Clarity
Know what your data is, and where it can go
Value
Start with the labels you already own

Why work with Valto on Purview?

We start with what you are licensed for

Purview is the most licence-gated area of Microsoft 365 and the most common reason organisations do nothing is not knowing what they already have. We establish that first, and in most cases the basics are already covered.

We configure less than you might expect

Four sensitivity labels people use beat fourteen they ignore, and DLP set to block on day one gets switched off by the end of the month. We start narrow, in warning mode, and extend once it is working.

Clear about what is a legal decision and what is a configuration one

We implement the retention and classification decisions your organisation has made, and tell you where one has not been made. We do not set your retention periods, and we will tell you when you need advice we are not qualified to give.

Classification is what makes Copilot safe to deploy

Sensitivity labels and DLP determine what an AI assistant can surface and what can leave the organisation. This work is the prerequisite for most Copilot rollouts, and it improves search and governance whether or not Copilot goes ahead.

Configured with the rest of the estate in mind

Labels are enforced through identity, applied across SharePoint, Teams and endpoints, and interact with device policy. We configure Purview in the context of the estate rather than in isolation.

Power Apps Envisioning Workshop

WHAT WE TYPICALLY FIND

Where data protection turns out to be assumed rather than configured

Very little of what we find is missing licensing. It is capability switched off, policies that protect part of the estate, and decisions nobody ever wrote down.

  • No retention schedule written down anywhere, and a configuration that reflects nobody's decision
  • Sensitivity labels available in existing licences and never enabled
  • A label scheme created once, never adopted, and now ignored
  • DLP policies in audit mode indefinitely, generating reports nobody reads
  • Sensitive information sitting in general-access locations with no classification

Turn data protection into business value

Data protection is easier to fund when it is clear what changes. These are the outcomes the work is for.

Copilot surfaces whatever the signed-in user can reach and summarises whatever it finds. Classification and DLP are what turn that from a governance risk into a controlled capability, and this work is the prerequisite for most Copilot rollouts.
Most sensitive data leaves organisations by mistake rather than by malice: wrong recipient, wrong attachment, a file shared with a link that was never meant to travel. DLP in warning mode prevents a large share of that without obstructing anybody.
Data you have deleted on schedule cannot be leaked, requested or disclosed. Disciplined retention reduces the volume at risk and the cost of answering a subject access request or a disclosure exercise.
Classification and search working properly turns a data subject request from an all-hands exercise into a defined task.
A documented classification scheme, a configured retention position and audit logs that go back far enough are what turn an assertion into evidence.
Encrypted, labelled content is protected even when it leaves the environment, which means a compromised account or a lost file has a smaller consequence.

How we deliver Purview projects

From establishing where your sensitive data actually is, through to a classification scheme people use and a retention position that matches what your organisation has decided.

  1. Security assessments
    1

    Assessment

    Establish the current position

    We review where sensitive information sits, what is labelled, how content is shared, what your retention configuration actually does, and what your licences entitle you to. This is also where we identify whether a retention schedule exists.

  2. SharePoint Consultant hosting a requirements workshop
    2

    Design

    Agree the scheme, not just the settings

    We design a sensitivity label scheme and DLP approach around how your people actually work, and confirm with you which decisions are yours to make and which we are implementing. Fewer labels, clearly understood, is the objective.

  3. People working on computers
    3

    Pilot

    Test it on real work

    We apply the scheme to a defined group and see what happens. Labelling and DLP are felt by users immediately, and the false positives only surface against real activity.

  4. Woman working at a computer
    4

    Rollout

    Extend in phases, in warning mode first

    We extend across the estate in stages, with DLP warning before it blocks, and communications so people understand what the labels mean and why they exist.

  5. Valto team at Microsoft London
    5

    Review

    Tune, extend and evidence

    We reduce false positives, extend automatic labelling where it is working, and establish the reporting that lets you evidence the position to whoever asks.

We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how classification, identity, devices and content fit together rather than treating data protection as a set of policies to switch on. Whether you're classifying data for the first time, preparing for Microsoft 365 Copilot, or trying to work out whether your retention configuration does what you think it does, we help organisations get real control of information they already hold.

WHY ORGANISATIONS CHOOSE VALTO

Microsoft Solutions Partner
Apps on a phone

CONNECTED, ACROSS MICROSOFT

A label is only as good as what enforces it

A sensitivity label is a decision. Whether that decision is honoured depends on Entra ID and conditional access controlling who can open the file, Intune controlling which devices it can be opened on, SharePoint and Teams controlling where it lives, and Defender detecting when something tries to move it. Purview classifies; the rest of the estate enforces. Valto brings together expertise across Microsoft 365, Entra ID, Intune, Defender, SharePoint and Microsoft 365 Copilot. That lets our consultants design classification that the rest of your environment can actually act on, and recognise when the answer is a permissions or sharing change rather than another label. The result is one consistent position on what your data is, who can reach it and where it is allowed to go.

The team driving you forward

Rob Thomas
Rob ThomasMS365 & Azure Business Unit Lead
SharePoint Consultant hosting a requirements workshop
Harry BarnettPre-Sales Consultant
Girl with trophy
Will JonesSenior Cloud Consultant
James BelseySenior Project Manager

Questions, answered plainly

Practical answers on what your licences include, how classification relates to Copilot, what happens to users when DLP is switched on, and who decides your retention periods.

In almost every case, yes. Copilot surfaces whatever the signed-in user can reach and summarises whatever it finds, so unclassified sensitive content in general-access locations becomes considerably more discoverable than anybody intended. Sensitivity labels and DLP are the controls that make it manageable. The work also improves search and governance whether or not Copilot goes ahead.
It depends on your licensing and it is genuinely hard to work out, which is why we start there. Broadly, basic labelling, basic DLP and basic retention are available across most business plans including Business Premium. Automatic labelling, endpoint DLP, records management, insider risk and communication compliance generally need E5 or an add-on. We confirm your exact entitlement rather than working from the plan name.
You do, and that is not us being unhelpful. How long you must keep employment records, contracts, clinical records, financial records or client files is set by statute, by your regulator, by contract and by your own risk position. Those are legal and records management decisions. What we do is implement and enforce them, tell you what your current configuration actually does, and identify where a decision has not been made.
It is extremely common and it is a good place to start rather than a reason to delay. We can tell you what your current configuration is actually doing, which is usually not what people assume, and set out the questions that need answering. Plenty of organisations discover the practical position first and formalise the schedule afterwards.
Not if it is introduced properly. The usual failure is switching DLP to blocking mode on day one: false positives appear, somebody senior cannot send something urgent, and the policy gets relaxed to nothing within a month. We start in warning mode, tune against real activity, and only move to blocking where it is genuinely warranted. Most sensitive data leaves by accident, and a warning prevents a large share of it.
Fewer than you think. Four labels that people understand and use are worth more than fourteen that get ignored, and a scheme nobody adopts is worse than none because it creates a false impression of control. We would rather start narrow and extend once it is working.
The assessment is short. Designing and piloting a classification scheme for a typical mid-sized organisation runs over a few weeks, and rollout is phased from there. DLP tuning continues for a period after go-live, because false positives can only be assessed against real activity.
Microsoft Purview is Microsoft's data governance, protection and compliance suite. It covers sensitivity labels and information protection, data loss prevention, data lifecycle and records management, insider risk management, communication compliance, eDiscovery and audit. It is licensed in pieces across the Microsoft 365 plans rather than as a single product, which is why most organisations hold an inconsistent slice of it.

FREE DATA PROTECTION REVIEW

Find out what you hold, and where it can go

Whether you're preparing for Microsoft 365 Copilot, working out whether your retention configuration does what you think it does, responding to a regulator or customer, or classifying data for the first time, start by establishing your current position.

  • Microsoft data protection specialists

    Speak directly with consultants who configure classification, DLP and retention every day.

  • Start with what you own

    Most business plans already include labelling, DLP and retention. We confirm what your licences cover before recommending anything new.

  • Proportionate by design

    Fewer labels, warning before blocking, and a scheme your people will actually use.

  1. 1
  2. 2
What is your enquiry about?*