Security
Microsoft Purview & data protection
Before you can control what your AI sees, you have to know what your data is. Valto configures Microsoft Purview: sensitivity labels that determine who can open a document and whether it can leave the organisation, data loss prevention policies that stop sensitive information being shared by accident, and retention and records management that enforce the schedule your organisation has decided on. We start by establishing what your licences already include and where your data actually sits.

TRUSTED BY ORGANISATIONS LIKE YOURS













Know what your data is, and where it is allowed to go
Most organisations can tell you their retention policy in principle and cannot tell you whether it is applied. Sensitive documents sit in general locations, nothing is labelled, sharing links have accumulated for years, and the only real control on what leaves the organisation is that people are careful. That was tolerable while the risk was theoretical. It is less tolerable now that an AI assistant will happily summarise whatever the signed-in user can technically reach, which is usually a great deal more than anyone intended. Valto establishes the position first: where your sensitive information actually sits, what is labelled and what is not, what your existing licences already entitle you to, and where the gap is between the retention position your organisation has decided on and the one currently configured. Most organisations find that decision was never written down. We then configure what is needed and no more. A classification scheme with four labels that people use is worth considerably more than one with fourteen that they ignore, and over-configured DLP is the fastest way to get a policy switched off after a fortnight of blocked emails.
What Purview actually covers, and what you already have
Purview is a set of capabilities rather than one product, and they are licensed in pieces. This is roughly what each one does and where it usually sits. Confirming your actual entitlement is the first thing we do.
Our Purview services
Establish where your sensitive data actually is
We review what information you hold and where it sits, what is currently labelled, how content is being shared internally and externally, what your retention configuration actually does, and what your licences entitle you to. You get a prioritised findings report. Almost every assessment finds sensitive content in general locations and a retention configuration that does not match what anyone believed it was.
Why work with Valto on Purview?
We start with what you are licensed for
Purview is the most licence-gated area of Microsoft 365 and the most common reason organisations do nothing is not knowing what they already have. We establish that first, and in most cases the basics are already covered.
We configure less than you might expect
Four sensitivity labels people use beat fourteen they ignore, and DLP set to block on day one gets switched off by the end of the month. We start narrow, in warning mode, and extend once it is working.
Clear about what is a legal decision and what is a configuration one
We implement the retention and classification decisions your organisation has made, and tell you where one has not been made. We do not set your retention periods, and we will tell you when you need advice we are not qualified to give.
Classification is what makes Copilot safe to deploy
Sensitivity labels and DLP determine what an AI assistant can surface and what can leave the organisation. This work is the prerequisite for most Copilot rollouts, and it improves search and governance whether or not Copilot goes ahead.
Configured with the rest of the estate in mind
Labels are enforced through identity, applied across SharePoint, Teams and endpoints, and interact with device policy. We configure Purview in the context of the estate rather than in isolation.

WHAT WE TYPICALLY FIND
Where data protection turns out to be assumed rather than configured
Very little of what we find is missing licensing. It is capability switched off, policies that protect part of the estate, and decisions nobody ever wrote down.
- No retention schedule written down anywhere, and a configuration that reflects nobody's decision
- Sensitivity labels available in existing licences and never enabled
- A label scheme created once, never adopted, and now ignored
- DLP policies in audit mode indefinitely, generating reports nobody reads
- Sensitive information sitting in general-access locations with no classification
Turn data protection into business value
Data protection is easier to fund when it is clear what changes. These are the outcomes the work is for.
How we deliver Purview projects
From establishing where your sensitive data actually is, through to a classification scheme people use and a retention position that matches what your organisation has decided.
1Assessment
Establish the current position
We review where sensitive information sits, what is labelled, how content is shared, what your retention configuration actually does, and what your licences entitle you to. This is also where we identify whether a retention schedule exists.
2Design
Agree the scheme, not just the settings
We design a sensitivity label scheme and DLP approach around how your people actually work, and confirm with you which decisions are yours to make and which we are implementing. Fewer labels, clearly understood, is the objective.
3Pilot
Test it on real work
We apply the scheme to a defined group and see what happens. Labelling and DLP are felt by users immediately, and the false positives only surface against real activity.
4Rollout
Extend in phases, in warning mode first
We extend across the estate in stages, with DLP warning before it blocks, and communications so people understand what the labels mean and why they exist.
5Review
Tune, extend and evidence
We reduce false positives, extend automatic labelling where it is working, and establish the reporting that lets you evidence the position to whoever asks.
We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how classification, identity, devices and content fit together rather than treating data protection as a set of policies to switch on. Whether you're classifying data for the first time, preparing for Microsoft 365 Copilot, or trying to work out whether your retention configuration does what you think it does, we help organisations get real control of information they already hold.
WHY ORGANISATIONS CHOOSE VALTO


CONNECTED, ACROSS MICROSOFT
A label is only as good as what enforces it
A sensitivity label is a decision. Whether that decision is honoured depends on Entra ID and conditional access controlling who can open the file, Intune controlling which devices it can be opened on, SharePoint and Teams controlling where it lives, and Defender detecting when something tries to move it. Purview classifies; the rest of the estate enforces. Valto brings together expertise across Microsoft 365, Entra ID, Intune, Defender, SharePoint and Microsoft 365 Copilot. That lets our consultants design classification that the rest of your environment can actually act on, and recognise when the answer is a permissions or sharing change rather than another label. The result is one consistent position on what your data is, who can reach it and where it is allowed to go.
The team driving you forward




You may also be interested in
Questions, answered plainly
Practical answers on what your licences include, how classification relates to Copilot, what happens to users when DLP is switched on, and who decides your retention periods.
FREE DATA PROTECTION REVIEW
Find out what you hold, and where it can go
Whether you're preparing for Microsoft 365 Copilot, working out whether your retention configuration does what you think it does, responding to a regulator or customer, or classifying data for the first time, start by establishing your current position.
Microsoft data protection specialists
Speak directly with consultants who configure classification, DLP and retention every day.
Start with what you own
Most business plans already include labelling, DLP and retention. We confirm what your licences cover before recommending anything new.
Proportionate by design
Fewer labels, warning before blocking, and a scheme your people will actually use.


