Purview Solution Baseline
The Purview Solution Baseline allows MSPs to configure and monitor Microsoft Purview tenant settings at scale across managed customer accounts. It is based on the Microsoft 365 Business Premium license and is compatible with any license that includes an Exchange Online service plan, including Microsoft 365 E3/E5 and Office 365 E3/E5.
The baseline is organized into the following areas: Prerequisites, Audit, Endpoint DLP, Information Protection, and Record Management. Each action within the baseline supports one or more action modes that control how the baseline is applied.
Action modes
Each action in the Purview Solution Baseline supports one or more of the following modes:
| Mode | Description |
|---|---|
| Enforce | The action is applied and enforced on the tenant. The configured setting is written to the tenant. |
| Report Only | The action is monitored for drift but not enforced. The current state of the setting is reported without making changes. |
| Exclude | The action is not monitored or enforced. The setting is skipped entirely. |
Prerequisites
License validation
Before applying the Purview Solution Baseline, Nerdio Manager verifies that the tenant has a compatible license. A license that includes the Exchange Online service plan is required, such as Microsoft 365 Business Premium, Microsoft 365 E3/E5, or Office 365 E3/E5.
Supported modes: Report Only, Exclude
To verify license status, navigate to the Microsoft 365 Admin Center, Licenses and confirm that a qualifying license is assigned.
Permissions
The Nerdio Manager app registration (service principal) must be assigned one of the following Entra ID directory roles:
- Compliance Administrator (minimum required)
- Global Administrator
Supported modes: Report Only, Exclude
To verify, navigate to Entra ID, Roles and administrators, locate the assigned role, and confirm the service principal is listed as a member.
Enable Purview Management
This action enables Purview management features within Nerdio Manager and ensures the service principal has the Exchange.ManageAsApp API permission. When enforced, the following changes are applied:
- The Purview Management setting is enabled in the account settings.
- The Exchange.ManageAsApp API permission is granted to the service principal if it has not already been granted.
- Purview-related features and monitoring are enabled within Nerdio Manager.
Supported modes: Report Only, Enforce, Exclude
To verify API permissions, navigate to App Registration, API permissions in the Azure portal and confirm that Exchange.ManageAsApp is listed.
Audit
Enable Audit Logging
This action enables Microsoft Purview audit logging for the tenant. Audit logging records user and administrator activity across Microsoft 365 services, making logs available for search and compliance review.
Supported modes: Report Only, Enforce, Exclude
To verify:
- Navigate to Audit Log Search in the Microsoft Purview portal.
- In Report Only mode: confirm whether audit logging is enabled. If disabled, the page displays a banner prompting you to enable auditing.
- In Enforce mode: confirm the banner is no longer present and that the audit log search functionality is available. Search for recent activity to confirm logs are being collected.
- In Exclude mode: confirm that the audit logging state is unchanged.
Audit Log Data Retention
This action creates a custom audit log retention policy with a configured retention duration. Retention policies control how long audit log records are kept before they are deleted.
Note: The default retention period (180 days for standard licenses, 365 days for premium licenses) is applied as a tenant-wide default and does not appear as a policy in the retention policies list. Custom policies created by this action will appear as separate entries.
Supported modes: Report Only, Enforce, Exclude
To verify:
- Navigate to Audit, Retention Policies in the Microsoft Purview portal.
- In Report Only mode: document any existing custom retention policies and their configured durations.
- In Enforce mode: confirm that a new retention policy appears with the configured duration (for example, 12 months or 10 years) and shows a status of Enabled.
- In Exclude mode: confirm that existing retention policies are unchanged.
Endpoint DLP
Endpoint DLP settings are configured in the DLP Global Settings page in the Microsoft Purview portal. Expand the Endpoint DLP settings section to access the settings described below.
Always Audit File Activity for Devices
This action controls whether file activity on onboarded devices is always audited, regardless of whether a DLP policy is applied to the device.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Always audit file activity for devices toggle in the Endpoint DLP settings section. In Enforce mode, confirm the toggle is set to On.
Advanced Classification Scanning and Protection
This action enables advanced classification scanning, which allows more comprehensive content inspection and protection on endpoint devices.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Advanced classification scanning and protection toggle in the Endpoint DLP settings section. In Enforce mode, confirm the toggle is set to On.
Advanced Classification Bandwidth Limits
This action configures the bandwidth limit used by advanced classification scanning, measured in MB per 24-hour period. A value of 0 indicates no limit (unlimited). This setting is only available when Advanced classification scanning and protection is enabled.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Bandwidth limits setting in the Endpoint DLP settings section. In Enforce mode, confirm the value matches the configured limit, or shows Unlimited if set to 0.
File Path Exclusions (Windows)
This action adds file path exclusions for Windows devices to the Endpoint DLP settings. Paths in the exclusion list are not monitored by Endpoint DLP policies.
Note: This action only supports Exclude mode. Paths are added to the exclusion list and are not removed by this action.
Supported modes: Exclude
To verify, locate the File path exclusions for Windows list in the Endpoint DLP settings section and confirm that the configured paths appear in the list.
File Path Exclusions (Mac)
This action adds file path exclusions for Mac devices to the Endpoint DLP settings. Paths in the exclusion list are not monitored by Endpoint DLP policies.
Note: This action only supports Exclude mode. Paths are added to the exclusion list and are not removed by this action.
Supported modes: Exclude
To verify, locate the File path exclusions for Mac list in the Endpoint DLP settings section and confirm that the configured paths appear in the list.
Unsupported File Extension Exclusions
This action adds file extensions to the unsupported file extension exclusions list. Files with these extensions are not inspected by Endpoint DLP.
Note: This action only supports Exclude mode. Extensions are added to the exclusion list without a leading dot (for example, log not .log) and are not removed by this action.
Supported modes: Exclude
To verify, locate the Unsupported file extension exclusions list in the Endpoint DLP settings section and confirm that the configured extensions appear in the list.
Network Share Coverage
This action controls whether network share activity is included in Endpoint DLP monitoring.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Network share coverage and exclusions toggle in the Endpoint DLP settings section. In Enforce mode, confirm the toggle is set to On.
Network Share Exclusions
This action configures a list of network share paths that are excluded from Endpoint DLP monitoring. This setting is only available when Network share coverage and exclusions is enabled.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the network share path list in the Endpoint DLP settings section. In Enforce mode, confirm the configured exclusion paths appear in the list.
Unallowed Browsers
This action configures the list of browser executables that are blocked from accessing sensitive data on endpoints. By default, only Microsoft Edge is permitted. Other browsers must be explicitly listed here to be restricted.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Browser and domain restrictions to sensitive data list in the Endpoint DLP settings section. In Enforce mode, confirm the configured browser executables (for example, firefox.exe) appear in the list.
Servers (Endpoint DLP)
This action controls whether onboarded servers are included in Endpoint DLP monitoring.
Supported modes: Report Only, Enforce, Exclude
To verify, locate the Endpoint DLP support for onboarded servers toggle in the Endpoint DLP settings section. In Enforce mode, confirm the toggle is set to On.
Information Protection
Enable Sensitivity Labels (OneDrive and SharePoint)
This action enables sensitivity labels for files stored in OneDrive and SharePoint. Enabling this setting is a prerequisite for co-authoring on encrypted files.
Supported modes: Report Only, Enforce, Exclude
To verify:
- Navigate to Purview, Information Protection Settings.
- Go to the Co-authoring for files with sensitivity labels section.
- Review the Prerequisites note, which states: "Sensitivity labels must be enabled for files in OneDrive and SharePoint." A secondary note indicates when this was turned on and confirms the setting was also enabled at that time.
- In Enforce mode: confirm that the prerequisites note confirms sensitivity labels for OneDrive and SharePoint are enabled.
Co-authoring for Encrypted Files
This action enables co-authoring support for files encrypted with sensitivity labels. When enabled, multiple users can simultaneously edit encrypted Office files stored in SharePoint or OneDrive.
Supported modes: Report Only, Enforce, Exclude
To verify:
- Navigate to Purview, Information Protection Settings.
- Locate the Turn on co-authoring for files with sensitivity labels toggle.
- In Enforce mode: confirm the toggle is set to On.
Record Management
OneDrive Deletion (Labeled Items)
This action reports on whether automatic deletion of old versions is enabled for OneDrive sites. This setting is managed in the SharePoint Admin Center and controls whether version history items are automatically removed.
Note:Enforce mode is not supported for this action. The baseline can report on the current state but cannot apply changes.
Supported modes: Report Only, Exclude
To verify:
- Navigate to SharePoint Admin Center, Settings.
- Scroll to the Site version history section.
- In Report Only mode: document the current state of Enable automatic deletion of versions for OneDrive and note any configured version limits.
- In Exclude mode: confirm the setting is unchanged.
SharePoint Deletion (Labeled Items)
This action reports on whether automatic deletion of old versions is enabled for SharePoint sites. This setting is managed in the SharePoint Admin Center and controls whether version history items are automatically removed.
Note:Enforce mode is not supported for this action. The baseline can report on the current state but cannot apply changes.
Supported modes: Report Only, Exclude
To verify:
- Navigate to SharePoint Admin Center, Settings.
- Scroll to the Site version history section.
- In Report Only mode: document the current state of Enable automatic deletion of versions for SharePoint and note any configured version limits.
- In Exclude mode: confirm the setting is unchanged.
Quick reference
| Portal | URL |
|---|---|
| Microsoft Purview portal | https://purview.microsoft.com/ |
| DLP Global Settings | https://purview.microsoft.com/datalossprevention?viewid=globalsettings |
| Audit Log Search | https://purview.microsoft.com/audit/auditsearch |
| Audit Retention Policies | https://purview.microsoft.com/audit/auditpolicies |
| Information Protection Settings | https://purview.microsoft.com/settings/application-settings/informationprotection |
| Record Management | https://purview.microsoft.com/recordsmanagement |
| SharePoint Admin Center, Settings | https://admin.microsoft.com/sharepoint?page=settings&modern=true |
| Microsoft 365 Admin Center, Licenses | https://admin.microsoft.com/Adminportal/Home#/licenses |
Comments (0 comments)