Back to CyberLabs
Microsoft Purview · Healthcare

Designing and Automating Microsoft Purview Data Protection for a Healthcare Organization

Sensitivity labels, DLP, Compliance Manager, DSPM, DSPM for AI, audit, and PowerShell automation across Microsoft 365

Expert8–12 hrs core · 3–5 hrs advanced automation · 3–5 hrs optional (endpoint + AI)Contoso Health Services38 sectionsSections 1–38 (complete)

All activities are simulated. Use a Microsoft 365 test tenant only — never a production tenant. All names, records, and identifiers are synthetic training data.

Lab Scenario — Contoso Health Services

You have been engaged as the Data Protection lead for Contoso Health Services, a fictional healthcare organization running Microsoft 365. You will design, deploy, test, operate, automate, document, and troubleshoot Microsoft Purview controls that protect sensitive healthcare and privacy information across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, endpoints, and approved generative AI. This is a production-styled, end-to-end implementation lab — not a high-level demo. You will execute every procedure in a Microsoft 365 test tenant and produce audit-ready, reproducible evidence. All people, records, and identifiers are SYNTHETIC. Never run these procedures in a production tenant.

Data handled

Electronic protected health information (ePHI)
Patient account information
Medical record numbers (MRN)
Health insurance information
Employee information
Financial information
Research information
Public communications

Identified risks

  • • Employees email patient information to personal email accounts.
  • • Medical documents are stored in SharePoint without classification.
  • • Users share confidential documents through unrestricted links.
  • • Sensitive files are copied to removable USB devices.
  • • Users paste sensitive healthcare information into generative AI websites.
  • • Highly confidential documents do not have encryption controls.
  • • Administrators cannot consistently report which labels and DLP policies are deployed.
  • • The organization lacks repeatable evidence for HIPAA audits.
  • • Security controls are manually configured and are difficult to reproduce.
  • • Compliance and security teams lack centralized visibility into data risks.

Learning Outcomes

1. Explain the Microsoft Purview data protection architecture.

2. Translate healthcare and privacy requirements into technical controls.

3. Design a sensitivity-label taxonomy.

4. Create and publish sensitivity labels.

5. Configure encryption and access restrictions.

6. Configure headers, footers, and watermarks.

7. Create automatic labeling policies.

8. Configure DLP policies across Microsoft 365 workloads.

9. Configure endpoint DLP controls.

10. Test DLP policy tips, alerts, blocks, and overrides.

11. Review data exposure through Data Explorer, Activity Explorer, alerts, and audit logs.

12. Assess Microsoft Purview DSPM and DSPM for AI findings.

13. Protect sensitive information used with AI and generative AI applications.

14. Use Compliance Manager to evaluate HIPAA-related improvement actions.

15. Use PowerShell to create, verify, report, modify, and remove Purview configurations.

16. Produce audit-ready evidence.

17. Troubleshoot common Purview deployment problems.

18. Develop a phased production deployment strategy.

Tenant options

  • • Microsoft 365 E5 test tenant (preferred)
  • • Microsoft 365 E5 developer or training tenant, when available
  • • Microsoft 365 E3 tenant with the required compliance add-ons
  • • An authorized Microsoft training tenant containing Purview capabilities

Required workloads

  • • Microsoft Entra ID
  • • Exchange Online
  • • SharePoint Online
  • • OneDrive for Business
  • • Microsoft Teams
  • • Microsoft Purview
  • • Microsoft Defender XDR
  • • Microsoft Defender for Endpoint (endpoint exercises)
  • • At least one Windows 11 test device
  • • Microsoft 365 Copilot access (optional)
  • • Access to supported generative AI sites for DSPM for AI testing (optional)

Audiences

  • • Experienced Microsoft 365 administrators
  • • Security engineers
  • • Microsoft Purview engineers
  • • Compliance engineers
  • • Data protection specialists
  • • Cloud security architects
  • • Healthcare security professionals
  • • Students preparing for senior Microsoft Purview roles

Pre-deployment licensing checklist

Not every Purview capability is included in every E3, E5, Business Premium, trial, or developer tenant. Licensing is feature-dependent and subject to change. Always confirm the specific capability's licensing in current Microsoft documentation before you rely on it in the lab.

• Microsoft Purview Information Protection — manual sensitivity labeling — Available on more plans; confirm current requirements.

• Service-side automatic labeling (auto-labeling policies) — E5-tier / Info Protection add-on; verify.

• Data Loss Prevention (Exchange, SharePoint, OneDrive, Teams) — Confirm included workloads by plan.

• Endpoint DLP — M365 E5 / E3 + compliance add-on; device onboarding required.

• Microsoft Defender for Endpoint — Required for endpoint DLP and device exercises.

• Insider Risk Management (where used) — E5-tier; optional in this lab.

• Communication Compliance (where used) — E5-tier; optional in this lab.

• Audit (Standard / Premium) — Standard audit is widely available; Premium audit has extra licensing.

• Compliance Manager — Included with most plans; assessment templates may differ.

• Microsoft 365 Copilot — Separate licensing; optional for AI exercises.

• Data Security Posture Management (DSPM) — Confirm current licensing.

• DSPM for AI — Confirm current licensing; needed for AI exercises.

• Adaptive Protection (if included) — Links Insider Risk + DLP; confirm availability.

Administrative roles (least privilege)

  • • Global Administrator (initial tenant setup only)
  • • Compliance Administrator
  • • Compliance Data Administrator
  • • Security Administrator
  • • Information Protection
  • • Information Protection Admins
  • • Data Loss Prevention
  • • Organization Management (or appropriate Exchange role)
  • • Audit roles
  • • Compliance Manager roles
  • • Microsoft Defender for Endpoint administrator
  • • SharePoint Administrator
  • • Teams Administrator
  • • Exchange Administrator

Test identities (fictional)

  • • Alex Doctor — Physician (alex.doctor@TenantDomain)
  • • Priya Nurse — Nurse (priya.nurse@TenantDomain)
  • • Jordan Billing — Billing employee (jordan.billing@TenantDomain)
  • • Taylor Research — Research employee (taylor.research@TenantDomain)
  • • Morgan Compliance — Compliance analyst (morgan.compliance@TenantDomain)
  • • Casey External — External recipient (casey.external@ExternalDomain)
  • • Purview Administrator — Lab administrator (purview.admin@TenantDomain)

Test groups

CHS-All-Employees
CHS-Clinical-Team
CHS-Billing-Team
CHS-Research-Team
CHS-Compliance-Team
CHS-Purview-Pilot
CHS-Purview-Excluded
CHS-DLP-Test-Users

Sensitivity label taxonomy

Label architecture

LabelPurposeProtection
PublicApproved public informationNo encryption
InternalRoutine internal business informationInternal marking
ConfidentialSensitive business or employee dataInternal-only access
Confidential – ClinicalHealthcare and clinical informationClinical group access
Confidential – BillingBilling and insurance informationBilling group access
Highly ConfidentialHighest-risk organizational dataRestricted encryption
Highly Confidential – Patient DataElectronic protected health informationNamed group encryption, markings, restricted access
Highly Confidential – ResearchSensitive research dataResearch group encryption