Skip to content

Commit 28eca6f

Browse files
Merge pull request #49970 from MicrosoftDocs/NEW-purview-understand-retention
New purview understand retention
2 parents 0b9e721 + 622c3c8 commit 28eca6f

File tree

13 files changed

+325
-2
lines changed

13 files changed

+325
-2
lines changed

learn-pr/paths/purview-implement-retention/index.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ uid: learn.wwl.purview-implement-retention
33
metadata:
44
title: 'Implement and manage retention in Microsoft Purview (SC-401)'
55
description: 'Retention is key to meeting compliance requirements and managing the lifecycle of organizational data. Microsoft Purview enables organizations to apply retention policies and labels that preserve or delete data based on business, legal, or regulatory needs. This learning path aligns with exam SC-401: Microsoft Information Security Administrator.'
6-
ms.date: 03/25/2025
6+
ms.date: 04/11/2025
77
author: wwlpublish
88
ms.author: riswinto
99
ms.topic: learning-path
@@ -25,7 +25,7 @@ products:
2525
subjects:
2626
- security
2727
modules:
28-
- learn-m365.m365-compliance-information-governance
28+
- learn.wwl.purview-understand-retention
2929
- learn.wwl.purview-implement-manage-retention
3030
trophy:
3131
uid: learn.wwl.purview-implement-retention.trophy
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-understand-retention.decide-apply-retention
3+
title: Decide when to apply retention
4+
metadata:
5+
title: Decide when to apply retention
6+
description: "Decide when to apply retention."
7+
ms.date: 04/11/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/decide-apply-retention.md)]
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
Retention helps organizations control how long data is kept and when it can be deleted. However, not all content needs the same retention approach. Understanding when to use retention, what it can and can't do, and how it compares to other tools like data loss prevention (DLP) is key to using it effectively.
2+
3+
## When retention is needed
4+
5+
Retention is useful in many scenarios where data must be preserved for a period of time or removed after it's no longer needed. These needs might be driven by legal, regulatory, operational, or internal business requirements.
6+
7+
For example:
8+
9+
- A company might need to retain employee records for seven years after separation, in case of future audits or legal disputes.
10+
- A finance department might need to retain year-end reports for five years to meet regulatory requirements.
11+
- A project team might want to delete temporary planning documents after one year to reduce data clutter and minimize risk.
12+
13+
Retention can also help prevent accidental or intentional deletion of important information. When a retention rule is in place, content is preserved even if a user tries to delete it.
14+
15+
## Retention vs data loss prevention
16+
17+
Retention and data loss prevention (DLP) both help protect information, but they do so in different ways.
18+
19+
- **DLP** is focused on preventing sensitive information from being shared or exposed. It looks at how users interact with content. Based on the action, it can block or warn about risky behavior such as copying, pasting, uploading, or sending sensitive data.
20+
- **Retention** is focused on controlling how long data is kept. It ensures that content is preserved for a required time and deleted when it's no longer needed.
21+
22+
These tools are often used together. For example, DLP might prevent users from sharing sensitive documents externally, while a retention policy ensures those same documents are preserved for three years to meet internal business requirements.
23+
24+
## Scoping retention to specific users, sites, or content types
25+
26+
Retention doesn't have to apply to everyone or everything in your environment. Microsoft Purview lets you target retention settings to the locations and content that require them.
27+
28+
You can:
29+
30+
- Apply retention to specific mailboxes, OneDrive accounts, or SharePoint sites
31+
- Target content based on sensitivity labels, file types, or custom metadata
32+
- Use adaptive scopes to dynamically target users, groups, or sites based on Microsoft Entra ID attributes
33+
34+
This flexibility makes it possible to apply different retention rules to different teams, regions, or types of content. A policy might apply to all users in the HR department, while another targets project sites tagged with a specific classification.
35+
36+
## What retention doesn't do
37+
38+
Retention is designed to control how long content is kept. It's not a tool for:
39+
40+
- Blocking access to content
41+
- Encrypting or protecting content in transit
42+
- Monitoring or detecting data movement
43+
- Preventing sharing or accidental exposure
44+
45+
Retention doesn't stop users from reading or editing content. It simply ensures the content is preserved or removed based on the configured rules. For other protection needs, retention should be used alongside tools like sensitivity labels, DLP, and encryption.
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
As data moves across Microsoft 365, not all content needs to be treated the same way. Some files need to be preserved for audits or investigations, while others should be deleted once they're no longer useful. Without clear rules, important information might be deleted too early, or sensitive data might remain long after it's needed.
2+
3+
Microsoft Purview retention helps organizations manage content lifespan across mail, files, and messages. It supports operational, regulatory, and security needs by preserving data that matters and removing what doesn't. Knowing when and how to apply retention is key to protecting data and reducing risk.
4+
5+
In this unit, you:
6+
7+
- Identify common scenarios where retention helps protect or manage data
8+
- Compare how retention and data loss prevention support different types of data protection
9+
- Learn how to target retention based on users, locations, or content types
10+
- Recognize what retention does and doesn't control
11+
12+
By the end, you'll understand how to use retention to support data protection and compliance across Microsoft 365.
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
Retention helps organizations define how long content should be kept and when it can be deleted. Not all retention settings work the same way. Microsoft Purview uses two main methods to apply retention: retention labels and retention policies. Each plays a different role in managing data and supporting compliance and security goals.
2+
3+
Understanding how these tools work, and when to use them, helps ensure your organization meets its requirements for protecting and managing data.
4+
5+
## How retention differs from deletion
6+
7+
When you delete content in Microsoft 365, it typically moves to a recycle bin or deleted items folder. Eventually, it might be permanently removed from the service.
8+
9+
Retention works differently. Retention settings preserve content for a defined period, even if a user deletes it. That content remains discoverable to authorized personnel during its retention period and is only permanently deleted based on the rule that was configured.
10+
11+
Retention can also delete content automatically when it's no longer needed. This reduces exposure from old or unnecessary content that might still contain sensitive information.
12+
13+
## What are retention labels?
14+
15+
Retention labels are applied to individual items such as emails, documents, or Teams chats. These labels can be applied manually by users or automatically using retention label policies. Label policies allow you to publish labels so users can apply them, or configure rules that apply labels automatically based on conditions such as sensitive info types or keywords.
16+
17+
Each label defines how long the content should be retained and what happens after that time expires. For example, a label might retain a document for seven years and then delete it. Another label might mark content as a record to prevent changes or early deletion.
18+
19+
Retention labels provide flexibility. They allow you to apply different retention settings based on the type or purpose of the content. A financial report might require a longer retention period than a casual chat conversation. Labels can be configured to support both needs.
20+
21+
## What are retention policies?
22+
23+
Retention policies are used to apply retention settings across a broader location. Instead of labeling individual items, a policy can apply a default retention rule to all content within a location, such as all mailboxes or all SharePoint sites.
24+
25+
Retention policies are helpful when:
26+
27+
- A general rule applies across a location
28+
- All content needs to be covered, even if it's unlabeled
29+
- You want to minimize the need for users to take action
30+
31+
Retention labels and policies can be used together. For example, a policy might apply a general rule to all content in a site, while certain files receive more specific retention settings through labels.
32+
33+
## Key retention settings
34+
35+
When configuring a retention label or policy, you choose what action should be taken and when it should occur. Microsoft Purview supports several configurations:
36+
37+
- **Retain-only**: Keeps content for a defined period. No automatic action is taken when the period ends.
38+
- **Delete-only**: Deletes content after a defined period, without preserving it beforehand.
39+
- **Retain then delete**: Retains content for a set time and deletes it automatically when that time expires.
40+
41+
Retention labels can also **mark content as a record**. When this option is used, the content becomes immutable. Users can't edit, move, or delete the item while the label is applied. This setting is often used for content that must be preserved without modification for legal or regulatory purposes.
42+
43+
Retention can also be scoped dynamically using **adaptive scope**. Adaptive scopes allow you to apply a label or policy to a dynamic set of users, sites, or groups based on Microsoft Entra ID attributes. For example, you might apply a retention label only to users in the legal department or to sites with a specific region tag. The full setup for adaptive scopes is covered in a later unit, but it's helpful to know that this option exists when planning a retention strategy.
44+
45+
## How retention works with classification, labeling, and data loss prevention
46+
47+
Retention doesn't replace classification, sensitivity labels, or data loss prevention. These tools are designed to work together to support a secure and compliant environment.
48+
49+
- **Classification** helps identify content that might need protection or special handling.
50+
- **Sensitivity labels** apply encryption and access restrictions to protect data in use or in transit.
51+
- **Data loss prevention policies** monitor and block the sharing of sensitive information.
52+
53+
Retention helps ensure that content is kept or removed based on defined rules. Together, these tools support data protection throughout the entire content lifecycle, from creation to deletion.
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
In Microsoft 365, it's easy to create and share data. Without the right controls, it's as easy for that data to linger indefinitely or disappear before it should. Whether the goal is to meet regulatory requirements, reduce exposure to stale content, or preserve business records, Microsoft Purview provides retention policies to help manage the lifespan of data in a secure, predictable way.
2+
3+
Retention in Microsoft Purview lets organizations decide how long to keep content and what happens when that time is up. You can retain content to make sure it's available for legal or operational reasons. You can delete content to reduce risk. Or you can do both. Retain it for a defined period, then delete it when it's no longer needed.
4+
5+
## Protecting data through retention
6+
7+
While retention is often used for compliance, it also plays a key role in data security. It protects important information from being deleted, either by accident or on purpose. Once a retention rule is in place, content is preserved even if a user tries to remove it. This is especially important when the content might be subject to audits, investigations, or legal holds.
8+
9+
Retention also helps prevent risk from forgotten or outdated files. Without rules to remove stale content, organizations are left with documents that are no longer in use but still contain sensitive information. These files might sit on SharePoint sites or in OneDrive accounts long after they're needed. If there's no business or legal reason to keep them, removing them helps reduce exposure to future threats.
10+
11+
## Understanding the data lifecycle
12+
13+
Retention is one part of managing the data lifecycle. The data lifecycle refers to how information is handled from the time it's created until the time it's deleted. In Microsoft Purview, lifecycle management includes several steps:
14+
15+
- Classifying content
16+
- Protecting sensitive data
17+
- Applying retention rules
18+
- Disposing of content when it's no longer needed
19+
20+
Retention plays a central role by ensuring that data is kept for as long as needed, and removed when it's no longer necessary.
21+
22+
## Examples of how retention supports security and governance
23+
24+
Retention policies are used to solve common, real-world problems related to data security and compliance:
25+
26+
- A manager deletes a Teams message thread about an ongoing HR investigation. Retention keeps that content preserved until the required time period ends.
27+
- A marketing team stores outdated customer reports in SharePoint. A retention policy deletes those files automatically after three years. This reduces the amount of sensitive data left unmonitored.
28+
- A company is required to keep employee tax forms for seven years. Retention policies ensure that these files are held for the full required duration, even if someone attempts to clean up their mailbox.
29+
30+
These examples show how retention supports both compliance and security goals. It helps control how long data exists and ensures it isn't removed too soon or kept longer than necessary.
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
Not all content needs to be kept forever. Without retention, sensitive or important information might be deleted too soon, or left behind longer than it should be. In this unit, you explored when to use retention and how to apply it effectively.
2+
3+
You learned how to:
4+
5+
- Identify when retention is appropriate for business, legal, or operational needs
6+
- Understand the difference between retention and data loss prevention, and how they work together
7+
- Apply retention selectively by scoping it to specific users, groups, or content
8+
- Recognize the limitations of retention and what it isn't designed to do
9+
10+
Using retention in Microsoft Purview helps organizations protect key data, reduce exposure to unnecessary content, and meet their regulatory obligations, all without relying on manual oversight or inconsistent decisions. When applied strategically, retention supports a more secure and manageable data environment.
11+
12+
## Resources
13+
14+
- [Govern your data with Microsoft Purview](/purview/manage-data-governance?azure-portal=true)
15+
- [Learn about retention policies and retention labels](/purview/retention?azure-portal=true)
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
### YamlMime:Module
2+
uid: learn.wwl.purview-understand-retention
3+
metadata:
4+
title: Understand retention in Microsoft Purview
5+
description: Understand retention in Microsoft Purview
6+
ms.date: 04/11/2025
7+
author: wwlpublish
8+
ms.author: riswinto
9+
ms.topic: module
10+
ai-usage: ai-assisted
11+
ms.service: purview
12+
title: Understand retention in Microsoft Purview
13+
summary: |
14+
Microsoft Purview retention helps organizations manage how long data is kept and when it can be deleted. Learn how to apply retention strategically to meet compliance requirements, reduce risk, and protect important information throughout its lifecycle.
15+
abstract: |
16+
In this unit you learn how to:
17+
- Identify common use cases for applying retention
18+
- Explain how retention supports data protection alongside tools like data loss prevention
19+
- Apply retention settings to specific users, sites, or content types
20+
- Recognize what retention does and doesn't control
21+
prerequisites: |
22+
None
23+
iconUrl: /training/achievements/generic-badge.svg
24+
levels:
25+
- intermediate
26+
roles:
27+
- administrator
28+
- auditor
29+
products:
30+
- m365
31+
- microsoft-purview
32+
subjects:
33+
- data-management
34+
units:
35+
- learn.wwl.purview-understand-retention.introduction
36+
- learn.wwl.purview-understand-retention.retention-overview
37+
- learn.wwl.purview-understand-retention.retention-labels-retention-policies
38+
- learn.wwl.purview-understand-retention.decide-apply-retention
39+
- learn.wwl.purview-understand-retention.knowledge-check
40+
- learn.wwl.purview-understand-retention.summary
41+
badge:
42+
uid: learn.wwl.purview-understand-retention.badge
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-understand-retention.introduction
3+
title: Introduction
4+
metadata:
5+
title: Introduction
6+
description: "Introduction."
7+
ms.date: 04/11/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 1
14+
content: |
15+
[!include[](includes/introduction.md)]
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-understand-retention.knowledge-check
3+
title: Module assessment
4+
metadata:
5+
title: Module assessment
6+
description: "Knowledge check"
7+
ms.date: 04/11/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
quiz:
15+
title: "Check your knowledge"
16+
questions:
17+
- content: "Your organization needs to preserve employee records for a fixed period after separation. Which Microsoft Purview feature is best suited for this task?"
18+
choices:
19+
- content: "Sensitivity labels"
20+
isCorrect: false
21+
explanation: "Incorrect: Sensitivity labels are used to apply protection settings, not manage data retention timelines."
22+
- content: "Data Loss Prevention (DLP) policies"
23+
isCorrect: false
24+
explanation: "Incorrect: DLP policies help prevent data sharing violations but don't control how long content is retained."
25+
- content: "Retention policies"
26+
isCorrect: true
27+
explanation: "Correct: Retention policies allow organizations to preserve data for a required period, such as keeping employee records after separation."
28+
29+
- content: "An organization wants to automatically delete project documents two years after project completion. Which retention setting should they configure?"
30+
choices:
31+
- content: "Retain-only"
32+
isCorrect: false
33+
explanation: "Incorrect: Retain-only keeps content for a period without deleting it afterward."
34+
- content: "Delete-only"
35+
isCorrect: true
36+
explanation: "Correct: Delete-only retention settings automatically remove content after a specified time."
37+
- content: "Retain then delete"
38+
isCorrect: false
39+
explanation: "Incorrect: Retain then delete first preserves content, which might not be necessary in this case."
40+
41+
- content: "What is one way to scope a retention policy to apply only to specific users or locations?"
42+
choices:
43+
- content: "Use adaptive scope based on Microsoft Entra ID attributes"
44+
isCorrect: true
45+
explanation: "Correct: Adaptive scopes let you apply retention to users, groups, or sites based on Microsoft Entra ID attributes."
46+
- content: "Tag files with keywords in SharePoint"
47+
isCorrect: false
48+
explanation: "Incorrect: While metadata can help classify content, adaptive scope is the correct method for targeting policies."
49+
- content: "Apply a DLP rule to the content"
50+
isCorrect: false
51+
explanation: "Incorrect: DLP rules don't control retention settings or policy scope."

0 commit comments

Comments
 (0)