Lab 3 – Microsoft Purview: Audit, DLP, eDiscovery & Insider Risk
SC-200: Microsoft Security Operations Analyst
Overview
Explored Microsoft Purview compliance capabilities relevant to a security operations analyst role — including audit log search, DLP alert investigation, eDiscovery content search, and insider risk alert triage.
Tasks Completed
- Explored the Microsoft Purview compliance portal and reviewed the Audit solution
- Searched the unified audit log for user and admin activity events
- Reviewed and investigated a Data Loss Prevention policy alert, examined matched content and policy details
- Created and ran a Content Search in Microsoft Purview eDiscovery to locate items across Exchange and SharePoint
- Reviewed eDiscovery search results, exported a report, and examined match statistics
- Navigated to the Insider Risk Management solution and investigated an active insider risk alert
- Reviewed the insider risk alert timeline, user activity sequence, and available triage actions
Environment: Microsoft 365 E5 test tenant.
Source Material
Completed using Lab 3 – Exercise 1: Explore Microsoft Purview Audit from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Investigate a DLP Alert, Search with eDiscovery, and Investigate an Insider Risk Alert. Completed in a personal Microsoft 365 E5 test tenant.
← Back to SC-200 Labs