Your input shapes our product. Suggest a feature now →
  1. Home
  2. Blog
  3. Purview vs Built-in Compliance

Microsoft Purview vs SharePoint Compliance: When to Upgrade

SharePoint Online ships with more compliance capability than most administrators realise. Retention policies, sensitivity labels, basic data loss prevention, and 90-day audit logs are all present before a single Microsoft Purview add-on is purchased. The question of whether Purview is actually necessary deserves an honest answer, because the upgrade carries real administrative overhead and a non-trivial licence cost.

The short version: most organisations with fewer than 300 seats and no specific regulatory obligation are well served by what Microsoft 365 E3 or Business Premium already includes. The long version is more nuanced.

What SharePoint's built-in compliance covers

The Microsoft Purview compliance portal is included with Business Premium, E3, and above. What that means is that the interface for managing retention and sensitivity labels, running content searches, and setting basic DLP policies is available without a separate Purview product licence. What differs between plans is the depth of each capability.

Retention labels and policies

SharePoint administrators can create retention labels that hold documents in place for a defined period, mark them for deletion, or trigger a disposition review before permanent removal. Labels can be applied manually, set as a library default, or triggered by content type. Retention policies can also target entire SharePoint sites, retaining all content within them without per-file labeling.

For most legal hold, contract lifecycle, and records management requirements, this is sufficient. The built-in retention system handles the standard "keep for 7 years, then prompt for review" scenario without advanced Purview.

Data loss prevention at the site level

DLP policies covering SharePoint and OneDrive are available in Business Premium and E3. These policies detect predefined sensitive information types (credit card numbers, national ID formats, health record keywords) and either alert on or block the sharing of documents containing them. The out-of-the-box sensitive info type library covers the most common patterns. Custom sensitive info types can be added using regular expressions or keyword dictionaries.

The limitation is scope. Basic DLP covers SharePoint and OneDrive files. It does not monitor Teams chat messages or Exchange email content from the same policy. Cross-workload DLP is a Purview premium feature.

Sensitivity labels

Manual sensitivity labeling (where users choose a label from a menu in SharePoint or Office apps) is included in E3 and Business Premium. Labels can restrict external sharing at the site level, apply content marking (watermarks, headers), and apply Azure RMS encryption when the label's encryption settings define permitted users. Service-side auto-labelling is the E5 feature - it crawls existing files and applies labels in the background without user action.

What Microsoft Purview adds

Purview extends compliance coverage into workloads and scenarios that SharePoint's built-in features do not reach. The table below maps the most common compliance needs to what each tier actually covers.

Compliance capability Built-in (E3 / Business Premium) Microsoft Purview (E5 or add-on)
Retain documents for 7 years Yes Yes
Block external sharing per library Yes (SharePoint admin center) Yes
Manually apply sensitivity labels to files Yes Yes
Auto-label files based on content (service-side) No Yes (Purview Information Protection P2)
DLP across SharePoint and OneDrive Yes (standard info types) Yes (advanced types, more granular controls)
DLP across Teams messages and Exchange No Yes
Communication compliance (Teams, email monitoring) No Yes (Purview Communication Compliance)
eDiscovery case management and legal hold Limited (standard content search) Yes (Purview eDiscovery Premium)
Insider risk management No Yes (Purview Insider Risk Management)
Audit log retention beyond 180 days No (standard: 90 days; premium: 180 days) Yes (up to 1 year with Audit Standard Premium, 10 years with Audit Premium add-on)
Compliance score dashboard Limited Yes (Compliance Manager)

When should you move to Microsoft Purview?

The upgrade makes sense when the built-in feature set has a specific gap your organisation actually needs to close. Common triggers:

  • Your organisation operates under a regulatory framework that requires cross-workload monitoring (HIPAA, PCI DSS, financial services regulations) and the DLP policies need to cover Teams messages and email as well as files.
  • Legal needs to run eDiscovery cases with custodian management, hold notifications, and review sets, rather than ad-hoc content searches.
  • You need service-side auto-labelling to classify existing content in SharePoint and OneDrive without requiring users to manually label every file.
  • Your audit log retention requirement exceeds 180 days (standard Microsoft 365 audit log retention).
  • You have a security team that needs insider risk signals: data exfiltration patterns, departing employee file downloads, or policy violation sequences across Microsoft 365 services.
  • You are reporting compliance posture to a board or auditor and need a structured scoring framework (Compliance Manager).

If none of those apply, the investment in Purview licences and the additional administrative surface area may not be justified yet. The more common problem in small to mid-sized Microsoft 365 tenants is not a missing compliance product; it is an unreviewed permission structure and years of accumulated sharing links that haven't been audited.

Review shared links and permissions with ShareMaster

The permissions gap that Purview cannot fill

Microsoft Purview classifies and monitors content. It does not change who has access to that content. A DLP policy can detect when someone shares a confidential document externally and block it. But if the document library itself has 40 direct permission grants to contractors who left the organisation two years ago, Purview does not surface that. It is not designed to.

The risk in over-indexing on Purview is the assumption that compliance tooling has replaced the fundamentals. Stale external users, unique permissions scattered across hundreds of document libraries, and thousands of "anyone with the link" sharing links are governance problems, not classification problems. Purview operates above that layer; the layer itself still needs to be maintained.

For SharePoint admins, the practical sequence is: audit and tighten the permission structure first, then layer in classification and monitoring. The guide to fixing broken SharePoint permission inheritance and the Shared Links and Permissions tool are the starting points for that baseline work.

A practical decision checklist

Before committing to the Purview upgrade, run through these questions:

  • Have you reviewed and cleaned up external sharing links and guest accounts in the past 12 months?
  • Do you have documented retention schedules, or are you using retention labels already?
  • Does your current DLP coverage include all workloads where sensitive data actually lives (SharePoint, Teams, email, endpoints)?
  • Do you have a specific regulatory audit, legal hold, or insider risk incident driving the Purview evaluation, or is this a "nice to have" at this stage?

If the first item on that list is not yet done, the compliance investment order is wrong. A well-classified SharePoint environment with stale external access is still a liability. Sort the permissions layer first; the classification layer builds on top of it.

Frequently Asked Questions

Is Microsoft Purview free with Microsoft 365?

The Purview compliance portal is included with Business Premium, E3, and E5 plans. Premium features such as Advanced eDiscovery, Insider Risk Management, and Communication Compliance require E5 or dedicated Purview add-on licences.

Do I need a Purview licence to use sensitivity labels in SharePoint?

Manual labeling is available in Business Premium and E3. Service-side auto-labelling, which crawls existing files and applies labels without user action, requires E5 or Purview Information Protection P2.

What is the difference between retention labels and sensitivity labels in SharePoint?

Retention labels govern how long content is kept and when it is deleted. Sensitivity labels govern who can access content and whether it is encrypted. Both are managed in the Purview compliance portal, but they serve different objectives and can be applied independently.

Can I apply DLP policies to SharePoint without a Purview add-on?

Basic DLP policies covering SharePoint and OneDrive are available in Business Premium and E3. Cross-workload DLP (covering Teams and Exchange simultaneously), advanced sensitive info types, and endpoint DLP require E5 or the Purview Compliance add-on.

Try ShareMaster free for 14 days