ASD's Blueprint for Secure Cloud

Microsoft Purview

This section describes the configuration of Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 3 minutes

Automated Configuration Deployment and Assessment

Overview

Some of the Purview configurations can be automatically deployed using Microsoft 365 Desired State Configuration (DSC).

Some of the Purview configurations cannot be assessed automatically with M365DSC Blueprint. Please refer to those configuration pages to conduct a manual assessment.

ConfigurationBlueprint Automation Provided
Purview SettingsNo
Compliance ManagerNo
Data ClassificationNo
AuditNo
Data Loss PreventionYes (DSC)1
Data Lifecycle ManagementYes (DSC)
Information Protection
- LabelsYes (DSC)2
- Label PoliciesYes (DSC)3
- Auto-LabelingNo
Records ManagementNo

1: The Data Loss Prevention policies are created automatically, but the advanced rules must be manually configured. Refer to Data Loss Prevention Policies for configuration guidance.

2: The Protected Label encryption settings must be configured manually. Refer to Protected Label for configuration guidance.

3: The Test and Protected Label Policy must be changed to apply to test and protected user groups respectively. Refer to Test Policy and Protected Policy for configuration guidance.

Desired State Configuration

Before using the below DSC file, please refer to Automated Deployment for instructions.

Desired State Configuration File
Download Purview DSC (.ps1)
Note: download the linked .txt file and rename to .ps1
Configuration Data File:
The Configuration Data File can be found on the Automated Deployment page.
Service Principal permissions

To import the DSC as per the instructions on the Automated Deployment page, the following permissions will need to be added to the Service Principal:

"SCCaseHoldPolicy", "SCDLPCompliancePolicy", "SCLabelPolicy", "SCRetentionCompliancePolicy", "SCRetentionComplianceRule", "SCSensitivityLabel"

Microsoft Purview Settings

This section describes the configuration of Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Compliance Manager

This section describes the configuration of compliance within Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Data classification

This section describes the configuration of data classification within Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Audit

This section describes the configuration of audit within Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Data Loss Prevention

This section describes the configuration of data loss prevention within Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Data lifecycle management

This section describes the configuration of data lifecycle management within Microsoft Purview associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Information Protection

This section describes the configuration of information protection within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Records Management

This section describes the configuration of records management within Microsoft Purview associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra