Your company uses Microsoft Purview to manage data governance. You need to create a data classification rule that scans Azure Data Lake Storage for personally identifiable information (PII) such as email addresses. The rule must also apply a sensitivity label automatically. Which approach should you use?
Microsoft Purview provides native scanning that discovers data assets across on-premises and cloud sources, and you can define custom classification rules using regex or keyword patterns to identify PII such as SSNs or credit card numbers. Once the scan classifies content, Purview's auto-labeling automatically applies Microsoft 365 sensitivity labels to the assets based on the custom rule's classifier, enabling consistent data governance and protection. This directly matches the requirement to detect and label PII.
Why this answer
The correct option is B: create a custom scan rule in Microsoft Purview and configure auto-labeling. Microsoft Purview is the data governance service that supports scanning Azure Data Lake Storage with custom classification rules (using regex or dictionaries) to detect PII such as email addresses, and its auto-labeling policies can then apply sensitivity labels automatically to matching content. Option A is wrong because Azure Policy enforces resource configuration and compliance, not content-level PII detection or sensitivity labeling.
Option C is wrong because Power Automate is a workflow automation tool and does not provide Purview's built-in classification scanning for Data Lake Storage. Option D is wrong because Microsoft Defender for Cloud focuses on security posture and threat protection, not data classification or sensitivity labeling.