Courseiva

Microsoft Purview Sensitivity Labels Auto-Labeling for PHI and PII

Contoso Pharmaceuticals is implementing Microsoft Purview to meet regulatory compliance (HIPAA and GDPR). They need to: (1) automatically classify and protect patient health information (PHI) and personally identifiable information (PII) in Exchange Online, SharePoint Online, and OneDrive for Business; (2) detect and prevent unauthorized sharing of sensitive data; (3) retain audit logs for 7 years; and (4) allow users to manually apply classification labels to documents. The company has 5,000 users and uses Microsoft 365 E5 licenses. The security team wants to minimize manual effort and ensure consistent protection. What should the compliance administrator configure first?

Quick Answer

The correct first step is to create sensitivity labels with auto-labeling policies configured to detect PHI and PII, then publish them via label policies. This approach directly addresses the need for automated classification and protection across Exchange Online, SharePoint Online, and OneDrive for Business because auto-labeling uses built-in sensitive information types to scan content and apply labels without manual intervention, ensuring consistent coverage for HIPAA and GDPR compliance. On the SC-900 exam, this question tests your understanding of how Microsoft Purview’s Information Protection capabilities layer together—specifically that sensitivity labels handle classification and protection, while DLP, retention, and auditing serve separate functions. A common trap is confusing DLP policies (which block sharing but don’t classify) with auto-labeling, or assuming retention policies can replace classification. Remember the memory tip: “Labels first for class and protect; DLP blocks, retention keeps, audit logs.”

⚠ Common exam trap

SC-900 often tests the ordering of Purview components, and candidates frequently pick DLP first because it sounds like the most direct 'prevent sharing' control, missing that labels are the prerequisite classification layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create sensitivity labels with auto-labeling policies configured to detect PHI and PII, and publish them via label policies.

Sensitivity labels with auto-labeling policies are the foundational Purview capability that classifies and protects PHI/PII across Exchange, SharePoint, and OneDrive, and they also enable users to manually apply labels. Auto-labeling uses trainable classifiers and sensitive information types (SITs) to detect content and apply protection (encryption, markings) consistently with minimal manual effort. DLP, retention, and auditing build on top of labels but do not themselves provide the classification-and-protection layer the scenario requires first.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Data Loss Prevention (DLP) policies to block sharing of content containing PHI and PII.

    Why it's wrong here

    DLP blocks sharing based on sensitive information types, but it cannot apply the classification labels users must select manually, nor does it retain audit logs for seven years. DLP would be correct once labels and sensitive information types already exist to detect.

  • ✓

    Create sensitivity labels with auto-labeling policies configured to detect PHI and PII, and publish them via label policies.

    Why this is correct

    Sensitivity labels with auto-labelling policies satisfy the automated classification and protection requirement across Exchange Online, SharePoint Online and OneDrive for Business, detecting PHI and PII at scale. Publishing via label policies makes labels available for manual application, meeting the user-driven labelling requirement with minimal manual effort.

  • ✗

    Set up retention policies for Exchange, SharePoint, and OneDrive to retain data for 7 years.

    Why it's wrong here

    Retention policies preserve content for seven years but perform no automatic classification, no sharing prevention and no manual labelling, leaving three requirements unmet. Retention would be the correct first step if the only obligation were keeping records for a defined period.

  • ✗

    Enable auditing for all workloads and configure alert policies for unauthorized access.

    Why it's wrong here

    Auditing and alert policies only record and notify on activity; they neither classify PHI/PII nor prevent sharing, so requirements one, two and four remain unmet. Auditing would be the right starting point when the sole goal is visibility into user and admin activity.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. You are reviewing a Microsoft Purview DLP policy configuration for a compliance team. What is the effect of this policy?

medium
  • ✓ A.The policy blocks access but allows users to override with a justification
  • B.The policy automatically applies encryption to the content
  • C.The policy sends a notification but does not block access
  • D.The policy automatically blocks access without user override

Why A: The policy includes a BlockAccess action with behavior set to BlockWithOverride, meaning the action is blocked by default but the user can override with a business justification. Additionally, the NotifyUser action sends a custom notification to the user. This matches Option A. Option B is incorrect because there is no encryption action configured. Option C is incorrect because the policy does block access (with override), not just send a notification. Option D is incorrect because the policy allows user override, so it does not automatically block without override.

Variation 2. A compliance officer needs to create a policy that prevents users from sharing files containing medical record numbers (MRN) via email. Which Microsoft Purview solution should they use?

easy
  • A.Sensitivity labels
  • ✓ B.Data Loss Prevention (DLP)
  • C.eDiscovery
  • D.Insider risk management

Why B: Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and block the sharing of sensitive information, such as medical record numbers (MRN), via email. DLP policies can inspect email content and attachments for patterns (e.g., regex for MRNs) and automatically enforce actions like blocking the message or notifying the user, preventing data exfiltration.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.