Contoso Pharmaceuticals is implementing Microsoft Purview to meet regulatory compliance (HIPAA and GDPR). They need to: (1) automatically classify and protect patient health information (PHI) and personally identifiable information (PII) in Exchange Online, SharePoint Online, and OneDrive for Business; (2) detect and prevent unauthorized sharing of sensitive data; (3) retain audit logs for 7 years; and (4) allow users to manually apply classification labels to documents. The company has 5,000 users and uses Microsoft 365 E5 licenses. The security team wants to minimize manual effort and ensure consistent protection. What should the compliance administrator configure first?
Auto-labeling provides consistent classification and protection with minimal manual effort.
Why this answer
Sensitivity labels with auto-labeling policies can automatically classify and protect PHI and PII across Exchange Online, SharePoint Online, and OneDrive for Business, meeting the requirement for automated classification and consistent protection. Option A is wrong because DLP policies detect and prevent unauthorized sharing but do not classify or label data. Option C is wrong because retention policies only manage data retention, not classification or protection.
Option D is wrong because auditing logs activities but does not classify or protect content.