Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
vinayaklatthe avatar

Purview Information Governance

  • 56 installs
  • 165 repo stars
  • Updated June 18, 2026
  • vinayaklatthe/microsoft-security-skills

Helps with ai & agent building tasks.

About

purview-information-governance is a Claude Code skill in the AI & Agent Building category.

  • purview-information-governance
  • AI & Agent Building
  • AI-coding skill

Purview Information Governance by the numbers

  • 56 all-time installs (skills.sh)
  • +1 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #6,750 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/vinayaklatthe/microsoft-security-skills --skill purview-information-governance

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs56
repo stars165
Last updatedJune 18, 2026
Repositoryvinayaklatthe/microsoft-security-skills

What it does

Helps with ai & agent building tasks.

Files

SKILL.mdMarkdownGitHub ↗

Microsoft Purview Information Governance (Strategy)

Information governance ties Purview classification, protection, lifecycle, and insider risk into one coherent program so sensitive data is known, protected, governed, and defensibly retained - anchored to the Zero Trust Data pillar. This skill is about sequencing, not feature deep-dives.

When to use

Planning a multi-workstream Purview rollout, building a maturity roadmap, or rationalising an in-flight deployment that is delivering features in isolation rather than outcomes.

Do not use this skill for individual feature configuration - jump to the specific Purview skill (labels, DLP, lifecycle, IRM, DSPM for AI) once the sequencing question is settled.

Pick the right entry point for the program

Current stateStart here
No classification, no labelsPhase 1: Know - SITs + sensitivity label taxonomy in audit mode
Labels exist but adoption is lowPhase 1.5: auto-labelling in simulation + user training
Labels adopted, no DLPPhase 2: Protect - DLP per workload in simulation, then enforce
DLP live, no retentionPhase 3: Govern - retention policies + records (file plan)
All of the above, Copilot rolling outPhase 4: Manage AI risk - DSPM for AI + oversharing remediation
All above + insider concernsPhase 5: IRM + Adaptive Protection

Rule of thumb: each phase requires the previous one to be at "audit/simulation works" maturity. You cannot block what you cannot classify.

Approach

1. Know your data - Deploy classification: SITs, trainable classifiers, EDM, and use Content/Activity Explorer to understand what sensitive data exists and where. Verify: Content Explorer shows non-trivial counts for your top SITs across SharePoint/OneDrive/Exchange. 2. Protect your data - Roll out a sensitivity label taxonomy with marking/encryption, then layer DLP to prevent exfiltration of labelled/SIT content. Verify: top-tier label adoption visible; DLP audit-mode policies producing real (not noise) matches. 3. Govern your data - Apply retention and records policies for defensible retain/delete; prefer adaptive scopes so policies stay current. Verify: retention policies show coverage stats per workload; disposition review running. 4. Manage risk - Add Insider Risk Management and Communication Compliance for people-centric risk; add DSPM for AI as Copilot/genAI adoption grows. Verify: IRM alerts being triaged; DSPM for AI recommendations being actioned. 5. Operate as a program - Establish stewardship per business unit, monthly review cadences, and a metrics dashboard (coverage, label adoption, DLP incident trends, time-to-disposition). Verify: a named exec owner reviews metrics quarterly and approves the next-phase scope.

Guardrails

  • Don't start with enforcement - classification maturity must precede DLP blocking and

auto-labelling; otherwise you will tune false positives in production.

  • Govern by data sensitivity and regulation, not by what's licensed - inventory regulatory

obligations first (GDPR, HIPAA, PCI, sector rules) and map controls back.

  • Treat it as a program with owners and change management, not a one-off configuration - feature

toggles without business sponsorship will stall at pilot.

  • Pair every label/DLP rollout with user-facing communication; silent enforcement breeds

workarounds.

  • Resist scope creep: ship Phase 1 before designing Phase 4. A working Phase 1 unlocks everything.

Common anti-patterns

  • Buying E5, enabling everything, and calling that a "strategy".
  • Building a 9-tier label taxonomy nobody can apply correctly.
  • Deploying DLP in block mode on day one - generates incidents and political damage.
  • Treating Purview as IT-owned with no business data owners or stewards.
  • Skipping metrics; without coverage data, leadership cannot fund the next phase.

Example prompts

  • Sequence a Microsoft Purview information protection rollout.
  • Design a data protection program for the Zero Trust data pillar.
  • How do I protect and govern data end to end with Purview?
  • Plan an MIP strategy across classify, protect, and govern.
  • What is the right Purview phase to start if we have no labels today?

Microsoft Learn

  • Protect & govern data with Purview: https://learn.microsoft.com/purview/purview
  • Information protection: https://learn.microsoft.com/purview/information-protection
  • MIP deployment guidance: https://learn.microsoft.com/purview/information-protection-solution
  • Zero Trust data pillar: https://learn.microsoft.com/security/zero-trust/deploy/data
  • Data lifecycle management: https://learn.microsoft.com/purview/data-lifecycle-management
  • Insider Risk Management: https://learn.microsoft.com/purview/insider-risk-management

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.