M365Clarity · Data Governance

Microsoft 365 data governance checklist — DLP, sensitivity labels, retention, eDiscovery

M365Clarity · 24 June 2026

← All articles

Why data governance matters in Microsoft 365

Microsoft 365 is where most organisations store their most sensitive data — contracts, financial records, personnel files, customer information, strategic plans. The platform provides the tools to protect, classify, retain, and audit that data through Microsoft Purview. The problem is that most of those tools ship unconfigured and require deliberate activation before they do anything.

The result is that data governance in most Microsoft 365 tenants exists on paper — the licences are in place but the policies, labels, and retention rules have never been created. A regulatory inquiry, a legal hold request, or a data loss incident then reveals the gap that was quietly there the whole time.

Data Loss Prevention (DLP)

DLP policies in Microsoft Purview detect and prevent the sharing of sensitive content — credit card numbers, national insurance numbers, health data, confidential documents — across Exchange, SharePoint, OneDrive, Teams, and endpoints.

Key things to check:

Common gap: A DLP policy covering Exchange email exists, but SharePoint document libraries and Teams chats containing the same sensitive information types have no coverage at all.

Sensitivity labels

Sensitivity labels let you classify documents, emails, and meetings according to their confidentiality level — Public, Internal, Confidential, Highly Confidential. Labels can apply encryption, access restrictions, and watermarks automatically when content is classified.

Key things to check:

Retention policies

Retention policies define how long content is kept and when it is deleted. Microsoft 365 content that is not subject to a retention policy follows no structured lifecycle — it can be deleted by users at any time and is gone permanently once removed from the recycle bin.

Key things to check:

Audit logging

Unified audit logging in Microsoft 365 records admin and user activity across Exchange, SharePoint, OneDrive, Teams, Entra ID, and other services. It must be explicitly enabled — it is not on by default in all tenant configurations.

Critical check: Audit logging is not enabled by default in all Microsoft 365 configurations. If it has never been explicitly turned on, you may have months or years of activity with no audit record.

Microsoft 365 E5 or Purview Audit (Premium) extends audit log retention from 90 days to 1 year and adds additional log categories including Copilot AI interaction logs. Without the premium tier, audit logs are deleted after 90 days.

eDiscovery

eDiscovery Standard (included from E3) allows content search across Exchange, SharePoint, and Teams and supports legal holds — preserving content that would otherwise be deleted or modified. eDiscovery Premium (E5) adds custodian management, predictive coding, and case analytics.

Key things to check:

What M365Clarity checks in the Data Governance tab

The Data Governance tab in M365Clarity runs 23 checks across DLP policies, sensitivity label publication, auto-labelling, retention label and policy coverage, eDiscovery case and hold status, audit log activation, audit retention tier, insider risk management policies, and Compliance Manager score. Each finding is rated Red, Amber, or Green with plain-English remediation guidance.

Check your data governance posture in 30 seconds

M365Clarity scans 23 data governance checks across your Microsoft 365 tenant and shows you exactly what is configured, what is missing, and what to fix first.

Free scan — no agents required →

Related articles