Privacy and preparation
Using Microsoft Purview to find sensitive data in SharePoint and OneDrive
By SourceX Editorial · Updated
Short answer
Microsoft Purview finds sensitive data in SharePoint and OneDrive by matching files against sensitive information types and showing the results in content explorer, site by site. Use it to map where personal data sits before an export and to record a decision for each location. Purview locates and counts matches; it does not redact them.
Key takeaways
- Content explorer shows which SharePoint sites, OneDrive accounts and folders hold items matching sensitive information types or labels.
- Add custom sensitive information types for your own employee IDs, customer account numbers and project codes before trusting the map.
- Purview results are a location map, not a clean copy; redaction and a sampled human review still follow.
- Export the findings into a site-by-site inventory with an owner and a decision for every location.
- The blind spots are scanned images, unusual file types, names in free text and content added after the last classification.
What Purview tells you before an export#
Microsoft Purview tells you where content matching a sensitive information type sits across SharePoint sites and OneDrive accounts, and roughly how much of it there is. For an IT lead preparing records for licensing, that answers the first scoping question: which libraries can move forward, and which stay behind.
Purview does not produce a cleaned dataset. Its classification, labeling and data loss prevention features are designed to find, mark and control content where it lives, so a file full of customer phone numbers is unchanged after a scan. Redaction is a separate step with separate tools.
Treat the output as evidence for scope decisions. A project site whose only matches are client contact blocks is a reasonable candidate; an HR site with government ID matches in most folders is an exclusion, whatever else it holds.
How sensitive information types decide what counts#
Microsoft Purview sensitive information types are the classifiers that decide whether a file contains something like a bank account, passport or credit card number. Each built-in type pairs a pattern with supporting evidence such as checksums and nearby keywords, and it reports a confidence level for every match.
Built-in types cover the identifiers regulators list. They know nothing about your own record formats, so a technician ID, a customer account number or an internal project code goes unnoticed until you define it. Custom types and exact data match close that gap.
| Classifier | What it matches | Best use before an export | Watch for |
|---|---|---|---|
| Built-in sensitive information types | Standard identifiers such as card, bank account and government ID numbers | A first map of high-risk files across all sites | Order IDs and part numbers producing low-confidence matches |
| Custom sensitive information types | Your own patterns and keyword lists, such as employee IDs or project codes | Finding internal identifiers the built-in types miss | Patterns too loose to separate real IDs from other numbers |
| Exact data match | Values from a table you supply, such as your customer or employee list | Catching known names and account numbers inside documents | Setup effort and keeping the source table current |
| Trainable classifiers | Document categories such as resumes or contracts | Spotting whole document families to exclude | Coverage varies by category, so test on your own files |
| Sensitivity labels | Labels applied by people or auto-labeling policies | Respecting decisions your company already made | Labels reflect past judgment, not current content |
Before you open content explorer#
Content explorer needs the right access, the right licensing and a defined scope before it produces useful results. Microsoft separates the permission to see where matches are from the permission to open the matched content, so check which role groups your tenant uses and who holds them.
Feature availability depends on your Microsoft 365 licensing, so confirm with your administrator or reseller which classifiers and export options you have. Then agree the scope with the privacy lead: name the candidate sites and OneDrive accounts tied to record families you might license, and record which are out of scope from the start.
- Confirm which admins hold list-level access and which named reviewer, if any, may open file contents.
- List candidate sites by record family: project sites, knowledge bases, proposal libraries, support documentation.
- Mark default exclusions such as HR, payroll, legal, finance and executive sites.
- Note OneDrive accounts of departed employees that your retention settings still keep.
- Draft custom sensitive information types for internal ID formats and test them on one sample site first.
Step by step: mapping SharePoint and OneDrive with content explorer#
Purview content explorer is the view that lists locations holding classified content, filtered by sensitive information type, label or trainable classifier. The sequence below turns that view into a scope you can defend later.
Once the first pass is done, work site by site rather than type by type. Microsoft states that files uploaded to Teams channels are stored in the team's SharePoint site and files shared in Teams chats sit in the OneDrive of the person who shared them, so a company that runs on Teams should expect many of its working documents to surface here.
- Open content explorer in the Microsoft Purview portal; its place in the menu differs between the classic and new portal versions.
- Choose a sensitive information type, starting with the highest-risk ones such as government ID and bank account numbers.
- Filter to SharePoint, drill from site to library to folder, and then repeat for OneDrive.
- Note the item count per location and whether matches cluster in one folder or spread across the site.
- Repeat for your custom types and any trainable classifiers you intend to rely on.
- Where policy allows, let the named reviewer open a few matched files to confirm they are real hits.
- Copy or export each location's results into the inventory before moving to the next site.
Turn the results into an inventory#
A Purview inventory is a table with one row per site or OneDrive account, listing the record family it holds, the sensitive information types matched and a decision. Content explorer results can be exported, and Microsoft documents a PowerShell route for pulling content explorer data; check the current documentation for the command and the permissions it needs.
Keep the decision column simple. Three outcomes cover most locations: include after redaction, exclude, or hold for review. Give every row an owner so a named person answers for the call.
| Column | Example entry | Why it matters |
|---|---|---|
| Location | Project site for a regional transit design job | Ties every decision to one specific place |
| Record family | RFIs, submittal reviews, meeting minutes | Links the location to what might be licensed |
| Types matched | Bank account number, custom employee ID | Shows which risks drive the decision |
| Match spread | Clustered in one invoices folder | Clustered matches can be excluded by folder; spread matches need redaction |
| Decision | Include after redaction, without the invoices folder | Becomes the scope for the export |
| Owner and review date | Project principal and the date of review | Shows who approved the call and when |
Where Purview results mislead#
Purview results mislead mostly through what they leave out. Classification depends on readable, indexed text, so scanned drawings, photos of whiteboards and image-only PDFs may show no matches unless optical character recognition is enabled and licensed for those locations.
Names in free text are the bigger gap. A meeting minute noting that a client's site manager was out for surgery contains no listed identifier and will not appear, yet it is exactly the detail a redaction pass and a human sample must catch. Context that points to one person, such as a job title in a small office, is invisible to pattern matching.
Timing matters as well. Content added or changed since the last classification may not appear yet, so a new staging library needs to be classified before an empty result means anything. Password-protected files, large archives and uncommon file types deserve their own check.
Illustrative: a civil engineering firm maps its project sites#
Illustrative: a fictional civil engineering firm keeps one SharePoint site per project, with libraries for RFIs, submittals, meeting minutes and invoices, while engineers keep working drafts in OneDrive. The firm is considering licensing its RFI and submittal review history, and its IT lead runs content explorer before anyone exports a file.
Bank account matches cluster in the invoices libraries, where wire instructions appear on vendor forms. A custom type for employee IDs finds timesheet spreadsheets dropped into project sites. The RFI libraries show few listed identifiers, but the reviewer's sample of meeting minutes turns up client staff names and phone numbers in email signatures.
The firm includes RFI and submittal libraries after a redaction pass for names and contact details, excludes invoices, timesheets and every OneDrive account, and records each decision with an owner. The managing principal approves the scope with the inventory attached.
How SourceX uses a Purview inventory#
SourceX uses a Purview inventory as scoping evidence inside the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. The initial fit check asks only for metadata, such as site types, record families and years of history, so no files or scan results leave the company at that stage.
When a package reaches Preparation, the inventory shows which locations were excluded and why, and redaction and sampling build on it. Those results become part of the privacy record in the SourceX Evidence Packet, alongside provenance, licensing rights, permitted use and release authorization, and the supplier approves the release.
Frequently asked questions
Do files need sensitivity labels before content explorer shows them?
No. Content explorer lists items that match sensitive information types even when nobody has labeled them, and it shows labeled items as a separate view. Labels add your company's own judgment about a file, which is useful context, but an unlabeled site can still be mapped by sensitive information type alone.
Can Purview check a help desk or CRM export stored outside Microsoft 365?
Only if the export sits somewhere Purview covers, such as a restricted SharePoint library, or is reached through Microsoft's scanning option for on-premises file shares. SaaS exports often arrive as large CSV or JSON files, so confirm the file types are readable and consider a dedicated scanning tool for them.
Who should be allowed to see content explorer results?
Keep the group small. Counts and locations are enough for most scoping decisions, so many companies give list-level access to the IT lead and privacy lead and reserve content viewing for one named reviewer. Log who opened which files, because viewing matched content is itself access to personal data.
Is a SharePoint site with no matches safe to export?
No. An empty result means no listed pattern matched in indexed text. Names, health remarks, identifying context and text inside images can still be present. Treat a clean site as a candidate for redaction and a sampled human review, never as a finished release copy.
Should we copy candidate files into a staging site before scanning?
Often yes. A staging library with tight permissions ties the scan to exactly what would be released and leaves live project sites untouched. Let the new library finish classification before relying on its results, and scan again after redaction so the final copy has its own record.
Sources
- Microsoft states that files shared in Teams chats are stored in the OneDrive account of the user who shared them, while files uploaded to channels are stored in the team's SharePoint site. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.