Microsoft Purview – Exploring Sensitive Information Types – 1

Hi All,
Greetings!
We will keep exploring Microsoft Purview. Today we will discuss basics about Sensitive Information Types.
In this first article of Sensitive Information Types we will explore the concept of Sensitive Information Types.
What are Sensitive Information Types?
- Sensitive Information Types are predefined patterns or custom configuration to protect the sensitive data / information in our organization.
- What is Sensitive Information?
- Any data / information which is critical to organization
- Example:
- Personal data of Employee
- Financial Records
- Health Information
- What is Sensitive Information?
- SIT uses patterns like
- Regular expressions
- Checksums
- Keywords
- By using the above patterns SIT detects the sensitive information in emails, documents, databases.
- Identifying sensitive information helps organizations to prevent unauthorized access / sharing of the information.
How Sensitive Information types helps or why to use Sensitive Information Types?
- Sensitive Information Types (SITs) helps to identify sensitive data in our organization
- SITs helps to
- Automate data discovery: It helps to detect sensitive data at various locations including Emails, Documents, Files, Cloud Services.
- Prevent data loss: Based on SIT we could use DLP policies to stop oversharing or unauthorized sharing of data
- Fulfill Compliance requirement: SIT helps to identify and securing sensitive information, ensures that critical data is protected according to policies
- Minimize Risk: Accurately detecting sensitive information helps organizations reduce the risk of breaches, fines, and damage to their reputation.
Types of Sensitive Information
- Built-In Sensitive Information Types
- Custom Sensitive Information Types
Built-in SITs VS Custom SITs
| Criteria | Built-in SITs | Custom SITs |
|---|---|---|
| Ease of use | Preconfigured by Microsoft and ready to use | Requires manual setup and configuration |
| Maintenance | Managed and updated by Microsoft | Must be managed and updated by the organization |
| Scope of coverage | Covers common data types (financial, healthcare, etc.) | Can cover organization-specific data (employee IDs, project codes) |
| Accuracy | High, but might result in some false positives | Can be precise using exact data match or document fingerprinting |
| Customization | Limited to built-in data types | Fully customizable for unique data sets |
| Regulatory compliance | Suitable for standard regulations | Can be customized to meet specific regulatory requirements in specific industries |
| Recommended use cases | General data protection and compliance needs | Protecting proprietary or organization-specific data |
Navigating to built-in SITs
- We have detailed article on navigating to built-in SITs. Please have a look. Microsoft Purview – How to navigate to built-in SITs – https://knowledge-junction.in/2025/09/10/mspurview-navigate-built-in-sits/
REFERENCES
- Microsoft Purview portal. https://purview.microsoft.com/home
- Getting Started with Microsoft Purview – https://knowledge-junction.in/2025/06/28/getting-started-with-microsoft-purview/
- Microsoft Purview: Essential Interview Q&A – https://knowledge-junction.in/purview-essential-interview-preparation/
- How to navigate Microsoft Purview Portal – https://knowledge-junction.in/2023/05/04/mspurview-portal-how-to-navigate/
- How to navigate to built-in SITs – https://knowledge-junction.in/2025/09/10/mspurview-navigate-built-in-sits/
Thank you 🙂 Life is beautiful 🙂
Have a Great Time Ahead 🙂 🙂
