Compliance, Retention, Auditing, and Investigations
Back to Learn
SC-900Chapter 16

Microsoft SC-900 Certification Study

Compliance, Retention, Auditing, and Investigations

Compliance Manager, Communication Compliance, Information Barriers, retention, Records Management, eDiscovery, and Microsoft Purview Audit

Suggested study time: 48 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge surrounded by cloud, identity, and compliance icons

1. Introduction: from documentary obligation to continuous compliance

For much of corporate history, compliance meant filing documents, filling out checklists, and preparing folders for periodic audits. The digitalization of business has altered this model. Emails, messages, cloud files, meetings, identities, and administrative actions began to generate evidence at a continuous pace, making an approach based solely on manual controls and annual reviews insufficient.

The growth of data protection laws, sectoral rules, internal investigations, and litigation has also increased the need to demonstrate not only that a policy exists, but that it has been implemented, tested, monitored, and documented. In this context, compliance platforms have emerged that are capable of connecting requirements, controls, retention, auditing, and investigation.

For the reader, understanding this ecosystem helps answer practical questions: how long should a document be kept? Who changed a setting? How to preserve evidence when an investigation begins? How to prevent communication between areas with a conflict of interest? How to measure progress in relation to a standard? These decisions protect organizations, citizens, clients, and the very reliability of digital services.

Central idea

Compliance is not a permanent state. It is a continuous process of interpreting requirements, implementing controls, producing evidence, monitoring activities, and correcting deviations.

Flow between regulatory requirement, assessment, controls, improvement actions, and evidence.
Figure 1 - The Compliance Manager organizes requirements, controls, actions, and evidence in a continuous flow.

2. Overview of Microsoft Purview compliance solutions

Microsoft Purview brings together security, compliance, risk, and data governance capabilities. In this chapter, the focus is on solutions that help assess obligations, communications, manage the information lifecycle, preserve evidence, and investigate activities.

SolutionMain questionExpected result
Compliance ManagerWhat requirements and actions need to be met?Assessments, controls, evidence, improvement actions, and risk-based scoring.
Communication ComplianceAre there communications that indicate a breach of conduct or regulatory rule?Alerts, contextual review, and corrective actions.
Information BarriersWhich groups can or cannot communicate and collaborate?Separation between segments due to conflict of interest or confidentiality.
Data Lifecycle ManagementWhat should be kept or eliminated and for how long?Retention policies and labels.
Records ManagementWhich items require formal treatment as records?Immutability, file plan, retention by event, and controlled disposition.
eDiscoveryWhich data should be preserved, searched, reviewed, and exported?Cases, holds, searches, review sets, and evidence packages.
AuditWho did what, when, where, and in which service?Searchable records for investigation, security, and compliance.
Do not confuse Compliance Manager organizes compliance posture. Retention governs the lifecycle. eDiscovery preserves and collects evidence for a case. Audit records activities. The solutions complement each other, but they are not interchangeable.

3. Microsoft Purview Compliance Manager

The Compliance Manager is a solution to assess and manage compliance in cloud and multicloud environments. It offers pre-built assessments for standards and regulations, allows custom assessments, and centralizes tracking of the work needed to reduce data protection risks and demonstrate progress.

The tool does not interpret laws on behalf of the organization nor does it replace legal experts, auditors, or risk managers. Its role is to transform abstract requirements into an operational framework: controls, actions, responsible parties, tests, evidence, notes, and status.

Fundamental elements

  • Regulation or standard: source of requirements, such as a law, certification, norm, or internal policy.
  • Regulatory model: reusable structure that maps requirements to controls and actions.
  • : grouping of controls applicable to a standard and the selected scope.
  • : requirement that defines a technical, organizational, or procedural measure.
  • : recommended activity to implement, test, or document a .
  • Evidence: documentation, capture, report, or other material that supports the conclusion about the action.
  • : risk-based indicator that measures progress in improvement actions.

Shared responsibility

The Compliance Manager differentiates controls managed by Microsoft, controls managed by the customer, and shared controls. This distinction follows the cloud responsibility model.

4. Evaluations, regulatory models, and controls

An is the space in which an organization monitors its position regarding a regulation, standard, or policy. It brings together controls, in-scope services, actions, scoring, and evidence. A company can maintain separate assessments for different regions, business units, or environments, as long as the structure represents the actual scope.

Regulatory models provide a reusable foundation. Some are provided by Microsoft; others can be customized for internal policies or specific requirements. The availability of models depends on licensing. In current scenarios, it is also possible to build custom models from regulatory documents, but all mapping must be reviewed by responsible experts.

Type of controlMain responsibleConceptual example
Managed by MicrosoftMicrosoftOperation and audit of service cloud infrastructure controls.
Managed by the clientClient organizationSet internal policy, configure retention, train users, or review accesses.
SharedMicrosoft and clientMicrosoft protects the platform; the customer configures and governs the use of the service.

The same can appear in several assessments. The Compliance Manager seeks to avoid artificial counting of repeated work, linking actions and controls so that progress is monitored more consistently. Even so, the organization must verify whether an implementation truly satisfies each regulatory context.

Test point

The presence of a in the catalog does not mean it has been implemented. It is necessary to assign responsibility, status, test, gather evidence, and review periodically.

5. Improvement Actions and

Improvement actions are recommended tasks that help implement controls. They can be technical, such as changing a configuration, or non-technical, such as creating a procedure, conducting training, or producing documentation. Each action can have an owner, deadline, notes, evidence, and test status.

When an action offers an automatic test, the Compliance Manager can use signals from connected services to verify if the configuration has been implemented. Automation reduces manual work, but it does not eliminate the need to validate scope, exceptions, and operational effects.

How to interpret the

The adds points for improvement actions considering risk factors and type of action. The score helps prioritize efforts, compare progress, and show areas that need attention. It starts from a data protection baseline and changes as actions are implemented and tested.

Correct interpretationIncorrect interpretation
Progress indicator and risk-based prioritization.Automatic certificate of legal compliance.
View that depends on the scope, actions, and registered evidence.Proof that no requirement was violated.
Management tool to support audits and continuous improvement.Independent auditor substitute or legal opinion.
Score that can change with product, configuration, and requirements.Universal number comparable between companies without context.
Examination trap A high score does not guarantee compliance. It represents progress in completing recommended actions and should be interpreted within the scope of the assessment.

6.

Microsoft Purview helps detect, capture, review, and address communications that may be inappropriate or inconsistent with internal and regulatory requirements. Scenarios include sharing confidential information, offensive language, harassment, threats, conflicts of interest, and communications subject to financial market rules.

Policies can evaluate messages in supported channels, including Exchange, Teams, and other integrated services. Current features may also cover interactions with generative artificial intelligence applications, depending on connectors, licensing, and availability.

Privacy by design

  • Pseudonymization of user names by default in review experiences.
  • Role-based access to separate administration, analysis, and investigation.
  • Reviewers need to be explicitly defined in the policy.
  • Review and remediation actions are audited.
  • Policies must have a legitimate purpose, proportional scope, and documented governance.
Communication Compliance transforms policy, detection, alert, investigation, and remediation into a controlled workflow.
Figure 2 - converts policy matches into a controlled flow of analysis and remediation.

7. Policies and investigations in

A policy defines who is in scope, which channels will be analyzed, what conditions generate a match, and what percentage of the content will be presented for review. Microsoft provides templates for common scenarios, and organizations can create custom policies.

ComponentFunction
Users and groups in scopeThey determine which communications can be evaluated.
ChannelsThey define origins such as email, chat, collaboration, or connected applications.
ConditionsThey can use types of confidential information, classifiers, words, domains, and other signals.
SamplingControls the amount of content presented for review.
ReviewersPeople authorized to analyze alerts and corresponding items.
ActionsNotify, flag, document, remove messages in supported scenarios or escalate to eDiscovery.

Alerts are generated when messages meet the conditions. The reviewer analyzes the context, classifies the item, records notes, and chooses a proportional action. In more serious cases, the content may be escalated to a formal investigation in eDiscovery.

Difference for DLP

DLP controls the use and transfer of sensitive data. analyzes risks present in communications and provides a review flow for conduct or regulatory obligations. A message can trigger both solutions for different reasons.

8.

is a compliance solution that restricts communication and collaboration between groups and users. It is common in organizations subject to conflict of interest rules, segregation of duties, or the need to prevent teams involved in sensitive operations from exchanging information.

The model starts with segments defined by account attributes, such as department, location, role, or team. Next, policies such as block or allow determine which segments can interact. Once configured and activated, the policies are applied to the supported services.

Information Barriers connects segments, policies, and applications to restrict communication and collaboration.
Figure 3 - Segments and policies turn separation requirements into technical constraints on communication and collaboration.
ConceptObjective description
SegmentSet of users or groups defined by organizational attributes.
Blocking policyPrevents communication between specified segments.
Permission PolicyAllows a segment to communicate only with defined segments.
ApplicationProcess that distributes and implements policies in the services.
Organization modeDefine capabilities as support for one or multiple segments per user.
Operational principle Use the fewest number of policies necessary and test the effects. A poorly designed rule can prevent legitimate collaboration, meetings, file sharing, or people discovery.

9. Data Lifecycle Management

Microsoft Purview Data Lifecycle Management provides features to retain necessary content and eliminate content that has lost value. Retention meets regulatory, contractual, historical, and operational obligations; controlled deletion reduces cost, exposure to attacks, and liability associated with data kept without need.

Retention policies are the central mechanism for applying broad rules in workloads such as Exchange, SharePoint, OneDrive, Teams, and other supported services. Retention labels allow more granular decisions at the item level.

Possible results of a retention setup

  • Retain for a period and allow deletion after that period.
  • Retain for a period and automatically delete at the end.
  • Retain indefinitely as long as there is an obligation.
  • Delete content after a period, without requiring a minimum retention.
  • Start the period from creation, modification, labeling, or business event, depending on the feature. When users edit or delete content subject to retention, the service preserves a copy in a protected location. In SharePoint and OneDrive, this may involve the Preservation Library; in Exchange, the Recoverable Items area; in Teams messages and other services, hidden retention locations maintain the necessary evidence.

Retention is not backup

Backup seeks to restore data after failure or loss. Retention applies the obligation to preserve or delete content according to policy. One resource does not automatically replace the other.

10. Retention Policies

A applies the same setting at the level of a container or location. Examples: all messages from certain mailboxes, all documents from certain sites, or all messages from selected channels.

Static and adaptive scopes

Static scopes are defined directly in the policy and change when an administrator alters the selection. Adaptive scopes use attributes and queries to dynamically include or remove users, groups, or sites. This reduces maintenance in organizations with frequent changes, but requires reliable attributes and careful testing.

CharacteristicRetention policy
Application unitContainer or location.
InheritanceContent in the container receives the configuration automatically.
Typical useBroad and uniform rule by workload, group, user, or site.
Application by the userNormally invisible and automatic.
LimitationLower granularity for items with different business values in the same container.

A policy can be configured to retain, delete, or retain and then delete. The exact behavior varies by workload, item type, and when the period starts. In a real deployment, it is essential to validate the specific documentation for Exchange, SharePoint, OneDrive, Teams, and other services.

Example

A policy can retain all mailbox content from a regulated area for seven years. It does not require each user to label each message.

11. Retention labels and label policies

Retention labels apply rules at the level of documents, emails, or other supported items. They allow different content in the same location to have distinct periods, triggers, and outcomes. A contract can be retained by one rule, while a temporary draft on the same site follows another.

Comparison between retention policies by location and retention labels by item.
Figure 4 - Retention policies act broadly by location; labels act with item-level granularity.

Create, publish, and apply

Creating the label defines retention and deletion behavior. Publishing the label through a policy makes it available to selected users and locations. The application can be manual, default for a location, or automatic based on information types, keywords, searchable properties, trainable classifiers, and other supported mechanisms.

ElementPaper
Retention labelContains the rule applied to the item.
Publishing policyMakes labels available for users and locations.
Automatic application policyFinds content that meets conditions and applies the label.
Standard labelApplies a label to new items in a configured location, according to support.
Withholding per eventThe period begins when a business event occurs, such as the termination of a contract.
Do not confuse Sensitivity label classifies and can protect access. Retention label controls the lifecycle and can declare a record. An item can receive both.

12. Records Management

Records Management extends retention for content that must be treated as formal records. A represents evidence of business activity or decision and requires stricter controls on alteration, deletion, traceability, and disposition.

Records Management connects classification, declaration, retention, record controls, and disposition.
Figure 5 - Records Management connects classification, immutability, retention, and controlled disposition.

Main capabilities

  • Declare items as records or regulatory records by retention labels.
  • Organize labels and requirements in a file plan.
  • Apply withholding based on business events.
  • unlocking, editing, moving, or deleting according to the type of .
  • Perform disposition reviews before permanent deletion.
  • Maintain proof of disposition and auditable trail. Regulatory records receive stronger restrictions and should only be used when required. Improper configuration can prevent legitimate deletions or generate excessive retention. Therefore, legal, records managers, security, privacy, and data owners should participate in the taxonomy.

Essential distinction

Every may be held, but not every held item is a . Records Management adds formal classification, immutability , and disposition process.

The same item may be subject to multiple policies, labels, and holds. Microsoft 365 resolves conflicts according to preservation principles: retention tends to prevail over deletion, and the longer period usually wins when multiple settings require preservation. Explicit and granular settings may take precedence in specific scenarios.

For the SC-900, it is more important to understand the logic than to memorize all the rules: the service aims to prevent a deletion setting from destroying content still required by another retention or investigation obligation.

MechanismMain purposeTypical scope
Retention policyContinuous governance of the life cycle.Locations, users, groups, and workloads.
Retention labelGranular governance by value or item type.Document, email, or item.
eDiscovery holdPreserve relevant content for a specific investigation.Sources and consultations of the case.
Exchange Litigation HoldPreserve mailbox content in a legal scenario.Mailbox.
Backup/recoveryRestore content after incident or error.It depends on the service and the continuity strategy.
Be careful when closing cases Closing or deleting an eDiscovery case may release associated holds. Before closing, confirm if any other obligation still requires preservation.

14. Microsoft Purview eDiscovery

Electronic discovery, or eDiscovery, is the process of identifying, preserving, collecting, reviewing, and delivering electronically stored information as evidence in legal, regulatory, security, or internal investigations. The quality of the process depends on a defensible scope, access , proper preservation, and documentation of decisions.

Microsoft Purview eDiscovery searches data in services such as Exchange Online, SharePoint, OneDrive, Teams, Microsoft 365 Groups, and other supported locations. The classic experience of Content Search, eDiscovery Standard, and eDiscovery Premium was retired in August 2025. The current experience is unified in the Microsoft Purview portal, with basic or premium capabilities enabled according to licensing and case configuration.

And the term custodian?

In investigations, a custodian is the person who owns or controls potentially relevant data. In the classic product model, custodians were central objects in the Premium flow. In the current experience, the case is the central unit, and people, groups, and locations are added as data sources. The legal concept remains valid, but technical management has changed.

eDiscovery case centralizes sources, preservation, searches, review sets, and export.
Figure 6 - The current case focuses on sources, preservation, search, review, and export.

15. Cases, permissions, data sources, and holds

A case brings together all the elements related to an investigation: members, roles, searches, data sources, holds, review sets, processes, and exports. Access must follow the principle of least privilege, because the content may include private communications, personal data, intellectual property, and confidential information.

Data sources

Data sources represent people, groups, and locations related to the case. By selecting a user or group, eDiscovery can identify mailboxes, OneDrive, sites, groups, and other associated locations. The investigator refines the selection to reduce unnecessary collection.

Holds

A preserves content to prevent permanent deletion while the investigation is active. It can be broad or based on a query. Preservation occurs in the source services, keeping versions or copies in protected locations. Holds should be reviewed throughout the case to avoid excessive scope or loss of evidence.

StageControl question
Create caseWhich fact, request, or alert justifies the investigation?
Set membersWho can administer, search, review, and export?
Add fontsWhich users, groups, sites, and mailboxes may contain relevant ESI?
Apply holdWhich content should be preserved and for how long?
Audit the caseAre the actions, changes, and exports documented?
Proportional preservation Preserving everything can increase cost and privacy risk; preserving too little can destroy evidence. The scope must be justifiable and reviewed.

16. Searches, review sets, analysis, and export

Searches locate items by keywords, properties, participants, dates, item types, and other conditions. A well-designed query reduces false positives and facilitates a defensible review. Samples and query reports help adjust the scope before collecting large volumes.

Results can be exported directly or added to a when premium features are available. The copies items and metadata to Microsoft-managed storage, isolated by case, offering filters, viewers, tags, near-duplicate detection, email threading, themes, and other analyses.

ComponentUse
SearchIdentify responsive content in the sources.
HoldPreserve relevant data at the source.
Review setGather a processed copy for analysis and marking.
TagClassify items by relevance, privilege, subject, or decision.
AnalyticsReduce volume and group similar or related content.
ExportGenerate a package of items and reports for delivery or external analysis.
ProcessMonitor search, collection, analysis, and export tasks.

Exports must preserve metadata and reports necessary for the chain of custody. The team needs to document who initiated the process, which filters were used, what was included, how the package was transferred, and who received access.

Search is not isolated proof

An item found needs to be interpreted in context. Authenticity, completeness, chronology, legal privilege, and chain of custody continue to be responsibilities of the investigative process.

17. Microsoft Purview Audit

Microsoft Purview Audit offers an integrated solution to search for user and administrator activities across various Microsoft services. The captures thousands of operations, such as access, creation, deletion, sharing, configuration changes, administrative actions, and investigation events.

Audit helps security, IT, compliance, internal risk, and legal teams answer questions such as: who accessed a file? Who changed a policy? When was a message forwarded? Which administrator performed an action? At which IP address or application did the event occur?

Conceptual anatomy of an event

FieldExample of information
ActorUser, administrator, application, or service that performed the action.
ActivityOperation performed, such as access, download, deletion, or modification.
Date and timeRecorded moment, usually in UTC.
ServiceExchange, SharePoint, Entra, Teams, Purview, or another service.
ObjectFile, message, account, policy, site, or affected resource.
ContextIP, client, identifiers, result, and additional properties.

Searches can be filtered by period, users, activities, services, and other attributes. Results can be exported for analysis. Retention and the types of events available vary by license, service, and policy.

Audit and monitoring

Audit records activities for investigation. It does not replace SIEM, real-time alerts, DLP, or preventive controls, although these systems can consume audit events.

18. Audit (Standard) and Audit (Premium)

Audit (Premium) includes the features of Audit (Standard) and expands retention, events, and investigation.
Figure 7 - Audit (Premium) includes the features of Standard and expands retention, events, and investigation.
CapacityAudit (Standard)Audit (Premium)
Unified audit logYesYes
Portal search and exportYesYes
Thousands of searchable eventsYesYes
General standard retention180 days for supported eventsIncludes Standard
Default retention of Entra, Exchange, OneDrive, and SharePointAccording to standard capacityOne year for covered events and licensed users
Custom retention policiesNoYes
Retention of up to ten yearsNoWith additional leave and policy; it is not retroactive
High-value events and insightsLimitedExpanded
Greater API access capacityNoYes

In Premium, custom policies can set retention by service, activity, or user and use priorities. Records prior to the creation of a ten-year policy are not preserved retroactively. For investigations, this reinforces the importance of planning retention before an incident.

Exam trap

Audit (Premium) is not a separate product that replaces Standard; it includes the capabilities of Standard and adds more advanced retention, events, and investigation features.

19. Integrated practical scenario

Consider a financial institution that is preparing an acquisition operation. The investment banking and market analysis teams need to be separated to avoid conflicts of interest. A message in Teams seems to contain project data sent to an unauthorized group. The organization needs to investigate without destroying evidence and without exposing content to unnecessary people.

Integrated scenario connects preventive control, preservation, investigation, and governance.
Figure 8 - Different solutions contribute to prevention, preservation, investigation, and governance.

Step-by-step application

  • restrict communication between the defined segments and reduce new improper exchanges.
  • generates an alert because the message matches the confidential information or conflict of interest policy.
  • The reviewer confirms relevance and escalates the case to eDiscovery.
  • eDiscovery creates the case, defines members, adds users and locations as sources, and applies holds to preserve content.
  • Searches identify messages, files, and meetings; relevant items are added to the for analysis and tagging.
  • Audit reconstructs accesses, shares, changes, and administrative actions.
  • Retention and Records Management maintain mandatory records and allow controlled disposal at the end of the deadlines.
  • Compliance Manager records improvement actions, responsible parties, and evidence generated after the investigation.

Result

The organization reduces immediate risk, preserves the chain of evidence, limits access to the investigation, and turns the conclusions into verifiable improvements.

20. Comparisons and pitfalls of the SC-900

Confused conceptsDifference
compliance score vs certificationScore measures progress in actions; it does not certify compliance.
Communication Compliance vs DLPCommunication Compliance reviews communication and conduct; DLP controls data movement.
Information Barriers vs RBACIB restricts communication between segments; RBAC defines permissions over resources.
Sensitivity vs. retention labelSensitivity protects/classifies; retention governs keeping and excluding.
Retention policy vs labelPolicy acts by location; label acts by item.
Retention vs eDiscovery holdRetention is continuous governance; hold is preservation related to investigation.
eDiscovery vs AuditeDiscovery locates and preserves content; Audit records activities.
Audit (Standard) vs PremiumPremium includes Standard and adds extended retention and investigation.
Classic custodian vs. current sourceCustodian is a person of interest; the current experience centralizes sources and data in the case.
Records Management vs. inactive fileRecords Management applies formal controls, immutability, and audited disposition.

Statements that deserve suspicion

  • “A of 100% ensures legal compliance.”
  • replaces DLP and labels.”
  • "All retained content is automatically a ."
  • “Deleting a file removes the copy protected by retention or .”
  • “Audit (Premium) only changes the interface.”
  • “eDiscovery is just a search for keywords.”
  • “Holds should remain indefinitely, even after the obligation is closed.”

21. Quick review for the SC-900 exam

TermObjective memorization
Compliance ManagerEvaluations, controls, improvement actions, evidence, and score.
compliance scoreRisk-based progress; not a guarantee of compliance.
Communication ComplianceDetects and treats risks in communications.
Information BarriersRestricts communication and collaboration between segments.
Data Lifecycle ManagementRetains what is necessary and eliminates what has lost value.
Retention policyBroad rule applied at the location or container level.
Retention labelGranular rule applied at the item level.
Records ManagementManages records, immutability, file plan, and disposition.
eDiscoveryPreserves, searches, reviews, and exports ESI in cases.
HoldPrevents permanent deletion of relevant content.
Review setSpace for analysis, tagging, and analytics of collected items.
Audit (Standard)Event search and standard retention.
Audit (Premium)Extended retention, policies, events, and advanced investigation.
Final mind map Evaluate = Compliance Manager. Communicate responsibly = Communication Compliance. Separate groups = Information Barriers. Retain and delete = Data Lifecycle. Formalize records = Records Management. Preserve and collect = eDiscovery. Reconstruct actions = Audit.

22. Conclusion

Modern compliance depends on an integrated set of capabilities. The Compliance Manager transforms requirements into assessments, controls, and actions. and reduce communication risks. Data Lifecycle Management and Records Management govern retention and disposition. eDiscovery preserves and organizes evidence. Audit provides the timeline of activities.

The main takeaway is that none of these solutions, on their own, proves compliance. An organization needs to interpret obligations, set scopes, assign responsibilities, test controls, protect the privacy of investigated individuals, maintain evidence, and review policies. Technology makes the process more consistent, but governance and human judgment remain indispensable.

In my , the greatest value of Microsoft Purview lies in connecting activities that previously existed in separate tools and teams. When legal, security, privacy, IT, and business share criteria and evidence, compliance ceases to be a rushed preparation for audits and becomes part of the organization's daily operations.

Next step on the trail

In Chapter 17, the study progresses to data governance and discovery with Microsoft Purview Data Map and Unified Catalog.

23. Review questions

Question 1: Which statement correctly describes the ?

A) It is an automatic legal certification. B) Measures progress in improvement actions based on risk. C) Replaces external audits. D) Measures only the quantity of retained documents.

Commented answer

Correct answer: B. The helps prioritize and track actions, but it does not guarantee absolute compliance.

Question 2: Which feature is most suitable for applying the same retention rule to all

mailboxes of a group?

A) B) Sensitivity label C) D)

Commented answer

Correct answer: A. Retention policies operate at the site or container level and are suitable for broad rules.

Question 3: What is the main purpose of an eDiscovery ?

A) Increase the . B) Block communication between departments. C) Preserve relevant content to prevent deletion during an investigation. D) Encrypt all exported files.

Commented answer

Correct answer: C. The preserves content from case sources while the investigative obligation exists.

Question 4: What capability is characteristic of Audit (Premium) compared to Standard?

A) No event search. B) Extended retention and custom audit retention policies. C) eDiscovery replacement. D) Creation of sensitivity labels.

Commented answer

Correct answer: B. Audit (Premium) includes Standard and adds longer retention, policies, and advanced investigation features.

24. Essential Glossary

TermMeaning
AssessmentGrouping of controls for a standard, regulation, or policy.
compliance scoreRisk-based scoring to track improvement actions.
ControlTechnical, organizational, or procedural measure related to a requirement.
Improvement actionRecommended task to implement or test a control.
Communication ComplianceSolution to detect and address risks in communications.
Information BarriersPolicies that restrict collaboration between segments.
Retention policyRetention rule applied to location or container.
Retention labelRetention rule applied to the item.
RecordFormal content subject to record controls.
Disposition reviewReview before permanent deletion of records.
ESIElectronically stored information used as evidence.
HoldPreservation to prevent deletion during investigation.
Review setSet processed for review, marking, and analysis.
Unified audit logSearchable repository of user and administrator activities.

Official references consulted

  • Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals. Skills measured as of July 28, 2026.
  • Microsoft Learn - Microsoft Purview Compliance Manager; Compliance Manager scoring; Working with improvement actions.
  • Microsoft Learn - Microsoft Purview data compliance solutions.
  • Microsoft Learn - overview, planning, configuration, and investigation.
  • Microsoft Learn - overview and policy configuration.
  • Microsoft Learn - Data Lifecycle Management; retention policies and retention labels.
  • Microsoft Learn - Records Management, file plan and .
  • Microsoft Learn - eDiscovery overview, workflow, cases, data sources, holds, searches, review sets and export.
  • Microsoft Learn - Audit solutions overview; Audit (Standard) and Audit (Premium).

Note about update

The classic eDiscovery experience was retired on August 31, 2025. Features, names, licensing, retention periods, and portals may change. For actual deployment, always check the current documentation and applicable legal obligations.