Data Governance and Discovery with Microsoft Purview
Back to Learn
SC-900Chapter 11

Microsoft SC-900 Certification Study

Data Governance and Discovery with Microsoft Purview

Data governance, Data Map, scans, metadata, classification, lineage, quality, Unified Catalog, governance domains, data products, and responsible use

Suggested study time: 60 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation

Microsoft Certified: Security, Compliance, and Identity Fundamentals badge surrounded by cloud, identity, and compliance icons

1. Introduction

From database administration to governed data assets

Data governance did not emerge as an isolated product. Its roots are in data dictionaries, bank administration, record management, and the early quality programs and master data management. With the expansion of the internet, big data, cloud computing, and artificial intelligence, data began to circulate across dozens of platforms, teams, and countries. Knowing only where a file was stored became insufficient: it became necessary to understand the meaning, origin, quality, responsible party, and legitimate conditions of use of each data set.

For the reader, this knowledge transforms an apparently chaotic environment into an understandable system. For society, well-governed data increases the reliability of financial services, health, education, research, and public policies, as well as reducing risks of discrimination, leaks, and decisions based on incorrect information. In an era in which AI models learn from large volumes of data, the quality of the input directly influences confidence in the output.

Throughout this chapter, the abstract idea of "data governance" will be converted into concrete elements: assets, , classifications, owners, , data products, governance domains, and quality rules. The guiding question for the reader is simple: how does a person find the right data, understand its history, and know if they can use it safely?

Central idea

Invisible data, without an owner and without context, is not a reliable . Governance creates visibility, accountability, and usage criteria.

2. What is data governance

Data governance is the system of decisions, responsibilities, policies, standards, and controls that guides how data is created, described, protected, shared, used, maintained, and disposed of. It defines who decides, who executes, how quality is measured, what uses are acceptable, and how conflicts are resolved.

Good governance does not try to centralize all decisions in a single team. The modern model usually combines corporate standards with distributed responsibility across business domains. This federated approach allows Finance, Customers, Risk, or Human Resources to maintain context and ownership of their data, while a central office establishes common principles, roles, and metrics.

ConceptMain questionExample
Data governanceWho decides and according to which rules?Define owner, steward, access policy, and quality criteria.
Data managementHow is data operated during the life cycle?Modeling, integration, backup, storage, and archiving.
Data securityHow to prevent unauthorized access, alteration, or loss?Encryption, RBAC, DLP, monitoring, and response.
ComplianceWhich legal, regulatory, and contractual obligations need to be met?LGPD, retention, audit and evidence.
Data catalogHow to locate and understand assets and ?Search for tables, reports, owners, descriptions, and .
Do not confuse Governance defines the model of responsibility and decision-making. A catalog tool supports this model, but does not replace people, policies, and processes.

3. Fundamentals of governance

Governance cycle between discovery, cataloging, classification, documentation, and responsible use.
Figure 1 - Cycle that transforms scattered data into reliable and usable information.

3.1 Discovery and cataloging

Discovery is the ability to locate sources and assets in a data estate. Cataloging is the systematic organization of the of these assets so that they can be searched, understood, and governed. A catalog does not need to copy the content of all databases; it gathers descriptions, schemas, classifications, relationships, and accountability information.

3.2 and context

Classifying is associating categories with data based on technical patterns, semantics, or business rules. A column can be classified as an email address, tax identifier, or account number. The business context explains why this data exists, which process produces it, and which policies should accompany it.

3.3 Ownership, quality, and use

Ownership establishes accountability. Quality measures whether the data is suitable for the purpose. Responsible use combines legitimate purpose, minimization, security, transparency, and respect for applicable policies. These elements reinforce each other: without an owner, quality issues remain unresolved; without context, users may interpret the data incorrectly.

Five complementary governance concepts

  • Data access delivers the right access quickly while enforcing appropriate use, balancing protection with innovation.
  • Data curation organizes, annotates, and publishes information so it can be accessed safely, protected, and reused.
  • Data discovery makes relevant information findable for daily operations, analytics, and innovation.
  • maintains quality standards and an active lifecycle so information remains current, reliable, and protected.
  • Data understanding supplies dependable descriptors that explain what information means and how it should be used.

4. Roles and responsibilities

Governance roles connecting Data Governance Lead, data owner, data steward, data custodian, and data consumer.
Figure 2 - Complementary roles in a data governance program.

The is usually a business authority responsible for the value, risk, quality, and access rules of a domain or product. The translates decisions into daily practice: maintains definitions, resolves inconsistencies, monitors quality, and helps users interpret the assets. The data custodian operates the technical controls of the platform, but should not decide alone the business purpose of the data.

Consumers also have responsibility. Finding a dataset in the catalog does not mean that all use is authorized. The user must respect the purpose, terms, , privacy requirements, and access conditions. The central data office coordinates the model, sets standards, and measures maturity without taking away the specialized knowledge from the domains.

PaperTypical responsibilityRisk if absent
Data OfficeStandards, operational model, metrics, and coordination.Fragmented governance and incompatible criteria.
Decision about value, risk, quality, and access.Assets without accountability or priority.
Curation, glossary, quality, and consistency.Outdated catalog and ambiguous concepts.
CustodianTechnical operation, availability, and protection.Operational failures, excessive access, or data loss.
ConsumerUse according to purpose and terms.Incorrect interpretation or misuse.

Benefits for each governance audience

  • Consumers gain easier discovery, secure access, and enough context to interpret information correctly.
  • Owners and stewards gain curation, quality management, responsible-use controls, and impact analysis for anomalies that affect their information.
  • The central data office and executive stakeholders gain value creation, lower operating friction, and common estate-wide controls with federated accountability.

5. : data about data

Technical, business, operational, and social metadata describe the data assets.
Figure 3 - layers that help describe a data .

is information that describes other data. A table name, the type of a column, the owner, the time of an execution, and the relationship between a source and a report are examples. The value of a catalog depends on the richness, timeliness, and consistency of this .

Technical helps engineers understand structures. Business allows analysts to search using their own language. Operational shows processes and executions. Semantic connects assets to classifications, terms, and relationships. The Microsoft Purview brings these dimensions together in a graph.

Active

In the modern model, is not only used for documentation. It can guide search, access, quality, automation, and governance policies.

captured by the map

  • Technical describes schemas, data types, column names, structures, and locations discovered by scanning.
  • Business adds descriptions, glossary terms, owners, and usage context. Some descriptions can be promoted from Microsoft Power BI datasets or SQL tables, while stewards add other context manually.
  • Semantic includes collection mappings and classifications that explain how information is organized and categorized.
  • Operational records processing activity such as run status and execution time, helping users understand flow and freshness.

6. Governance architecture in Microsoft Purview

The current governance experience of Microsoft Purview has two central solutions. The is the technical foundation for capturing, storing, and relating . The is the SaaS experience aimed at consumption, curation, quality, health, and business value.

SolutionMain functionAudience and activities
Microsoft Purview Build the technical map and the graph.Administrators and curators record sources, configure scans, organize domains or collections, and monitor .
Microsoft Purview Transform into a governance and discovery experience for the business.Owners, stewards, and consumers work with domains, products, glossary, quality, health, search, and access.

The two solutions are complementary. Without , the catalog does not have a comprehensive technical view of the assets. Without , the technical inventory may remain difficult to interpret and use for business users. The expected flow is to capture , curate it, add context, and make reliable products available.

Summary for the SC-900

= technical foundation of . = business-oriented discovery, curation, and governance experience.

7. Microsoft Purview

Microsoft Purview Data Map connects sources, scans, ingestion, classification, and lineage.
Figure 4 - Conceptual components of the .

Microsoft Purview captures from analytical, operational, and SaaS systems in Azure, on-premises, hybrid, and multicloud environments. It stores assets and relationships in a graph structure, allowing representation of owners, stewards, hierarchies, classifications, and .

An can be a table, file, database, report, model, or other object recognized by the connector. The map can be enriched automatically through scans and integrations and manually through curation. The capacity is expressed by storage and operation throughput, with elasticity according to consumption.

7.1 Domains and collections in the

In , domains and collections help organize sources, scans, assets, and administrative responsibilities. Collections form hierarchies and can act as access boundaries for . These technical objects should not be confused with governance domains in the , which are context and business ownership boundaries for products and concepts.

inventory, not a copy of business data

Everything stored in is descriptive rather than the underlying business content. Roles and permissions in or govern the experience; they do not, by themselves, grant access to the source data.

The map connects hybrid estates that can span Azure, Amazon Web Services (AWS), Google Cloud, SaaS systems, and on-premises datacenters. A unified view is especially useful after acquisitions, across regions, and when different platforms support different workloads.

8. Recording, scans, and

Flow from source registration to scanning, ingestion, classification, and curation.
Figure 5 - Flow of registration, scanning, , and curation.

8.1 Registering is not scanning

Registering a source informs Microsoft Purview where it exists and in which domain or collection it will be organized. Registration alone does not extract the schema. The connects to the source using a supported authentication method, traverses the configured scope, and captures .

8.2 Levels

The current documentation describes levels. A basic level can capture name, size, and identifier; an intermediate level extracts schemas when available; a more complete level also evaluates samples against rules. The effective level depends on the source and configuration.

8.3

After the , the processes the and loads it into the . It can also receive from connected services, such as integration platforms. A completed does not necessarily mean that all assets are already available in the catalog: the needs to finish.

security

Credentials, integration runtime, connectivity, and permissions must follow the principle of least privilege. Catalog governance does not justify unrestricted access to sources.

9. , cataloging, and curation

Classifications help to recognize patterns in and, depending on the source and level, in sampled values. Examples include email, phone, identifiers, and financial data. They are useful for discovery and prioritization, but need to be assessed in context: a technical match may not, by itself, represent the actual purpose or risk of the .

ElementWhat does it representExample
Technical or semantic category applied to an or column.Email address, card, personal identifier.
DescriptionHuman explanation about content and purpose.Consolidated table of active clients.
Owner or expertContact responsible for the or for its understanding.Customer Data Team.
Standardized business definition.Active customer, net revenue, default.
Sensitivity labelProtection and sensitivity brand integrated into the Purview ecosystem.Confidential - Personal Data.

Curation is the work of improving the meaning and usefulness of . a catalog may have thousands of assets discovered automatically, but it will remain of little use if technical names do not have description, owner, or connection to business concepts. The steward transforms inventory into organizational knowledge.

Trap of evidence

, , and sensitivity label are related, but they are not synonyms.

Automated also helps AI governance by revealing assets that contain personal, financial, or other sensitive information before those assets are selected to train or ground AI models. Built-in patterns cover common types, and organizations can add classifications for their own context.

10. Data

Data lineage tracks origin, processing, storage, and consumption.
Figure 6 - from origin to consumption.

describes how data arises, moves, and is transformed until it reaches its destination. It can show relationships at the level and, in compatible integrations, at the column level. can be captured through scans, native pipeline connections, or integration APIs.

10.1 Impact Analysis

Before changing a column in the source, the team can check reports, models, and dependent products. This reduces changes that break downstream consumers. Impact analysis answers 'what will be affected if I change this ?'.

10.2 Root Cause Analysis

When an indicator shows an incorrect value, the team can navigate backward, identify transformations, and locate the origin point of the problem. The root cause answers 'where did this error come from?'.

10.3 Audit and trust

helps to explain the provenance of a number, to demonstrate controls, and to assess whether an AI output or report uses approved sources. It does not replace detailed operational logs, but it connects to provide an understandable view of the data's journey.

11. Ownership and stewardship

Property should not just be a field filled in to increase the completeness of the catalog. An owner needs to have the authority to make decisions about access, correction priority, quality criteria, and lifecycle. A steward needs time, processes, and metrics to keep the reliable.

DecisionOwnerStewardCustodian
Purpose and business valueApproves and responds.Documents and guides.Implements technical support.
Quality criterionDefine acceptable level.Sets up and monitors rules.Operates corrections and pipelines.
AccessApproves policy or criteria.Validate context and terms.Applies technical controls.
Data incidentDecide impact and priority.Investigates and usage.Contains and corrects platform.
ObsolescenceApproves discontinuation.Updates catalog and consumers.Archives or technically removes.

Federated governance distributes these roles by domains, but maintains corporate standards. The goal is not to create bureaucracy, but rather to eliminate the common state in which everyone uses a piece of data, but no one is responsible for its definition or quality.

Accountability

A critical without an owner is an organizational risk, even if it is technically protected.

12.

Quality cycle among definition, evaluation, control, action, and monitoring.
Figure 7 - Cycle of quality definition, evaluation, and improvement.

Quality is the suitability of the data for the declared purpose. A record may be sufficient for sending a communication, but inadequate for regulatory calculation. Therefore, metrics need to be linked to the use and risk of the .

DimensionQuestionExample of rule
CompletenessAre the required fields filled in?Percentage of non-null CPF greater than 99%.
ValidityDo the values follow the format or domain?Valid date of birth and not in the future.
UniquenessAre there undue duplications?A customer identifier per person.
ConsistencyDo related sources agree?Client status is the same in the CRM and in the data warehouse.
AccuracyDoes the value correctly represent reality?Address confirmed by a reliable source.
Current eventsIs the data recent enough?Load completed in the last 24 hours.

In the , quality rules can produce scores at the , product, and levels. Problems and actions provide visibility into what needs to be corrected. The score helps guide improvement, but it does not eliminate the need for human judgment and validation of the process that generates the data.

No-code quality rules and AI assistance

supports no-code and low-code checks through ready-made rules and AI-generated suggestions. Results roll up into scores for assets, data products, and governance domains. AI-enabled curation recommendations can also expose missing and help stewards improve discovery.

13. Microsoft Purview

Unified Catalog connects business governance, data products, glossary terms, discovery, and access.
Figure 8 - Resources that connect business context, discovery, and responsible use.

The Microsoft Purview is the governance and discovery experience built on the inventory. It organizes data by business context, allows grouping assets into products, standardizing vocabulary, tracking quality and health, searching information, and providing access workflows.

The proposal is to serve consumers, owners, and stewards in an integrated experience. Instead of navigating through a flat list of tables, the user can explore a , find a product associated with a purpose, and evaluate its description, owner, terms, assets, , and quality.

Current context

The new experience of the is being rolled out gradually and depends on the enterprise version and regional availability. Features and preview statuses may change.

14. Governance domains

A is a business boundary that organizes ownership, discovery, and application of governance practices. It can represent Finance, Marketing, Customers, a product, a corporate entity, a regulatory obligation, or a project. It functions as a mini catalog oriented to the context of that area.

The domain contains owners and concepts such as data products, glossary terms, OKRs, and critical data elements. The idea is to bring governance closer to the teams that understand the business, without losing corporate standards. This reduces the bottleneck caused by a central team that would need to curate every across the company.

domain/collection
Organizes products and concepts from a business perspective.Organizes sources, scans, assets, and administrative access to .
There are owners and business stewards.It has functions and hierarchical administration limits.
Supports discovery, policies, and product value.Supports technical operation, delegation, and isolation of map resources.
Example: Clients or Credit Risk.Example: Brazil unit, Production environment, or CRM collection.
The essential distinction of the of the is not just a technical folder. It represents responsibility, language, and business value.

15. Data products

A is a logical grouping of assets related to a use case. It can bring together tables, files, reports, models, and documentation needed for a purpose, such as '360 Customer View' or 'Monthly Regulatory Indicators.' The product adds context and reduces the work of searching for each component separately.

Product componentPurpose
Name and descriptionExplain what the product delivers and what problem it exists for.
Business useDefine purpose, audience, and supported decisions.
Owner and contactsProvide accountability and support.
Associated assetsGather necessary sources, tables, files, and reports.
Glossary and CDEsStandardize meaning and highlight critical elements.
Quality and healthDemonstrate confidence and pending actions.
Terms and accessInform conditions of use and facilitate access requests.

A is not necessarily a copy of the data nor a new database. It is a governed and value-oriented packaging, which points to existing assets and provides everything the consumer needs to assess and use these assets responsibly.

x

An is an individual object. A combines assets and context for a reusable purpose.

Each is managed by one , although consumers can discover it while browsing other domains. This model keeps accountability clear without hiding useful products from the broader organization.

16. Glossary, CDEs and objectives

16.1 Glossary terms

Glossary terms create a common vocabulary. They translate technical names, reduce ambiguities, and allow different areas to agree on concepts such as “active customer,” “recognized revenue,” or “critical incident.” In the current experience, terms can be active objects that also carry policies and governance guidelines.

16.2 critical data elements

critical data elements, or CDEs, represent important elements that may appear with different names in different systems. A "Customer ID" concept can relate to the columns CustID, ClientNumber, and CID. This abstraction helps to standardize, apply quality rules, and handle critical data consistently.

16.3 OKRs

Objectives and Key Results connect governance to value. Instead of measuring only the number of cataloged assets, the organization can track objectives such as reducing the time to find reliable data or increasing the quality of products used by AI models.

ObjectQuestion that answers
What does this concept mean for the business?
Which technical fields represent this critical element?
OKRWhat business outcome should governance produce?
What pattern or category was identified in the ?

17. Discovery, search, and access

Data discovery is the ability of a person to locate relevant information without previously knowing the server, database, or technical name of the table. In the , the search can consider name, description, , glossary, critical data elements, owner, and other attributes. Current features also include natural language search, as available.

Finding does not mean automatically accessing. The catalog can expose for discovery while keeping the content protected at the source. Access requests and policies help balance self-service with security, purpose, and right-use. Actual controls continue to depend on the data platforms and the available integrations.

StageConsumer questionUseful information in the catalog
SearchIs there a product for my problem?Name, description, domain, glossary, and use case.
EvaluateCan I trust and interpret correctly?Owner, quality, , timeliness, and terms.
Request accessWho approves and what conditions apply?Policy, purpose, contact, and request flow.
ConsumeHow to use without breaking rules?Terms of use, , and context.
Give feedbackHow to report an error or need?Owner, steward, and support channels.
Principle of least privilege The goal of self-service is not to remove controls, but to reduce friction for approved and traceable uses.

Search, browse, and AI-assisted discovery

Search is appropriate when a consumer knows what to look for. Browse supports exploration by collection or by the hierarchy of a cataloged source. The AI-powered copilot accepts everyday language, so users can describe the information they need without knowing an exact name or .

18. Heritage health and responsible use

expands the view beyond a single quality rule. Health controls measure governance practices, scores show progress, and actions indicate necessary corrections. A healthy has understandable assets, defined owners, complete products, executed rules, proper access, and updated .

Responsible use means using data for a legitimate, proportional, and transparent purpose. It includes respecting privacy, avoiding excessive collection, assessing biases, maintaining security, documenting limitations, and not reusing data outside the approved context. In the AI era, governance is part of the model's own security: incorrect data, without consent or provenance, can produce harmful results.

Sign of healthGovernance question
Owner definedIs there someone responsible for decisions and corrections?
Description and glossaryDoes a user understand meaning and purpose?
Available Is it possible to explain origin and dependencies?
Measured qualityAre there rules and outcomes appropriate for the use?
Governed accessDoes the consumption occur by authorized people and purposes?
Followed actionsDo problems have a person in charge, priority, and deadline?
AI Governance A sophisticated model does not make up for data without quality, context, permission, or representativeness.

Health controls and corrective actions

Health controls measure whether governance practices improve accuracy, consistency, security, regulatory alignment, availability, and operational efficiency. Health actions translate failed checks into concrete work. Completing those actions raises the governance health score and makes the catalog more useful and discoverable.

19. Integrated practical scenario

Integrated scenario governs the Customer 360 data product from discovery to consumption.
Figure 9 - Governance flow of the 360 Customer Vision product.

A financial institution keeps customer data in the CRM, transactions in Azure SQL, histories in the data lake, and reports in Power BI. Analysts spend days searching for sources and do not know which table is official. The first step is to register and the sources in the . The scans capture schemas, classifications, and assets; pipeline integrations enrich the .

In the , the organization creates the "Clients", assigns an owner and stewards, and defines terms such as Active Client and Client Identifier. Relevant assets are grouped in the "360° Client View". Completeness, uniqueness, and timeliness rules generate scores. The description informs purpose and limitations; the access policy requires justification and approval.

A data scientist searches for customer data in business language, finds the product, examines quality and , and requests access for a retention model. The owner evaluates the purpose, access is granted according to policy, and consumption is associated with a governed set. The gain is not just technological: the organization reduces rework, improves traceability, and makes responsibility for the data explicit.

20. Implementation and best practices

  • Start with use cases and priority domains, not with an attempt to catalog everything without purpose.
  • Define owners and stewards before requiring mass completion.
  • Automate discovery and , but maintain human curation for context and quality.
  • Associate quality rules with the purpose and risk of each product.
  • Integrate cataloging into pipelines, architecture, security, privacy, and change processes.
  • Measure business results, such as discovery time, reuse, incident reduction, and trust.
  • Review , products, and policies to avoid a catalog that is technically complete but outdated.

20.1 Frequent errors

ErrorConsequenceCorrection
Catalog without use caseLarge volume of assets without consumers.Prioritize products and discovery journeys.
Confuse owner with administratorBusiness decisions remain with those who only operate the platform.Separate accountability from technical custody.
Treat quality as a unique projectScores degrade after the initial delivery.Create continuous monitoring and actions.
Expose without governanceSensitive information or critical relationships become excessively visible.Apply roles, domains, collections, and least privilege.
Ignore Changes break reports and causes remain hidden.Integrate pipelines and review dependencies.
Use glossary without adoptionTerms exist, but they do not change the language of business.Involve specialists and apply terms to products.

21. Important comparisons for the SC-900

ConceptsEssential difference
vs captures and relates ; offers business-oriented discovery and governance.
x collection organizes business context and responsibility; collection organizes and administrative access in the .
x An is an individual object; a combines assets for a purpose.
x identifies category; defines business meaning.
x audit log represents the flow and transformation of data; audit log records activities of users and administrators.
Owner vs. custodianOwner is responsible for value and decisions; custodian operates technical controls.
Quality score x guaranteeScore guides confidence and improvement, but it does not prove that the data is perfect for every use.
Discovery x accessFinding does not automatically grant access to the content.
Technical map memorization -> . Business catalog -> . Grouping by use -> . Organizational context -> . Data history -> .

22. Quick review

TermObjective memorization
Data governanceDecisions, roles, standards, and controls to create value and reduce risk.
Distributed graph.
Captures , schema, and classifications, according to support.
Processes and loads into the .
Information that describes data and its relationships.
Origin, movement, transformation, and destination.
Business-oriented SaaS experience in discovery and governance.
Context limit, property, and governance.
package for a use case.
Standardized vocabulary and business context.
CDELogical representation of a critical element in different systems.
Measurable suitability for the purpose.
Maturity view, controls, and actions of the assets.
Responsible useLegitimate, safe, transparent use and in accordance with purpose.
Final mind map Discover -> . Understand -> , , and . Organize -> governance domains and data products. Trust -> owner, glossary, and quality. Use -> search, access, and responsible use.

23. Conclusion

Data governance connects technology, responsibility, and value. Discovery reveals the assets; cataloging organizes ; identifies categories; ownership establishes accountability; quality measures fitness; explains the journey; and responsible use defines limits for consumption. When these elements are treated separately, gaps remain. When they work as a system, data becomes more reliable and reusable.

The Microsoft Purview provides the technical foundation by capturing and relationships in on-premises, hybrid, and multicloud environments. The uses this foundation to create a business-oriented experience with governance domains, data products, glossaries, search, quality, health, and access. The main distinction for the exam is to understand that the map describes the assets, while the catalog transforms this description into a governance and discovery experience.

In my assessment, the greatest benefit of modern governance is not producing documentation: it is reducing the distance between those who create, those who protect, those who understand, and those who use the data. In a society increasingly dependent on automated decisions, reliable and responsible data ceases to be an operational detail and becomes a condition for sustainable innovation.

End of the SC-900 trail

This chapter concludes the 11 reading chapters currently published in the track. The final review should connect identity, security, compliance, and governance as complementary responsibilities in the Microsoft cloud.

24. Review questions

Question 1: Which statement correctly describes the Microsoft Purview ?

A) It is a repository that replaces all databases. B) It is the foundation that captures and relates of distributed assets. C) It is an exclusive email protection tool. D) It is just an audit dashboard.

Commented answer

Correct answer: B. The maintains a graph of , classifications, relationships, and over the data assets.

Question 2: What is the main purpose of a in the ?

A) Replace the user's identity. B) Group assets and context for a reusable use case. C) Create a mandatory copy of all data. D) Perform virtual machine backups.

Commented answer

Correct answer: B. The brings together assets, purpose, owner, terms, quality, and other information useful for consumption.

Question 3: What does data help to understand?

A) Only those who logged into the portal. B) Origin, movement, transformation, and destination of the data. C) Only the storage price. D) Only retention policies.

Commented answer

Correct answer: B. The supports root cause, impact, audit, and trust in the derived data.

Question 4: Which difference between discovery and access is correct?

A) Finding an always grants access to the content. B) Discovery allows you to locate and understand ; access remains subject to policies and permissions. C) Access exists only for administrators. D) Search overrides controls at the source.

Commented answer

Correct answer: B. The catalog can make searchable without automatically releasing the underlying data.

Question 5: Which feature adds business context and can carry governance policies?

A) Glossary terms B) Data products C) OKRs D) Scans

Correct answer: A. Glossary terms define business concepts, connect them to products and assets, and can carry policies for management, governance, discovery, and use.

Question 6: Which concept organizes, annotates, and publishes information for safe reuse?

A) B) Data access C) Data curation D) Data

Correct answer: C. Data curation turns discovered assets into understandable, protected, and reusable information.

Question 7: How do and work together?

A) They operate independently. B) scans sources for . C) captures , and uses it for curation and governance. D) Both grant direct source access.

Correct answer: C. The map supplies the inventory; the catalog adds business organization, discovery, quality, health, and access workflows.

25. Essential Glossary

TermMeaning
Individual object described in the catalog, such as a table, file, or report.
Information that describes structure, context, operation, or data relationships.
graph that underpins discovery and governance.
Process of connecting to and capturing from a source.
Processing that populates the with .
Category applied to an or attribute.
Representation of the origin, transformation, and destination of the data.
Experience in discovery, curation, and business-oriented governance.
Organizational limit for product and concept ownership and governance.
Set of assets and context organized for a purpose.
Standardized business term.
Logical representation of critical information in different assets.
Responsible for decisions and accountability regarding data.
Responsible for the daily curation and quality.
Adequacy of the data to the purpose.
View of controls, scores, and governance actions of the assets.

Official references consulted

  • Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals.
  • Microsoft Learn - Data governance with Microsoft Purview.
  • Microsoft Learn - Learn about Microsoft Purview .
  • Microsoft Learn - Scans and in Microsoft Purview ; data sources; scanning best practices.
  • Microsoft Learn - Data in Microsoft Purview and user guidance.
  • Microsoft Learn - Learn about Microsoft Purview .
  • Microsoft Learn - Governance domains, data products, glossary terms, and search in .
  • Microsoft Learn - , scores, health controls, health actions and reports in .
  • Microsoft Learn - Data governance roles and permissions in Microsoft Purview.

Note about update

The Microsoft Purview experience evolves rapidly. The availability of the , preview features, names, licensing, permissions, and integrations may change. For actual deployment, always check the current official documentation.