01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name owners for Exchange, SharePoint, Teams, Entra and compliance configuration.
- Separate global administrators, workload administrators, records roles and service principals.
- Assess Microsoft and connected app roles from current contracts and actual data flows.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Mail, Teams meetings and messages, SharePoint forms, file sharing and directory sync.
- Employee notes, recordings, transcripts, attachments and exported reports.
- Graph API, Power Platform, add-ins and third-party backup or security tools.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Map authoritative repositories and discourage uncontrolled channel or mailbox copies.
- Review recording, transcription, guest access and telemetry choices against named purposes.
- Challenge broad Graph permissions and indefinite team or site creation.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Link collection surfaces to the correct notice and preference workflow.
- Test whether marketing or communications preferences reach connected sending systems.
- Keep employee monitoring or recording assessments separate from access permission.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review privileged roles, PIM where used, guest users, sharing links and service principals.
- Test least privilege at tenant, site, team and file levels.
- Exercise departure, access revocation, mailbox handling and OneDrive transfer.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Map retention labels and policies to workload, record category and trigger.
- Test deletion with recycle bins, holds, inactive mailboxes, backups and external exports.
- Record licence dependencies and policy precedence.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current terms, DPA, location commitments and sub-processor information.
- List Power Platform environments, add-ins, backups and Graph-integrated services.
- Document assistance, exit, deletion and incident commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm audit availability, licensing and retention for needed event types.
- Save samples for privileged changes, sharing, search and export.
- Route detections to an investigation and breach-decision record.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search by verified identifiers across mail, sites, drives, Teams and connected systems.
- 02
Coordinate correction where the same record appears in directories and business repositories.
- 03
Apply documented hold and retention exceptions.
- 04
Re-run search and record residual copies and downstream responses.
10
Bounded configuration
Configuration checklist
Privileged roles and service principals are reviewed at the right scope.
- Admin path
- Verify in the current admin console
- Evidence to save
- Dated role assignment export and decision log.
Policies and labels cover intended workloads with known precedence.
- Admin path
- Verify in the current admin console
- Evidence to save
- Policy export, licence note and test record.
Required events are searchable for the planned period.
- Admin path
- Verify in the current admin console
- Evidence to save
- Audit sample, event coverage and retention note.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Workload and repository map
Privileged role and app-permission review
Guest and sharing sample
Retention coverage matrix
Audit export sample
Account-exit and rights-search exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Purview, audit and identity features depend on subscription and licence.
- Workload retention and deletion behaviours are not identical.
- Third-party backups and exports can remain after tenant-side action.
Questions to resolve
- Which workloads and licences are in use?
- Which service principals have broad Graph access?
- Where do holds override deletion?
- Which system owns a person’s authoritative record?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionMicrosoft, Microsoft 365, Entra and Purview are trademarks of Microsoft Corporation. References are nominative and do not imply endorsement. No affiliation or endorsement is implied.