Cloud, Azure & Identity Security
Most organisations protect data at the network edge and stop there. Once a file moves into email, a cloud app, or a personal device, it is effectively unprotected.
Who this is for: Organisations that have never mapped where their sensitive data lives across Microsoft 365 and Azure.
The problem: Perimeter and endpoint controls do nothing once a file leaves the network, by email, cloud app, or personal device.
The outcome: A Microsoft Purview programme covering classification, DLP, insider risk, and posture management in one practice.
The problem
Firewalls and endpoint controls protect the perimeter. They do nothing once a file leaves it. A spreadsheet containing customer data gets emailed to a personal address, uploaded to an unsanctioned cloud app, or copied to a USB drive, and every network control the organisation invested in becomes irrelevant. The data is what needed protecting. The organisation protected the network instead.
This gap gets worse as organisations adopt Microsoft 365 more fully. Data now moves constantly between SharePoint, Teams, Exchange, OneDrive, and third-party apps connected to the tenant. Most organisations have no visibility into where their sensitive data actually lives, who can access it, or where it is going. They discover the answer during a breach investigation or a regulatory audit, not before.
Insider risk compounds the problem. Not every data loss is a malicious external attacker. Departing employees take client lists. Contractors copy source code. Well-meaning staff share confidential files with the wrong distribution list. Most organisations have no programme to detect any of this before the data has already left.
Data classification is where most of these programmes stall before they start. Without a defined taxonomy for what counts as confidential, restricted, or public, DLP policies have nothing consistent to act on, and sensitivity labels get applied inconsistently or not at all. Classification for information security purposes, deciding how sensitive a document is and how it should be handled, is a distinct discipline from labelling data for other purposes such as training machine learning models, and organisations sometimes conflate the two when scoping this work.
Many organisations already pay for the Microsoft 365 licensing tier that includes Purview and are simply not using it. The capability sits switched off inside a licence the organisation already holds, while the organisation continues to treat data protection as an unsolved problem requiring new spend.
What we do
FortressPoint builds Microsoft Purview programmes for enterprises across UK and Nigerian markets. We start by identifying where your sensitive data actually lives across Microsoft 365 and Azure, then design a classification taxonomy for information security that reflects your real data types, not a generic template.
From the taxonomy we build Data Loss Prevention policies that stop data leaving through email, cloud apps, and endpoints, calibrated to block real risk without stopping your team from doing their jobs. We implement Insider Risk Management to detect risky behaviour, data exfiltration attempts, and policy violations before they become incidents. And we deploy Data Security Posture Management across Microsoft 365 and Azure so you have a continuous view of where sensitive data sits and how exposed it is.
This is not a bolt-on to your existing security programme. We integrate it with the identity and endpoint controls we build under Cloud, Azure & Identity Security, so data protection policies and Conditional Access work together rather than as separate, uncoordinated tools.
We roll DLP policies out in stages, starting in audit mode so you can see what the policy would have blocked before it starts blocking anything. This gives your team the chance to tune thresholds and exceptions before a policy goes live, which is the difference between a control that stays on and one that gets disabled after a week of complaints.
Where an organisation already holds a Purview-capable licence, we prioritise configuring what is already paid for before recommending any additional spend. Most engagements start by making better use of existing licensing rather than buying new capability.
Who this is for
What you get
Why FortressPoint
We treat data protection as part of your security architecture, not a standalone compliance exercise. Purview policies are designed to work with the identity and endpoint controls we already build, not as a separate, disconnected layer.
We calibrate DLP and classification policies to your actual data and workflows. Overly aggressive policies get switched off by frustrated users within weeks. We build policies your team can live with, so the controls stay on.
We understand the regulatory weight this capability carries in both markets. Data classification and DLP are core evidence auditors and regulators ask for under ISO 27001, UK GDPR, and NDPA 2023. What we build is designed to hold up under that scrutiny, not just to function day to day.
We build the classification taxonomy around information security, not around unrelated uses of the term such as labelling data for AI training. Getting this scope right at the start avoids a programme that solves the wrong problem.
Common questions
Microsoft Purview is Microsoft’s data governance and protection platform, covering data classification, sensitivity labelling, Data Loss Prevention, Insider Risk Management, and Data Security Posture Management across Microsoft 365 and Azure. It gives you a way to find sensitive data, label it, control how it moves, and monitor risky behaviour around it, all from one platform.
Data Loss Prevention stops specific actions, such as emailing a labelled file outside the organisation, based on policy rules. Insider Risk Management looks at patterns of behaviour, such as a departing employee downloading an unusual volume of files, to flag risk that a single rule-based DLP policy would not catch on its own. Most programmes need both, working together.
DSPM gives you a continuous, organisation-wide view of where your sensitive data lives, who can access it, how exposed it is, and where your policies have gaps. Rather than a one-off assessment, it is an ongoing capability that flags new exposure as your data estate changes.
Some Purview capability is included in most Microsoft 365 licences, and the more advanced features, including Insider Risk Management and DSPM, typically require Microsoft 365 E5 or specific Purview add-on licences. We review your current licensing before recommending any upgrade, since many organisations already hold more capability than they are using.
Data classification for information security assigns a sensitivity level, such as confidential or restricted, to control how a document is handled and protected. That is a different activity from labelling data to train machine learning models, which is a data annotation task unrelated to security. This service covers the security discipline, not the annotation one.
If you cannot say with confidence where your sensitive data lives or what stops it leaving, contact us.