Microsoft Purview portal Retention policies eDiscovery Audit log Capstone assessment
Day 1
Retention policies
Day 2
eDiscovery
Day 3
Audit log + Insider risk
Day 4
Sensitivity labels deep-dive
Day 5
Capstone assessment

Week 8 is the governance layer that makes everything else legally defensible. The DLP policies, sensitivity labels, and audit log from Week 7 become the foundation for retention policies (what to keep and for how long), eDiscovery (finding content for legal requests), audit investigation (tracing exactly what happened and who did it), and the final capstone that covers the full eight-week M365 administration stack.

The Microsoft Purview compliance stack — what Week 8 covers
Retention policies Define how long content must be kept (legal/regulatory hold) and when it must be deleted. Applied to Exchange, SharePoint, OneDrive, Teams.
eDiscovery Search and export M365 content for legal requests, regulatory investigations, or HR disputes. Standard vs Premium tiers.
Audit log 180-day searchable record of all admin and user activity. Who did what, when, from where. Required for incident investigation and regulatory compliance.
Sensitivity labels (deep) Encryption on labels, auto-labelling policies, SharePoint library defaults, label inheritance, Office app integration beyond basic setup.
Insider risk (intro) Detects risky user behaviour patterns — bulk downloads, data exfiltration before resignation, policy violations. Covered in Day 3.
Daily breakdown
Day 1
Lecture: retention policy model, adaptive vs static scopes, retention vs deletion
Lab 8-A: Create retention policies for Exchange (3 years), SharePoint/OneDrive (5 years), Teams messages (1 year) → test with content deletion → verify preserved in Compliance portal
Day 2
Lecture: eDiscovery Standard vs Premium, legal hold, search vs export
Lab 8-B: Create eDiscovery Standard case → place Priya Nair mailbox on legal hold → search Finance content → export results → review export package
Day 3
Lecture: audit log structure, search operators, insider risk overview
Lab 8-C: Audit log search — reconstruct the Week 7 incident timeline → export audit results → configure insider risk management policy (intro) → review indicators
Day 4
Lecture: label encryption, auto-labelling policies, SharePoint defaults, label inheritance
Lab 8-D: Add encryption to Confidential/Finance label → create auto-labelling policy for credit card SIT → set SharePoint Finance library default label → test label inheritance in Office apps
Day 5
Review — full 8-week stack synthesis
Capstone: 3-part scenario requiring identity, endpoint, and compliance investigation — eDiscovery search, audit log reconstruction, and governance recommendation covering the full M365 admin stack
Key design decisions for Week 8
Day 1 retention connects directly to Week 4 (OneDrive retention) and Week 5 (meeting recordings). Students configured OneDrive retention in Lab 4-D and discussed recording expiry in Lab 5-D. Day 1 implements proper Purview retention policies that supersede and formalise those earlier settings. The 180-day OneDrive retention from Week 4 gets replaced by a policy-managed retention period — demonstrating why Purview is the right place to govern retention, not individual workload settings.
Day 2 eDiscovery uses the Week 7 incident as its source material. Students place Priya Nair's mailbox on legal hold and search for Finance-related content — the same scenario from the Week 7 assessment. This makes eDiscovery feel purposeful rather than academic: they are performing the discovery that would happen in a real post-incident investigation.
Day 3 audit log reconstruction is the most forensically realistic exercise in the course. Students use the unified audit log (enabled in Lab 7-C) to reconstruct the exact timeline of the Week 7 incident — who accessed what file, when the sharing link was created, who triggered the DLP match. The audit log search operators and export workflow are directly applicable to real incident response.
Day 4 sensitivity labels go deep. The basic labels created in Week 7 Day 5 now get encryption applied, auto-labelling policies, and SharePoint library defaults. This is where labels become genuinely useful rather than just cosmetic stamps. The auto-labelling policy using the Credit Card SIT connects back to the DLP policy from Lab 7-D — students see how labels and DLP work together.
Week 8 connections to earlier work
Week 8 topicConnects toThe payoff
Retention policiesLab 4-D — OneDrive retention; Lab 5-D — recording expiryPurview retention policies replace ad-hoc workload settings with legally defensible, centrally managed retention. The 180-day OneDrive setting from Week 4 is now a formal retention policy.
eDiscovery + legal holdWeek 7 — the Finance incident; Week 3 — Exchange mailboxesThe mailboxes configured in Week 3 and the incident investigated in Week 7 become the source for an eDiscovery case. Legal hold prevents the Payroll-Q4.docx content from being deleted.
Audit log reconstructionLab 7-C — audit log enabled; Week 7 assessment — incident timelineThe audit log enabled in Lab 7-C now contains the data needed to reconstruct exactly what happened in the Week 7 incident. Students search by user, operation, and date to build a forensic timeline.
Sensitivity labels (deep)Week 7 Day 5 — labels created; Lab 7-D — DLP policiesThe Confidential/Finance label from Week 7 gets encryption added. Auto-labelling uses the Credit Card SIT from Lab 7-D. The DLP policy gets a label condition. Everything connects.
Insider risk managementWeek 6 — endpoint management; Week 7 — Defender for EndpointInsider risk uses signals from Defender for Endpoint, DLP alerts, and audit events to detect risky behaviour patterns. The telemetry infrastructure from Weeks 6–7 feeds Week 8's insider risk indicators.
Day 5 capstone — scope and structure
SectionTopic coverageMarks
Part A — Identity and accessInvestigate a suspicious sign-in using Entra ID sign-in logs. Determine whether CA policies functioned correctly. Identify the specific policy gap.25
Part B — Compliance investigationRun an audit log search to reconstruct a user's activity over a 48-hour period. Place their mailbox on legal hold. Export relevant content as an eDiscovery package.25
Part C — Data governanceApply a sensitivity label with encryption to a Finance document. Verify the label prevents external access. Write a retention policy justification for the Finance team's document library.25
Part D — Written synthesisGiven the full 8-week M365 configuration at Lakeview Logistics, identify the three most significant remaining governance gaps and recommend specific controls for each. Justify each recommendation with reference to a specific risk scenario.25
Start with Day 1 →Course Outline →