Watchtower Docs
ReferenceCheck catalog

Microsoft Purview

All 4 Microsoft Purview checks - what each one checks, why, and the access used to evaluate it.

4 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.

CheckSeverityWhat it checksWhy it mattersAccess used
Microsoft 365 audit log search is enabled
wt.purview.audit-log-enabled
HIGHChecks that the Microsoft 365 unified audit log is enabled, ensuring that user and administrator activity across Exchange Online, SharePoint, Teams, and other services is collected for security monitoring and forensic investigation.The unified audit log is the primary source of evidence for detecting and investigating security incidents in Microsoft 365. Without it, activities such as mailbox access by suspicious accounts, file downloads, permission changes, and configuration modifications go unrecorded, making incident response and forensics impossible.Exchange.ManageAsApp - via adminAuditLogConfig
DLP policies are enabled
wt.purview.dlp-policies-enabled
HIGHChecks that at least one Data Loss Prevention (DLP) policy is actively enabled in Microsoft Purview, scanning content across Microsoft 365 services to detect and block sensitive data from being shared inappropriately.Without active DLP policies, sensitive information - such as credit card numbers, health records, and confidential documents - can be shared externally via email, SharePoint, Teams, or OneDrive without detection. DLP policies enforce data-handling rules and provide the alert and blocking capabilities needed to prevent accidental or intentional data exfiltration.DataLossPreventionPolicy.Read.All - via dlpPolicies
DLP policies are enabled for Microsoft Teams
wt.purview.dlp-policies-teams-enabled
HIGHChecks that at least one enabled DLP policy is scoped to Microsoft Teams, preventing sensitive data from being shared in Teams chats and channel messages.Teams is increasingly used for file sharing and sensitive communications, making it a significant data exfiltration vector. DLP policies not extended to Teams leave a gap where sensitive data shared in chats and channels - including files, credit card numbers, and confidential documents - goes undetected and unblocked.DataLossPreventionPolicy.Read.All - via dlpPolicies
Information Protection sensitivity label policies are published
wt.purview.sensitivity-labels-published
MEDIUMChecks that at least one sensitivity label policy has been published to users, making Microsoft Purview sensitivity labels available for classifying and protecting documents and emails.Sensitivity labels enable users and automated policies to classify content and apply protection controls (encryption, access restrictions, DLP matching) to documents and emails. Without published labels, content classification cannot be enforced, leaving sensitive data unprotected as it flows through email, SharePoint, and Teams.InformationProtectionPolicy.Read.All - via labelPolicies