Topic
Security & Compliance
Security is not a layer you add at the end. Labels, DLP, access and auditability shape the platform itself, and those choices run through Fabric, Foundry, Copilot and Purview at the same time.
- articles
- 23
- minutes of reading
- 49
- episodes
- 5
Use Cases
- 01
Manufacturing: classification and lifecycle management as the foundation for Copilot
A vehicle engine manufacturer automates classification and lifecycle management for tens of millions of files with Microsoft Purview, as a precondition for a responsible Microsoft 365 Copilot pilot.
3 min read - 02
Finance: speeding up analysis and reporting with Microsoft 365 Copilot
A financial services firm uses Copilot in Outlook, Word and Excel to summarize files and draft reports, with an agent on internal guidelines and DLP on financial data.
2 min read - 03
Finance: demonstrable lineage for regulatory reporting
A financial institution consolidates a patchwork of services onto Fabric and builds controlled, demonstrably correct regulatory reporting with Warehouse, Purview lineage and Git-driven ALM.
3 min read - 04
Finance: Insider Risk and Adaptive Protection at a financial institution
A financial institution makes security controls risk-driven with Insider Risk Management and Adaptive Protection, and ties communication oversight to a demonstrable audit trail.
2 min read - 05
Government: knowledge access with strict governance in Microsoft 365 Copilot
A government agency exposes large document corpora with Copilot within a strict grounding scope, after oversharing remediation and with labels, DLP and EU Data Boundary.
2 min read - 06
Government: data mesh with delegated ownership
A municipality exposes department data as an integral view through Fabric domains and OneLake shortcuts, with delegated ownership per department and central GDPR safeguards.
2 min read - 07
Government: DLP and compliance at scale with Microsoft Purview
A government organization phases in Data Loss Prevention across mail, endpoints and network, with retention, Communication Compliance and a demonstrable audit trail for the regulator.
2 min read - 08
Government: Sovereign policy assistant with Microsoft Foundry
A ministry surfaces internal policy corpora through a RAG agent in an isolated project, with EU region, private networking and strict guardrails.
2 min read - 09
Healthcare: Clinical knowledge assistant with Microsoft Foundry
An academic hospital surfaces protocols and guidelines through a grounded RAG agent, with groundedness evaluation and citations as a condition for use in the consultation room.
2 min read - 10
Healthcare: relieving administrative load with Microsoft 365 Copilot
A healthcare organization uses Copilot in Word, Outlook and Teams to draft reports and correspondence, and an agent on care protocols to find policy faster.
2 min read - 11
Healthcare: protecting special category data with Microsoft Purview
A healthcare organization classifies and protects patient data with Data Map, sensitivity labels, DLP and Insider Risk Management, without slowing down care delivery.
2 min read - 12
Technology: safe Copilot rollout with Purview DSPM
A software vendor rolls out Microsoft 365 Copilot and uses Purview DSPM to gain visibility and policy over which sensitive data flows through AI prompts and responses.
2 min read - 13
Manufacturing: protecting intellectual property with Microsoft Purview
A manufacturer protects drawings, recipes and process data with classification, encrypted labels and Endpoint DLP, while making engineering data findable through the Unified Catalog at the same time.
2 min read - 14
Retail: trusted analytics with Data Products in the Unified Catalog
A retail chain builds trusted, owner-backed Data Products in the Purview Unified Catalog, so analysts reuse sales, inventory and customer data without second-guessing it.
2 min read - 15
Finance: RAG for compliance questions with Microsoft Foundry
An insurer surfaces thousands of policy terms and policy documents via RAG, with strict grounding and a full audit trail.
2 min read
Best Practices
- 16
Rolling out Microsoft 365 Copilot: remediating oversharing and governing agents
Why Copilot does not create access but inherits existing permissions, and how to remediate oversharing, pick the right agent building block, and govern agents before broad adoption.
3 min read - 17
Data governance best practices
Design a scalable governance model with domains, business glossary, data owners, stewardship, and automated data discovery across Microsoft Fabric and Azure.
1 min read - 18
Information Protection at enterprise scale
Implement sensitivity labels, encryption, auto-labeling, and protection policies that work consistently across Microsoft 365, Copilot, Teams, SharePoint, and Exchange.
1 min read - 19
Data Security and DLP best practices
Build effective Data Loss Prevention, Insider Risk, Adaptive Protection, and Data Security Posture Management policies without disrupting productivity.
1 min read
How-tos
Architecture Discussions
Known Limitations
- 22
SQL analytics endpoint RLS does not apply in Spark
Row-level and column-level security defined on the SQL analytics endpoint applies only there. For isolation that also holds in Spark you need OneLake Security.
1 min read - 23
OneLake availability on KQL data is a copy with delay
KQL tables you expose as Delta through OneLake availability are not a zero-latency mirror, and KQL RLS does not apply to that copy.
1 min read
Listen
The podcast on governance and security
View the seriesPractise
Test your choices
Reading shows you what can go wrong. Practising shows you whether you see it coming in a real engagement.
Continue learning
Use Cases
Real architecture cases per Microsoft technology and industry: the business challenge, the chosen architecture, why that choice, the alternatives and the trade-offs.
30 casesArchitecture Lab
Practise the decisions in a realistic customer engagement, then read the debrief.
4 engagementsPodcasts
Four shows on Microsoft architecture: real-world experience, design decisions and trade-offs, playable right here.
28 episodes
