A unified data governance solution that helps manage, protect, and discover data across your organization
Microsoft Purview can support this scenario, but the strongest supported path in the available guidance is to use classification, auto-labeling, DLP, and workflow/automation around exceptions rather than expecting a native SharePoint-to-Purview migration review experience.
A practical approach is:
- Classify data at rest in SharePoint and OneDrive
- Purview can automatically classify and label sensitive data at rest in SharePoint and OneDrive by using auto-labeling policies.
- This is the best fit for identifying content that should be reviewed before transfer.
- Use sensitivity labels such as Confidential or Strictly Confidential so review can focus on labeled content instead of every file.
- Use DLP for detection and response before or during transfer
- For SharePoint and OneDrive, Purview DLP policies are the supported control plane for sensitive-content detection and protective action.
- A recommended pattern is to configure policies, set them first to simulation mode, confirm they detect the same content expected, and then turn them on.
- User notifications and policy tips can be configured to match alerting needs.
- If quarantine is needed, Purview supports file quarantine for SharePoint and OneDrive after the quarantine location is configured.
- Create a review inventory by documenting policy scope and matches
- The available migration guidance recommends documenting:
- policy name and description
- target apps such as SharePoint and OneDrive
- inspection method
- sensitive information types or labels detected
- context filters such as sharing level, file type, and user groups
- governance actions
- That structure is a good model for a risk-based inventory for Data Stewards: focus review on content matched by sensitive information types, labels, sharing context, and governance actions.
- The available migration guidance recommends documenting:
- Use automation where Purview has no native steward notification flow
- Native notification to data stewards for newly discovered assets lacking metadata is not available.
- The documented pattern is to use Azure Function + Purview REST API or Power Automate to:
- query recently added or updated assets
- check for missing metadata or other review conditions
- send notifications to the relevant stewards
- The same pattern can be adapted for migration governance: notify stewards only for content that meets high-risk criteria.
- Use workflow-based approval outside direct file-by-file manual review
- Where older SharePoint routing or records workflows were used, the recommended replacement pattern is Power Automate for routing content automatically.
- For this migration scenario, that supports a business sign-off process around high-risk content rather than requiring review of all content.
What is supported clearly from the available material:
- Best-suited Purview capabilities
- Auto-labeling for sensitive data at rest in SharePoint and OneDrive.
- Purview DLP for detection, simulation, alerting, restriction, and quarantine actions.
- Power Automate / Azure Function + Purview API for steward notification and approval workflows.
- Risk-based inventory
- Purview can help identify sensitive content through labels, sensitive information types, and DLP conditions.
- A practical inventory should prioritize content by:
- sensitivity labels
- sensitive information types
- sharing level
- file type
- user group context
- governance action required
- Recommended approach for large-scale SharePoint and OneDrive migration assessment
- Auto-classify and auto-label existing SharePoint and OneDrive content.
- Build DLP policies for the same sensitive data patterns.
- Run DLP in simulation mode first.
- Produce a steward review list from labeled/DLP-matched content only.
- Use Power Automate or Azure Function + Purview REST API to route approval tasks and notifications.
- Turn on DLP enforcement for transfer controls after validation.
What is not supported in the available material:
- No direct evidence here that Purview provides a built-in AI-driven migration risk prioritization dashboard specifically for SharePoint/OneDrive migration review.
- No direct support here for using eDiscovery, Content Explorer, or Activity Explorer as the recommended primary migration-assessment workflow.
- No direct support here for a direct SharePoint Online to Purview automated metadata scanning, version history extraction, or lineage capability for files stored in SharePoint Online.
So the most grounded recommendation is to center the solution on auto-labeling + DLP + automation-assisted steward approval for high-risk content, instead of relying on a native migration-review feature.
References:
- Can sensitive data at rest get labeled in MS Purview - Microsoft Q&A
- Migrate file policies to Microsoft Purview
- Can Purview notify the relevant data stewards that there is a new asset to add metadata to? - Microsoft Q&A
- Migration strategies for moving to Microsoft Purview risk and compliance solutions from older information management and records management for SharePoint for Microsoft 365
- SharePoint Online to Microsoft Purview - Microsoft Q&A