How Can Microsoft Purview Help Data Stewards Review and Control Data Migration from SharePoint and OneDrive?

Soumya Mohanty 21 Reputation points
2026-09-23T09:34:43.2233333+00:00

We are preparing for a business transition where a large volume of data stored in SharePoint Online and OneDrive will be copied to a new organization/owner.

To reduce the risk of sensitive data being transferred without proper review, we have proposed assigning Data Stewards to oversee and approve the migration. However, manually reviewing every file is not practical due to the volume of data.

We are exploring how Microsoft Purview can help automate or simplify this process.

Some ideas we are considering:

Automatically classify existing content using Sensitivity Labels or auto-labeling policies.

Identify and prioritize Confidential or Strictly Confidential content for Data Steward review.

Use Content Explorer, Activity Explorer, DLP, or eDiscovery to identify sensitive data before migration.

Generate reports or inventories of sensitive content that require approval before being copied.

Use AI-driven capabilities to prioritize high-risk data and reduce the review effort.

Monitor ongoing data transfers using DLP policies and alerts.

Our objective:

Instead of asking Data Stewards to review every file, we want technology to help:

Discover and classify sensitive content.

Prioritize content based on risk.

Present only high-risk data for Data Steward review.

Require business sign-off before sensitive data is exported or copied.

Questions:

What Microsoft Purview capabilities are best suited for this scenario?

Can Purview provide a risk-based inventory of content that should be reviewed before migration?

Are organizations using Purview eDiscovery, Content Explorer, auto-labeling, DLP, or AI capabilities for similar migration assessments?

Is there a recommended approach to support Data Stewards during large-scale SharePoint and OneDrive migrations?

Any guidance, best practices, or real-world experiences would be greatly appreciated.

Thank you.

Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-23T09:35:11.9866667+00:00

    Microsoft Purview can support this scenario, but the strongest supported path in the available guidance is to use classification, auto-labeling, DLP, and workflow/automation around exceptions rather than expecting a native SharePoint-to-Purview migration review experience.

    A practical approach is:

    1. Classify data at rest in SharePoint and OneDrive
      • Purview can automatically classify and label sensitive data at rest in SharePoint and OneDrive by using auto-labeling policies.
      • This is the best fit for identifying content that should be reviewed before transfer.
      • Use sensitivity labels such as Confidential or Strictly Confidential so review can focus on labeled content instead of every file.
    2. Use DLP for detection and response before or during transfer
      • For SharePoint and OneDrive, Purview DLP policies are the supported control plane for sensitive-content detection and protective action.
      • A recommended pattern is to configure policies, set them first to simulation mode, confirm they detect the same content expected, and then turn them on.
      • User notifications and policy tips can be configured to match alerting needs.
      • If quarantine is needed, Purview supports file quarantine for SharePoint and OneDrive after the quarantine location is configured.
    3. Create a review inventory by documenting policy scope and matches
      • The available migration guidance recommends documenting:
        • policy name and description
        • target apps such as SharePoint and OneDrive
        • inspection method
        • sensitive information types or labels detected
        • context filters such as sharing level, file type, and user groups
        • governance actions
      • That structure is a good model for a risk-based inventory for Data Stewards: focus review on content matched by sensitive information types, labels, sharing context, and governance actions.
    4. Use automation where Purview has no native steward notification flow
      • Native notification to data stewards for newly discovered assets lacking metadata is not available.
      • The documented pattern is to use Azure Function + Purview REST API or Power Automate to:
        • query recently added or updated assets
        • check for missing metadata or other review conditions
        • send notifications to the relevant stewards
      • The same pattern can be adapted for migration governance: notify stewards only for content that meets high-risk criteria.
    5. Use workflow-based approval outside direct file-by-file manual review
      • Where older SharePoint routing or records workflows were used, the recommended replacement pattern is Power Automate for routing content automatically.
      • For this migration scenario, that supports a business sign-off process around high-risk content rather than requiring review of all content.

    What is supported clearly from the available material:

    • Best-suited Purview capabilities
      • Auto-labeling for sensitive data at rest in SharePoint and OneDrive.
      • Purview DLP for detection, simulation, alerting, restriction, and quarantine actions.
      • Power Automate / Azure Function + Purview API for steward notification and approval workflows.
    • Risk-based inventory
      • Purview can help identify sensitive content through labels, sensitive information types, and DLP conditions.
      • A practical inventory should prioritize content by:
        • sensitivity labels
        • sensitive information types
        • sharing level
        • file type
        • user group context
        • governance action required
    • Recommended approach for large-scale SharePoint and OneDrive migration assessment
      1. Auto-classify and auto-label existing SharePoint and OneDrive content.
      2. Build DLP policies for the same sensitive data patterns.
      3. Run DLP in simulation mode first.
      4. Produce a steward review list from labeled/DLP-matched content only.
      5. Use Power Automate or Azure Function + Purview REST API to route approval tasks and notifications.
      6. Turn on DLP enforcement for transfer controls after validation.

    What is not supported in the available material:

    • No direct evidence here that Purview provides a built-in AI-driven migration risk prioritization dashboard specifically for SharePoint/OneDrive migration review.
    • No direct support here for using eDiscovery, Content Explorer, or Activity Explorer as the recommended primary migration-assessment workflow.
    • No direct support here for a direct SharePoint Online to Purview automated metadata scanning, version history extraction, or lineage capability for files stored in SharePoint Online.

    So the most grounded recommendation is to center the solution on auto-labeling + DLP + automation-assisted steward approval for high-risk content, instead of relying on a native migration-review feature.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.