Microsoft Purview · Public Preview

Unified Classification Management Experience

Your starting point for understanding the value of unified classifier management, reviewing your current estate, and turning visibility into safer day-to-day administration.

01 · Admin value

Understand why unified management matters

The Unified Classification Management Experience (CME) gives you a centralized control plane for understanding and governing how sensitive information is detected across Microsoft Purview. It brings built-in and custom Sensitive Information Types (SITs), trainable classifiers, Exact Data Match (EDM), document fingerprints, credentials, and named entities into one management experience available through Data Loss Prevention (DLP), Information Protection (MIP), and Data Security Posture Management (DSPM).

The administrative value: CME is more than a collection of configuration pages. It provides the inventory, policy-dependency awareness, and consistent lifecycle controls needed to manage classification safely at enterprise scale.

See the estate

Find supported classifier types in one inventory and understand what your organization already uses.

Understand impact

Review classified-item counts and policy dependencies before making a change that could affect protection.

Govern consistently

Use a common process to discover, create, inspect, validate, update, and retire classifiers.

02 · Operating model

Manage classifiers through one repeatable workflow

Use this lifecycle to reduce change risk, clarify accountability, and keep critical classifiers aligned with business needs.

Continuous classification lifecycle

Inventory Record purpose, owner, and related policies.
Assess Review match quality, dependencies, and business impact.
Test Test representative samples against expected results.
Approve Confirm approvals, rollback triggers, and prior configuration.
Change Apply only the approved change.
Validate Retest, confirm policy behavior, and investigate volume changes.
Review Record the outcome, schedule review, and roll back when needed.
Repeat Use each outcome to improve the next cycle.

Assign clear ownership

Business owner

Defines the need, confirms continued relevance, and accepts quality tradeoffs.

Classification administrator

Documents dependencies, coordinates testing, implements the change, and preserves evidence.

Policy owner or reviewer

Assesses enforcement impact, validates results, and approves the outcome.

Use a simple review cadence

Monthly

  • Review new and recently changed classifiers.
  • Investigate unexpected count or coverage changes.
  • Confirm that critical classifiers still have an owner.

Quarterly

  • Review dependencies, ownership, and validation evidence.
  • Assess unused, overlapping, and low-quality classifiers.
  • Prioritize gaps created by business or regulatory change.
Stable enforcement: Existing policies continue to evaluate the same classifier GUIDs unless you deliberately change the classifier or its policy references.
03 · Classification strategy

Focus your strategy on business risk and detection quality

Answer these questions before creating or changing classifiers.

Business need and inventory What sensitive data and business process must be protected, and does an existing classifier already meet the need?
Quality gaps Where do current classifiers create false positives, miss important content, or overlap with another definition?
Classification method Which method best fits the data: built-in or custom SIT, EDM, fingerprinting, named entities, credentials, or a trainable classifier?
Data-estate visibility Which workloads and repositories must be reviewed, and where can matched items be validated?
Ownership and dependencies Who owns the classifier, which policies depend on it, and who must approve a change?
Testing and lifecycle What results are acceptable, what triggers rollback, and when should the classifier be reviewed or retired?

Choose the simplest method that fits the need

Need Start with
Common regulated identifierBuilt-in Sensitive Information Type
Organization-specific pattern, keywords, or evidenceCustom Sensitive Information Type
Exact values from an authoritative datasetExact Data Match
Standard form or document templateDocument fingerprinting
People, places, organizations, or named conceptsNamed entities
Passwords, tokens, keys, or secretsCredential classifiers
Documents recognized by meaning and contentTrainable classifier
04 · Get started

Start using unified classification management

Use these steps to become familiar with the experience and prepare it for your organization.

Review each available entry path
Open the unified hub through the DLP, MIP, and DSPM paths available in your tenant. Availability can vary by tenant and capability.
Launch the unified hub Access the hub from an available DLP, MIP, or DSPM path and complete the first-run tour.
Review your classifier inventory Use search, filters, and sorting to find and inspect the classifiers used by your organization.
Create a classifier Start from the single Create entry, select a supported classifier type, review its preparation guidance, and complete the type-specific flow.
Review policy dependencies before making changes Inspect where a classifier is used before editing or deleting it, and confirm the expected impact on DLP and labeling policies.

Check policy impact before making changes

Use the Affected policies count to identify the DLP and auto-labeling policies that depend on a classifier. Open each policy list and confirm ownership and expected impact before editing or deleting the classifier.

Validate classification results

Open a classifier and use the Matched items view to confirm where detections occur. Compare results across data sources, investigate unexpected coverage, and verify that the classifier supports its intended business scenario.

05 · Customer scenarios

See the experience applied to common challenges

Financial services

Before: Admins checked multiple locations and contacted several owners before changing a classifier.

Now: They review the centralized inventory and affected-policy count first.

Value: Safer changes with the right policy owners involved.

Healthcare

Before: Admins could not easily compare classifier coverage across Exchange, SharePoint, and OneDrive.

Now: They review matched items by data source and investigate gaps.

Value: Testing is focused on the workloads that need attention.

Retail

Before: Classifiers created by different teams lacked consistent ownership and review.

Now: Admins use one searchable inventory and a common lifecycle.

Value: Clearer ownership, less duplication, and faster reviews.

06 · FAQs

Get answers to common admin questions

What licenses are required?
Licensing varies by capability. Confirm requirements in the current Microsoft Purview licensing and commercial documentation.
Which roles can manage classifiers?
Applicable Microsoft Entra and Microsoft Purview roles include administrative, analyst, investigator, and reader roles. Assign the least-privileged role that fits the task. Viewing item lists or content in Data Explorer requires separate Data Explorer permissions.
How does this work with the existing classifier experiences?
The unified and existing experiences manage the same supported classifiers. Changes made in either experience are reflected in the other. Use current product documentation when planning production administration.
Can I delete a classifier used by a policy?
Review the affected-policy count and follow your change-control process before deleting it. Available actions can differ by classifier type.
How can I review content matched by a classifier?
Use Data Explorer to review matched items and their locations. In the Microsoft Purview portal, go to Information Protection > Explorers. Appropriate Data Explorer permissions are required.
Can I classify files already at rest?
Yes. On-demand classification can identify and classify supported sensitive content in files at rest, including files that need first-time or updated classification.