EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
Microsoft 365 Compliance Guide | EPC Group - EPC Group enterprise consulting

Microsoft 365 Compliance Guide | EPC Group

Enterprise Microsoft consulting insights from EPC Group — 29 years serving Fortune 500.

February 23, 2026|24 min read|Microsoft 365 Consulting

Microsoft 365 Compliance Guide: Enterprise Framework for Purview, DLP, and eDiscovery

A comprehensive Microsoft 365 compliance guide covering Purview Compliance Manager, Data Loss Prevention policies, retention labels, eDiscovery, and information barriers. Built for enterprises in healthcare, financial services, and government that must meet HIPAA, SOC 2, GDPR, and FedRAMP requirements.

Microsoft 365 Compliance Guide 2026: Purview, DLP, and eDiscovery

Last updated: 2026 | Read time: 6 min

Microsoft 365 includes a comprehensive compliance platform through Microsoft Purview. It covers data loss prevention, retention labels, eDiscovery, information barriers, and regulatory scoring via Compliance Manager. This guide explains how to configure each component for HIPAA, GDPR, FINRA, FedRAMP, SOC 2, and PCI DSS requirements.

  • Microsoft Purview Compliance Manager: pre-built assessments for 360+ regulations
  • Compliance Manager score: 0–100% measuring your current posture against selected frameworks
  • DLP policies detect sensitive information types (SITs) and enforce blocking, encryption, or notification
  • eDiscovery (Premium): conversation threading, near-duplicate detection, and predictive coding
  • Information barriers: restrict communication between specific departments (trading desk / research)
  • EPC Group: 29 years, 11,000+ engagements, 70+ Fortune 500 clients

The Microsoft 365 Compliance Landscape in 2026

Microsoft Purview is the unified compliance platform for Microsoft 365. It replaces the older Security & Compliance Center and consolidates all compliance capabilities into a single administration experience.

The platform covers four major compliance domains:

  • Data governance: Sensitivity labels, retention labels, records management
  • Risk and compliance: Compliance Manager, Insider Risk Management, Communication Compliance
  • Data protection: DLP policies, encryption, information barriers
  • eDiscovery and audit: Content Search, eDiscovery Standard and Premium, Audit Premium

Microsoft Purview Compliance Manager

Compliance Manager is the scoring and assessment engine. It measures your Microsoft 365 environment against regulatory frameworks and provides step-by-step improvement guidance.

  • Pre-built assessments for 360+ regulations: HIPAA, GDPR, SOC 2, FedRAMP, PCI DSS, and more
  • Compliance score: 0–100% reflecting your current posture on the selected frameworks
  • Improvement actions: specific configuration steps with point values and implementation guidance
  • Shared responsibility model: Microsoft-owned controls (platform security) vs customer-owned controls (your configuration)

Data Loss Prevention (DLP)

DLP policies detect sensitive content and take automated action to protect it. They apply across Exchange Online, SharePoint, OneDrive, Teams, and endpoints.

How DLP Policies Work

DLP policies identify sensitive content using Sensitive Information Types (SITs) — pattern-matching engines for credit card numbers, Social Security numbers, health records, and 300+ other data types. When a match is detected, the policy takes one of three actions:

  • Block sharing (prevent the user from sharing the file externally)
  • Require encryption (wrap the content in Rights Management before sending)
  • Notify compliance officers (generate an alert for review)

Auto-Apply Retention Labels

Auto-apply policies apply retention labels automatically based on three trigger types:

  • Sensitive information types: documents containing SSNs get labeled "PII – 7 Year Retention"
  • Keywords or searchable properties: documents in specific libraries or with specific metadata values
  • Trainable classifiers: contracts, financial statements, HR documents — pre-trained AI models

Retention Labels and Records Management

Retention labels define how long content must be kept and what happens at the end of the retention period (delete, review, or mark as a record).

Retention Label Design

  • Map retention labels to regulatory obligations: HIPAA (6 years), FINRA (3–6 years), SOX (7 years), SEC 17a-4 (immutable)
  • Create a label taxonomy before deploying — retroactive re-labeling is expensive
  • Use file plan for formal records management: item type, disposition reviewer, regulatory citation
  • Disposition review: requires a human reviewer before permanent deletion of regulated records

eDiscovery

eDiscovery searches for content across Microsoft 365 in response to legal holds, investigations, or regulatory inquiries. Microsoft 365 provides three tools with escalating capability.

  • Content Search: Finds content across mailboxes, sites, and Teams. No case management — results only.
  • eDiscovery (Standard): Adds legal hold, case management, and export capability.
  • eDiscovery (Premium): Adds conversation threading, near-duplicate detection, predictive coding (relevance ranking), and custodian management. Required for complex litigation with high document volumes.

Information Barriers

Information barriers (IB) restrict communication and collaboration between specific departments or user groups. They are required by regulation in financial services (Chinese Wall between trading desk and research) and are increasingly used in healthcare (separation between clinical and billing teams).

  • Restrict Teams messaging and meeting invites between designated groups
  • Block SharePoint file sharing across IB-separated departments
  • Prevent OneDrive sharing between restricted groups
  • Requires Microsoft 365 E5 or Compliance E5 add-on

EPC Group Microsoft 365 Compliance Services

EPC Group delivers Microsoft 365 compliance as fixed-fee engagements. Every engagement produces documented controls your compliance officer can sign off on.

  • Regulatory gap analysis vs your applicable frameworks (HIPAA, GDPR, FINRA, FedRAMP)
  • Compliance Manager optimization: review existing score, prioritize improvement actions
  • DLP policy design and deployment across all M365 workloads
  • Retention framework implementation: label taxonomy, auto-apply policies, records management
  • eDiscovery readiness assessment: hold verification, custodian mapping, search validation
  • Information barrier configuration for financial services and healthcare
  • Ongoing compliance monitoring with quarterly review cadence

Frequently Asked Questions

What is a Sensitive Information Type (SIT) and how many does Microsoft provide?

A Sensitive Information Type (SIT) is a pattern-matching engine that identifies specific data in Microsoft 365 content.

Microsoft provides 300+ pre-built SITs covering credit card numbers, Social Security numbers, passport numbers, health record identifiers, financial account numbers, and many more. You can also build custom SITs for organization-specific data patterns.

What is the difference between DLP and sensitivity labels?

Sensitivity labels classify and protect content — they travel with the file wherever it goes. DLP policies detect and prevent specific actions — they block sharing, require encryption, or alert on policy violations. Both work together: sensitivity labels identify what the content is; DLP policies enforce what can be done with it.

Do we need eDiscovery Premium or will Standard work?

eDiscovery Standard is sufficient for straightforward legal holds and content exports.

Premium is required when you have high document volumes, complex litigation requiring relevance ranking (predictive coding), conversation threading across Teams and email, or custodian management for large numbers of data subjects. Regulated industries with frequent regulatory inquiries typically need Premium.

What does EPC Group charge for a Microsoft 365 compliance engagement?

Engagements are fixed-fee based on the number of regulatory frameworks in scope, the complexity of your data environment, and whether you need ongoing managed compliance monitoring.

A baseline compliance engagement (gap analysis + DLP + retention framework) typically runs in the range of mid-five figures. Contact EPC Group for a scoped estimate at (888) 381-9725 or contact@epcgroup.net.

Start Your Microsoft 365 Compliance Engagement

EPC Group provides Microsoft 365 compliance consulting for Fortune 500 healthcare, financial services, federal government, and manufacturing organizations. Call (888) 381-9725, email contact@epcgroup.net, or visit /contact to schedule a Compliance Readiness Assessment.

Frequently Asked Questions

What is Microsoft Purview Compliance Manager?

Microsoft Purview Compliance Manager is a risk-based compliance management solution within Microsoft 365 that helps organizations assess, monitor, and improve their compliance posture. It provides pre-built assessments for 360+ regulations (HIPAA, GDPR, SOC 2, FedRAMP, PCI DSS, etc.), a compliance score (0-100%) that measures your current posture, and recommended improvement actions with step-by-step implementation guidance. Compliance Manager is included in Microsoft 365 E3/E5 licenses.

How do Microsoft 365 DLP policies work?

Data Loss Prevention (DLP) policies in Microsoft 365 detect and prevent the sharing of sensitive information across Exchange, SharePoint, OneDrive, Teams, and endpoint devices. DLP policies use sensitive information types (SITs) like credit card numbers, Social Security numbers, and health records to identify sensitive content, then enforce actions like blocking sharing, requiring encryption, or notifying compliance officers. Microsoft 365 E5 or E5 Compliance add-on is required for endpoint DLP.

What is the difference between retention labels and retention policies in Microsoft 365?

Retention policies apply retention settings broadly to entire locations (all Exchange mailboxes, all SharePoint sites) and are best for baseline retention across the organization. Retention labels apply to individual items (specific emails, documents) and support more granular control including disposition review, records management, and event-based retention. Most enterprises use both: retention policies for baseline data lifecycle management and retention labels for regulatory records that require specific handling.

How does eDiscovery work in Microsoft 365?

Microsoft 365 eDiscovery enables legal teams to search, preserve, collect, and export electronically stored information (ESI) for litigation, investigations, and regulatory inquiries. Content Search finds content across mailboxes, sites, and Teams. eDiscovery (Standard) adds legal hold, case management, and export. eDiscovery (Premium) adds advanced features like conversation threading, near-duplicate detection, predictive coding, and custodian management. Premium requires Microsoft 365 E5 or E5 eDiscovery add-on.

Do we need Microsoft 365 E5 for compliance features?

Not necessarily. Microsoft 365 E3 includes basic compliance features: Purview Compliance Manager (limited assessments), basic DLP for Exchange and SharePoint, standard retention policies, and Content Search. Microsoft 365 E5 adds advanced capabilities: endpoint DLP, advanced eDiscovery, auto-labeling, insider risk management, communication compliance, and information barriers. For regulated industries (healthcare, financial services), E5 or the E5 Compliance add-on ($12/user/month) is typically necessary to meet regulatory requirements.

Ready to get started?

EPC Group has completed over 10,000 implementations across Power BI, Microsoft Fabric, SharePoint, Azure, Microsoft 365, and Copilot. Let's talk about your project.

contact@epcgroup.net(888) 381-9725www.epcgroup.net
Schedule a Free Consultation