Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Connector ID | MicrosoftPurviewInformationProtection |
| Publisher | Microsoft |
| Used in Solutions | Microsoft Purview Information Protection |
| Collection Method | Native |
| Connector Definition Files | MicrosoftPurviewInformationProtection.json |
Microsoft Purview Information Protection helps you discover, classify, protect, and govern sensitive information wherever it lives or travels. Using these capabilities enable you to know your data, identify items that are sensitive and gain visibility into how they are being used to better protect your data. Sensitivity labels are the foundational capability that provide protection actions, applying encryption, access restrictions and visual markings.
Integrate Microsoft Purview Information Protection logs with Microsoft Sentinel to view dashboards, create custom alerts and improve investigation. For more information, see the [Microsoft Sentinel documentation](https://go.microsoft.com/fwlink/p/?linkid=2223811&wt.mc_id=sentinel_dataconnectordocs_content_cnl_csasci).
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
MicrosoftPurviewInformationProtection |
✓ | ✗ | ? |
Resource Provider Permissions: - Workspace (Workspace): read and write permissions.
Custom Permissions: - License: Enterprise Mobility + Security E5/A5 or Microsoft 365 E5/A5 or P2
Tenant Permissions: Requires GlobalAdmin, SecurityAdmin on the workspace's tenant
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Microsoft Purview Information Protection audit logs to Microsoft Sentinel
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊