How to Set Up Purview Labels in a Playbook and Scan

This article provides a walkthrough for the steps that come after the Microsoft Purview integration is configured, so Spirion can apply Purview (MIP) sensitivity labels to sensitive data it finds. It assumes you already know how to build playbooks and scans (links to how-to articles are provided).

Overview

Once the Purview Integration has been configured the following must be done:

  • Classifications labels must be created
  • A playbook must be made
  • Scans must be configured so that Purview labels can be applied to sensitive data.

This guide helps you walk though that process.

Note: You may need to consult guides on how to create playbooks and scans if you have not done these pieces before.

More Information

Video Demonstrations of Spirion Sensitive Data Platform and Microsoft Purview

  • Spirion Sensitive Data Platform Integration with Microsoft Purview: Video Demonstration with Jeremy Fields, archTIS Director of DevOps
  • Expanding Microsoft Purview Data Discovery and Classification with Spirion: Video Demonstration with Rob Server and Jonathan Turner

Feature and Complement Information


How to Create Classifications for Purview in Spirion Sensitive Data Platform

This section covers the creating of custom classifications to be used with Purview labels.

  1. From the left side navigation menu navigate to "Settings > Global Classifications" in the Spirion Console.
  2. Select Actions from the top right corner of the screen.
  3. Select Add New from the combo box.

  4. Fill out the fields in the Add Classification pop-up box.
    1. Name - Make this match the Purview labels with "-Purview" at the end of the classification name. 
      • Note: This will be used for reporting
    2. Type - Select a type for this classification
    3. Description - What is this classification for
    4. Assign Icon - (optional) pick an icon for this classification
    5. Assign Color - Pick a color for this classification when displayed in explorer
  5. Click the Confirm button.

    1. The playbook below is looking for SSNs. If one is found, then it performs the following actions:
      1. Labels the file with the SSN (in the database ONLY) with “Public-Purview” (Spirion label)
      2. Applies the Purview label “Public” to the actual metadata of the file itself

How to Add a Label to a Playbook

  • For general information about making playbooks see: How to Write a Playbook.
  • When adding a label to a playbook the MIP Label box appears to the right of the classification. See the graphic below.
  • Make sure to select the matching label to the classification and select Add/Replace label.
  1. The playbook below is looking for SSNs and if one is found then the Purview Information Protection Client on an Agent will:
    • Label the file with the SSN (in the database ONLY) with “Public-Purview” (Spirion label), and,
    • Apply “Public” (Purview label) to the actual metadata of the file

How to Set up the Purview Information Protection Client on a Spirion Agent

To make labels visible on a Spirion Agent the Purview Information Protection Client must be installed.

  1. Install the Purview Information Protection Client on machines where the Spirion agent is installed:
  2. Purview client log locations:
    • \ProgramFiles (x86)\Microsoft Purview Information Protection (64-bit operating systems only)
    • %localappdata%\Microsoft\MSIP
  3. To confirm a successful installation and that the client is connected with the Microsoft tenant:
    1. Open the Information Protection File Labeler
    2. Click “Help and Feedback.” 
  4. This shows the client is connected to the tenant and showing an active Session ID.

  5. To verify the file has been labeled appropriately, open one of the files that contained a match and verify the Purview label associated with the file: