Protego field desk
Security Operations, Identity and Compliance / 25-30% of exam

L9.Compliance Architecture with Purview, Policy & Defender

Course outlineLesson 9 of 18

Translate regulatory obligations into owned, testable controls using Microsoft Purview, Azure Policy, and Defender for Cloud without confusing compliance evidence with security assurance.

Translate obligations into control statements

Regulations describe outcomes and responsibilities. Convert each applicable requirement into a control objective, scope, owner, implementation, evidence source, test method, and review frequency. Legal and privacy stakeholders determine applicability; the architect designs technical support.

Choose the right control plane

Microsoft Purview supports data discovery, classification, protection, audit, records, and compliance workflows across supported environments. Azure Policy evaluates and enforces Azure resource configuration. Microsoft Defender for Cloud assesses posture against standards and provides recommendations.

NeedPrimary capability
Data classification and protectionMicrosoft Purview
Azure configuration guardrailAzure Policy
Cloud posture and standard assessmentDefender for Cloud
Legal interpretationQualified legal or compliance owner

Design exceptions and evidence

Controls need machine-readable evidence where possible, but automated status is not the whole assurance case. Record exceptions with risk, compensating controls, owner, expiry, and revalidation. Keep evidence access restricted and retention aligned to the requirement.

Avoid the compliance trap

A compliant configuration can still be vulnerable to a threat outside the selected benchmark. Use compliance assessment as one input to security architecture, not as proof that risk is eliminated.

Exam Focus Points
  • Translate requirements into scoped controls with owners, evidence, and tests
  • Purview focuses on data and compliance; Policy governs Azure configuration
  • Defender for Cloud assesses posture against standards and benchmarks
  • Compliance status is evidence, not proof that all security risk is addressed
Knowledge Check

1. Which service is the best fit for enforcing that Azure storage accounts disable public access?