Capstone: Prove the Security Layer End to End
Produce and test a complete Purview control package for a realistic company scenario.
In this lesson, you will learn to:
- Apply a repeatable method for the capstone: prove the security layer end to end in a licensed, governed, and testable Purview environment.
Capstone: Prove the Security Layer End to End
This lesson develops a practical understanding of the capstone: proving the security layer end to end while connecting design choices to supported capabilities, operational dependencies, user impact, and verifiable evidence.
Design one traceable control package
Your capstone company stores customer and employee data in SharePoint, Exchange, Teams, endpoints, a cloud data platform, and Microsoft 365 Copilot. It also permits one approved third-party AI service for public information. Leadership requires proof that high-risk customer exports cannot leave through ordinary email, sharing, removable media, or unapproved AI routes, while legitimate regulated transfers remain possible.
Produce: a policy statement; handling and retention standards; a RACI; data-flow diagram; license matrix; Data Map scope; catalog product; SIT or EDM design; sensitivity label; publishing and auto-labeling plan; DLP rules by location; exception procedure; retention rule; audit and eDiscovery plan; AI GRC decision; test matrix; incident playbook; evidence register; and quarterly metrics.
Every technical choice must trace to the control objective. Every control must state scope, dependency, residual risk, owner, and evidence. Do not claim protection for unsupported formats, unlicensed users, unmanaged devices, or data sources outside observation.
Run a failure-aware acceptance exercise
Test at least these journeys: a correct label applied manually; a high-confidence auto-label candidate; an external email; a SharePoint link; a guest opening an encrypted file; a Teams message; an endpoint copy; a public AI upload; Copilot grounding; user deletion of retained content; an eDiscovery hold; and an audit reconstruction.
For each test record prerequisites, data, actor, location, expected outcome, observed result, timestamps, event IDs, screenshots or exports, limitations, and pass criteria. Include negative tests that should remain allowed. Inject failures: an E3-only user, stale group membership, an unhealthy endpoint, unsupported format, expired exception, missing event, noisy SIT, and a delayed policy.
Present an assurance statement that distinguishes implemented, tested-effective, partially covered, and not covered controls. Assign remediation and review dates. This honest boundary is the final skill of the course: Purview adds a powerful security and governance layer when company decisions, product capabilities, operations, and evidence remain connected.
Resources
- Microsoft Learn reference for Capstone: Prove the Security Layer End to End — Official Microsoft documentation supporting the capability, prerequisites, and current product behavior taught in this lesson.