1. Understand the Purview Security and Governance System
Map the Purview Landscape and Its Security Boundaries Translate Licensing, Roles, and Governance into an Operating Model
2. Discover, Map, and Curate the Data Estate
Design Data Map Scanning and Metadata Collection Build Unified Catalog, Lineage, Quality, and Data Products
3. Classify and Protect Information
Engineer Sensitive Information Types and Classifiers Design Sensitivity Labels, Publishing, and Auto-Labeling
4. Prevent Unsafe Data Movement
Design DLP Policies from Business Scenarios Extend DLP to Endpoints, Browsers, Teams, and AI
5. Govern the Information Lifecycle
Design Retention Policies and Labels Operate Records, Events, Disposition, and Legal Holds
6. Investigate and Preserve Evidence
Use Purview Audit as Evidence Run eDiscovery Cases, Holds, Searches, and Reviews
7. Manage Human, Communication, and Compliance Risk
Operate Insider Risk and Communication Compliance Responsibly Use Information Barriers and Compliance Manager as Governed Controls
8. Protect Privacy, SharePoint, Microsoft 365, and AI
Secure SharePoint and Microsoft 365 Collaboration Paths Govern Microsoft 365 Copilot and Other Generative AI Protect Privacy and Support Data-Subject Workflows
9. Integrate, Report, and Operate Purview
Integrate Scanners, APIs, Reporting, and Multi-Cloud Sources Run Purview as a Production Security Service Turn DSPM Findings into Data Security Investigations
10. Design and Prove a Complete Purview Program
Build the Purview Target Architecture and Roadmap Capstone: Prove the Security Layer End to End
2. Discover, Map, and Curate the Data Estate

Build Unified Catalog, Lineage, Quality, and Data Products

Convert scanned metadata into business domains, trusted products, lineage, access workflows, and measurable data health.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Apply a repeatable method for build unified catalog, lineage, quality, and data products in a licensed, governed, and testable Purview environment.

Build Unified Catalog, Lineage, Quality, and Data Products

This lesson develops a practical understanding of build unified catalog, lineage, quality, and data products and connects design choices to supported capabilities, operational dependencies, user impact, and verifiable evidence.

A catalog becomes valuable when technical assets gain business context

Unified Catalog organizes metadata into governance domains and data products that people can find and understand. A domain establishes an accountability boundary. A data product packages data assets for a business purpose with an owner, description, intended use, access expectations, quality signals, and terms. Glossary terms provide shared language; critical data elements identify fields whose failure would materially affect the business.

Do not begin by importing thousands of glossary terms. Choose one domain with an important decision, identify consumers and stewards, curate a small set of products, and prove that users can discover and safely request the data they need. A “Customer 360” product should explain sources, freshness, quality, permitted use, owner, and lineage—not merely point to a table.

Lineage answers how data moved and changed. It helps assess downstream impact, investigate quality failures, and understand which reports or AI systems depend on a source. Validate automated lineage against real transformations and document manual gaps.

Measure trust rather than catalog volume

Catalog success is not the number of scanned assets. Measure whether important products have owners, descriptions, lineage, quality rules, current classifications, access instructions, and active consumers. A completeness percentage without a business denominator is cosmetic.

Use a product readiness review:

  • Is the business purpose and approved use clear?
  • Are authoritative and non-authoritative sources distinguished?
  • Does lineage cover the transformations that affect meaning?
  • Are critical elements linked to quality rules and accountable owners?
  • Can a consumer request access without bypassing source authorization?
  • Are privacy, retention, and security requirements visible?
  • Is there a review date and retirement path?

The catalog governs metadata and workflows; source systems still enforce underlying access. The Data Map and DLP limitations guide prevents the common mistake of assuming a catalog classification automatically blocks Microsoft 365 activity.

Resources