A unified data governance solution that helps manage, protect, and discover data across your organization
Hi AzGeek
Thank you for reaching out microsoft Q&A!. You are correct that today there are platform limitations in Microsoft Purview when it comes to automatically scanning and classifying Exchange Online mailbox content at-rest using Sensitive Information Types (SITs).
Current capability At present, Purview Information Protection auto-labeling policies don’t retroactively apply sensitivity labels to emails already stored in Exchange Online mailboxes. Auto-labeling primarily applies to SharePoint/OneDrive content and to emails during send/receive or when they are modified. Similarly, eDiscovery and Content Search help locate data but don’t perform continuous classification or automatic labeling of mailbox items.
Recommended alternatives / supported approach Although there isn’t a direct workaround to auto-classify historical emails, you can achieve the compliance objective by combining several Purview capabilities:
Microsoft Purview Data Loss Prevention (DLP): Use DLP policies with SITs to detect sensitive information in Exchange and generate alerts or enforcement actions. This provides ongoing visibility even though labels aren’t applied retroactively.
eDiscovery or Content Search: Run targeted searches to identify older emails that may contain sensitive content and perform review or remediation workflows as required.
Retention policies and retention labels: Implement lifecycle management to ensure emails are retained only for the required regulatory period and automatically deleted afterward.
Exchange mail flow rules / future auto-labeling: Use these for forward-looking protection so that new or modified emails are classified going forward.
Other Purview modules Modules such as Data Classification Analytics or Insider Risk Management provide reporting and activity insights but don’t automatically classify existing mailbox content at rest.
there isn’t currently a Purview feature that fully scans and auto-labels historical Exchange Online emails. The recommended design is to use DLP for detection, eDiscovery for discovery and remediation, and retention policies for lifecycle governance while applying auto-labeling to new email activity moving forward.
Please let us know if you’d like guidance designing a policy approach aligned to your compliance requirements, and we’ll be happy to assist further.
As for other Purview Modules, here are some related resources: