{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Microsoft Purview Integration","description":"Control the power of AI Agents in runtime.","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"microsoft-purview-integration","__idx":0},"children":["Microsoft Purview Integration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Connect Microsoft Purview to Capsule Security to enrich your AI data-source inventory with authoritative sensitivity labels and to reveal which identities can reach classified content that AI agents use."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This integration connects to the Microsoft Graph API to read your organization's Microsoft Purview Information Protection data. Instead of inferring how sensitive a data source is, Capsule attaches the sensitivity labels your organization already applies through Purview to the data sources AI agents access - turning \"an agent reads this file\" into \"an agent reads this ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Highly Confidential"]}," file.\""]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The integration syncs:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Sensitivity labels"]}," - Your tenant's Purview sensitivity-label catalog (names and priority order)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Data-source classifications"]}," - Labels applied to SharePoint and OneDrive files that Capsule already tracks as AI data sources (for example, files referenced in Microsoft 365 Copilot interactions)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identity access"]}," - Which users can reach labeled content, resolved from file permissions including group membership"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This is an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["enrichment"]}," integration: it does not create new inventory items. It layers classification onto data sources discovered by your other integrations, so it is most valuable alongside connectors like Microsoft 365 Copilot."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":2},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you begin, ensure you have:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Purview Information Protection"]}," sensitivity labels published in your tenant, with labels applied to content (manual labeling requires Microsoft 365 E3; automatic labeling requires E5)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Entra ID"]}," account with ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Global Administrator"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application Administrator"]}," role (to grant admin consent)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Capsule Security"]}," account with admin access"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-1-configure-the-integration-in-capsule","__idx":3},"children":["Step 1: Configure the Integration in Capsule"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Capsule Security"]}," portal"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Integrations"]}," in the left sidebar"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Find the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Purview"]}," card and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Set up Integration"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect with Microsoft"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["You'll be redirected to Microsoft's sign-in page"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-2-grant-admin-consent","__idx":4},"children":["Step 2: Grant Admin Consent"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Authorize the Capsule application to read your Purview sensitivity data."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"steps","__idx":5},"children":["Steps"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sign in with your Microsoft Entra ID account that has the required administrator role (see Prerequisites)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Review the permissions requested by the Capsule application"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Accept"]}," to grant admin consent for your organization"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"permissions","__idx":6},"children":["Permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Capsule application requires the following ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["application-level"]}," permissions on the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Graph"]}," API. All permissions are read-only."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Permission"},"children":["Permission"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SensitivityLabels.Read.All"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Application"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read the tenant's sensitivity-label catalog"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Files.Read.All"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Application"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read file metadata and extract applied sensitivity labels"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Sites.Read.All"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Application"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Enumerate SharePoint sites and drives"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Group.Read.All"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Application"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Expand group membership for file-access resolution"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Directory.Read.All"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Application"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Resolve users and groups in the directory"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Admin consent must be granted by a Global Administrator or Application Administrator. Once granted, the permissions apply tenant-wide."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"step-3-automatic-discovery-and-sync","__idx":7},"children":["Step 3: Automatic Discovery and Sync"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After you grant consent, Capsule automatically begins enriching your inventory."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"what-happens","__idx":8},"children":["What happens"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The tenant's sensitivity-label catalog is synced and kept up to date"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Capsule scans the SharePoint and OneDrive locations that host data sources already in your inventory, and extracts the sensitivity label applied to each file"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Label changes and file deletions are picked up incrementally on a recurring schedule"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["For labeled files, Capsule records which identities can access them - both direct permissions and access through group membership"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Classifications attach to matching data sources automatically, including data sources discovered ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["after"]}," the classification was ingested"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["No manual configuration is needed. Content is never read or stored - only label and permission metadata."]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"after-setup","__idx":9},"children":["After Setup"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once the integration is configured:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Initial sync begins automatically and may take several minutes depending on how many data sources are in scope"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Sensitivity labels appear on data sources in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Inventory > Data Sources"]}," - open a data source to see its label and classification chips"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Files protected with double-key encryption cannot be read and are skipped"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"troubleshooting","__idx":10},"children":["Troubleshooting"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"common-issues","__idx":11},"children":["Common Issues"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Consent failed or permissions error"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Verify your account has ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Global Administrator"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Application Administrator"]}," role in Microsoft Entra ID"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Ensure all five permissions listed above are granted and admin consent has been given"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No labels appearing on data sources"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm sensitivity labels are published and actually applied to files in your tenant"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Labels only appear on data sources Capsule already tracks - connect an AI platform integration (for example, Microsoft 365 Copilot) so there are data sources to enrich"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Allow several minutes after the first sync completes"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Labels missing for specific files"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Files protected with double-key encryption cannot be inspected and are skipped"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Very long file URLs (over 255 characters) are not matched"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connection test fails"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Ensure the Entra application has the required permissions granted with admin consent"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Verify Microsoft Purview Information Protection is active in your tenant"]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"support","__idx":12},"children":["Support"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For help with this integration:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Email"]},": support@capsule.security"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Include"]},": Your organization ID, Entra tenant ID, and any error messages"]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"references","__idx":13},"children":["References"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/purview/information-protection"},"children":["Microsoft Purview Information Protection"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/purview/sensitivity-labels"},"children":["Sensitivity labels overview"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/graph/api/driveitem-extractsensitivitylabels"},"children":["Microsoft Graph - extractSensitivityLabels"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/grant-admin-consent"},"children":["Microsoft Entra ID application permissions"]}]}]}]},"headings":[{"value":"Microsoft Purview Integration","id":"microsoft-purview-integration","depth":1},{"value":"Overview","id":"overview","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Step 1: Configure the Integration in Capsule","id":"step-1-configure-the-integration-in-capsule","depth":2},{"value":"Step 2: Grant Admin Consent","id":"step-2-grant-admin-consent","depth":2},{"value":"Steps","id":"steps","depth":3},{"value":"Permissions","id":"permissions","depth":3},{"value":"Step 3: Automatic Discovery and Sync","id":"step-3-automatic-discovery-and-sync","depth":2},{"value":"What happens","id":"what-happens","depth":3},{"value":"After Setup","id":"after-setup","depth":2},{"value":"Troubleshooting","id":"troubleshooting","depth":2},{"value":"Common Issues","id":"common-issues","depth":3},{"value":"Support","id":"support","depth":2},{"value":"References","id":"references","depth":2}],"frontmatter":{"seo":{"title":"Microsoft Purview Integration"}},"lastModified":"2026-07-22T15:37:08.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/microsoft-purview","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}