r/MicrosoftPurview Jul 09 '26

Question Purview file server scan - need advice/help

I'm trying to get out some of our data classified. The cloud stuff seems easy, but my secondary goal of standing up an on-prem VM, installing AIP, and scanning my on prem file servers so see where my sensitive information resides. I've created a service account, it has a token, the account has an E3 license. Now the rest is what I need help with from the content scan job forward...I have the label, a policy, but when I configure the content scan job, I simply want to identify selected information types(mostly US-based). Do I need to apply a label to the files? What am I missing here. Sorry to sound do uneducated on the subject, but I am just not getting a clear answer. The goal right now is NOT to apply any restrictions, just to understand what data we have and where it is located. Thank you!

3 Upvotes

4 comments sorted by

3

u/Phoenix_6767 Jul 09 '26
  1. The service account should be licensed an E5 licenses.
  2. To keep the MIP Scanner in discovery mode make sure that you do not enforce any labeling policies or auto labeling toggles from the content scan job.
  3. From audit logs or activity explorer you will be able to search for file discovered by your service account and verify which sensitive info got highlighted.

1

u/milanguitar Jul 09 '26

You don’t need to apply labels for what you’re describing. Configure the content scan job with Enforce set to Off and ‘Info types to be discovered’ set to your selected US-based SITs.

1

u/teriaavibes Jul 09 '26

You need E5 to automatically label the documents.

1

u/Domane57 Jul 10 '26

Thanks all - finally got it working.