Microsoft Purview Compliance Manager: Proven Lab (2026)

Your Microsoft 365 tenant is either compliant with ISO 27001, GDPR, or NIST right now, or it isn’t. Microsoft Purview Compliance Manager tells you exactly where you stand, what to fix, and how much each fix is worth.

In this guide, you’ll explore Microsoft Purview Compliance Manager from the Overview dashboard through to building a custom regulation template with your own controls. Specifically, you’ll learn:

  • How the Microsoft Purview Compliance Manager compliance score is calculated
  • How to read assessments and understand your improvement actions
  • How to navigate the Regulations library (391 templates)
  • How to create a custom regulation template with your own controls
  • MS-102 exam tips for icrosoft Purview Compliance Manager

What Is Microsoft Purview Compliance Manager?

Microsoft Purview Compliance Manager is a risk assessment dashboard inside the Microsoft Purview compliance portal. It measures how well your Microsoft 365 environment aligns with regulatory standards, GDPR, ISO 27001, NIST 800-53, PCI DSS, and hundreds more, and gives you a prioritized list of actions to improve that alignment.

The central output is a compliance score, a number from 0 to your maximum possible points, expressed as a percentage. It is not a certification. Reaching 100% in Microsoft Purview Compliance Manager does not mean your organization is certified to ISO 27001. It means you have implemented the Microsoft 365 controls that Microsoft recommends for that standard. Third-party auditors and process controls are your responsibility.

What Microsoft Purview Compliance Manager does exceptionally well is tell you which Microsoft 365 settings directly contribute to regulatory compliance and give you step-by-step implementation guidance for each one.


How the Microsoft Purview Compliance Score Works

The compliance score has two components:

ComponentWho Controls ItExample
Your pointsYou, by implementing improvement actionsEnable MFA: +27 points
Microsoft managed pointsMicrosoft automatically applied for platform-level controlsData centre physical security, service encryption

Your score = (Your points achieved + Microsoft-managed points achieved) ÷ Total possible points.

In a typical Microsoft 365 tenant, Microsoft already handles the majority of points automatically. Your points are the gap you need to close through configuration and policy implementation.

Key exam fact: The compliance score is a relative measure of risk reduction, not an absolute compliance certification. Admins sometimes confuse it with a pass/fail audit result — it is neither.


Step-by-Step Lab: Explore Microsoft Purview Compliance Manager

Prerequisites: Compliance Administrator or Global Administrator role. Access to purview.microsoft.com → Compliance Manager.


Step 1: The Overview Dashboard

Navigate to purview.microsoft.com → select Compliance Manager from the left navigation (or from the Solutions menu).

The Overview page is your compliance command center. It shows:

  • Overall compliance score: displayed as a dial and percentage
  • Key improvement actions: the highest-impact actions you haven’t completed yet
  • Solutions that affect your score: breakdown by Microsoft solution (Audit, DLP, eDiscovery, etc.)
Microsoft Purview Compliance Manager Overview page showing compliance score 59 percent with 12559.74 out of 22416 points achieved. Your points 151.74 out of 9915, and Microsoft managed 12408 out of 12501 with Key improvement actions list and Solutions panel showing score contributions
The Microsoft Purview Compliance Manager Overview: your compliance score, top improvement actions, and a solution-by-solution breakdown all on one screen

In this lab tenant, the score shows 59% (13,354.39/22,416 points). Microsoft managed points (12,408/12,501) are nearly complete; the remaining gap is almost entirely in the Your points bucket (946.39/9,915). This is typical of a new or trial tenant where no improvement actions have been implemented yet.

The Solutions that affect your score panel on the right show how many remaining actions exist per solution: Compliance Score (304 points, 28 actions), Audit (79 points, 9 actions), and so on. This tells you where to focus first.

💡 Best Practice: Start with the Solutions that affect your score panel rather than the raw improvement actions list. Find the solution with the highest remaining points and the fewest remaining actions that’s your best ROI for score improvement.


Step 2: Assessments

Click Assessments in the left navigation.

Assessments are the core working unit of Microsoft Purview Compliance Manager. Each assessment maps your environment to a specific regulation or standard, showing you which controls are satisfied and which are outstanding.

Microsoft Purview Compliance Manager Assessments page showing AI Baseline Assessment in progress at 64 percent with 2 of 80 your improvement actions and 96 of 96 Microsoft actions completed, and Data Protection Baseline for Microsoft 365 at 61 percent with 36 of 489 your improvement actions
Two default assessments, AI Baseline and Data Protection Baseline for Microsoft 365, are pre-created in every Compliance Manager tenant

By default, every Compliance Manager tenant includes two assessments:

AssessmentRegulationPurpose
Data Protection Baseline for Microsoft 365Microsoft’s own baselineFoundational data protection controls across M365
AI Baseline AssessmentAI Baseline regulationControls for responsible AI deployment

Notice the columns: Progress (overall %), Your improvement actions (actions you own), Microsoft actions (handled by Microsoft). In the AI Baseline, Microsoft has already completed 96/96 of its actions your 2/80 is the gap.

Click Data Protection Baseline for Microsoft 365 to open the assessment details.

Microsoft Purview Compliance Manager Data Protection Baseline for Microsoft 365 assessment showing 61 percent of assessment actions completed with 937 out of 9301 your points and 12345 out of 12438 Microsoft managed points, and Key improvement actions including Govern global administrative roles and Turn on email scanning for antivirus
Inside an assessment, the progress bar breaks down Microsoft-handled vs. your responsibility actions, with key improvement actions ranked by impact

The assessment detail shows:

  • Progress bar: purple for Microsoft 365 managed actions, dark for remaining
  • Your points achieved: 937/9,301, this is what you’re working on
  • Microsoft managed points: 12,345/12,438, nearly fully handled
  • Key improvement actions: highest-impact items sorted by points

💡 Best Practice: Use the Download as report button (top right of an assessment) to export assessment progress as a PDF. This is useful for compliance evidence packages showing an auditor your current state against a specific standard without giving them portal access.


Step 3: Improvement Actions

Click Improvement actions in the left navigation.

This page lists every recommended action across all your assessments 500 items in this tenant. Each action shows points available, which regulation it satisfies, which solution it belongs to, and its current test status.

Microsoft Purview Compliance Manager Improvement actions page showing 500 items with columns for Improvement action Points Service Regulations Groups, Solutions, Assessments, Categories, Test status, Action type, Assigned to, and Testing type
500 improvement actions across all assessments, filter by Regulation, Solution, Test status, or Category to prioritize.

Use the filters to narrow the list:

  • Regulations: ISO/IEC 27001:2013: see only ISO-relevant actions
  • Test status: None: see actions not yet assessed
  • Categories: Protect information: filter by compliance domain

Click any action to open its detail page.

Microsoft Purview Compliance Manager improvement action Generate and review reports for device compliance showing Owner Assign owner Implementation status Test status None Service Microsoft 365 Testing type Manual Testing source User verified with How to implement guidance using Microsoft Intune admin center
Each improvement action includes how to implement guidance, links to the relevant Microsoft portal, and fields to track owner, test status, and evidence

The improvement action detail page shows:

  • Owner: assign to the responsible admin or team
  • Implementation status: Not implemented, Implemented, Alternative implementation, Planned
  • Test status: None, Passed, Failed (Low/Medium/High risk), Not in scope
  • How to implement: step-by-step guidance from Microsoft
  • Evidence tab: upload screenshots, documents, or notes as audit evidence
  • Related controls tab: Which regulation controls this action

💡 Best Practice: Assign owners to improvement actions before working through them. Unassigned actions are no one’s responsibility assigned actions create accountability. Use the Assign to user button at the top of the Improvement actions list to bulk-assign by category or solution.

⚠️ Common Mistake: Marking an action as “Implemented” without uploading evidence. For any regulatory compliance programme, implementation claims without evidence are worthless. Attach at least one screenshot or policy document to each action you mark as complete.


Step 4: The Regulations Library

Click Regulations in the left navigation.

The Regulations library contains 391 regulation templates organized into categories. Each template defines the controls your organization needs to assess against a specific standard.

Microsoft Purview Compliance Manager Regulations page showing 391 items with columns for Regulation Status Availability Created by Last updated Overarching regulation Created date Activation Services Includes custom and Role type filters including Sub-Service Compliance Readiness with PCI DSS v4.0 SOC 2 ISO IEC 27001 2013 and NIST 800-53 rev.4
391 regulation templates from PCI DSS to ISO 27001 to NIST 800-53 covering every major global compliance standard

The regulation categories:

CategoryDescriptionExamples
Sub-Service Compliance ReadinessPre-deployed, always activePCI DSS v4.0, SOC 2, ISO/IEC 27001:2013, NIST 800-53
Included templatesFree, always availableData Protection Baseline, AI Baseline
Premium AI templatesRequires premium licenceNIST AI RMF, ISO/IEC 23894, EU AI Act
Premium templatesRequires a regulation license (381 total)GDPR, HIPAA, APRA CPS 234, hundreds more

The Availability column shows whether you’ve activated a template. Free templates can be activated immediately. Premium templates consume a regulation license (shown at the top of the page as “Purchased regulation licenses used”).


Step 5: View a Regulation Detail

Click ISO/IEC 27001:2013 from the Regulations list to see what’s inside.

Microsoft Purview Compliance Manager ISO IEC 27001 2013 regulation page showing All controls 233 items with Access Control family showing A.9.1.1 Access control policy A.9.1.2 Access to networks A.9.2.1 User registration and de-registration A.9.2.2 User access provisioning A.9.2.3 Management of privileged access rights
ISO 27001:2013 contains 233 controls across families, including Access Control — each maps to specific Microsoft 365 configurations
Microsoft Purview Compliance Manager ISO IEC 27001 2013 regulation Microsoft actions tab showing 347 items with Feature Action column and Azure Control Framework ID column including ACF1000 Access Control Policy and Procedures ACF1001 Reviewing Policy ACF1013 Account Management Automated System
Microsoft actions show what Microsoft handles automatically: 347 platform-level controls already managed for ISO 27001 compliance

The regulation details have two tabs: All controls and Microsoft actions:

  • All controls (233): every ISO 27001 control, grouped by control family (Access Control, Cryptography, Physical security, etc.), each with its ISO control ID (A.9.1.1, A.9.2.3, etc.)
  • Microsoft actions (347): Microsoft’s own actions mapped to ISO controls, showing what Microsoft manages on your behalf in the Azure Control Framework

Best Practices for Microsoft Purview Compliance Manager

  • Assign improvement actions before you start. Actions with no owner are never completed. Spend 30 minutes assigning categories to team members before anyone touches a single action.
  • Upload evidence for every action you mark as implemented. A screenshot of the configured setting, a policy document, or an export from the admin portal. Unsubstantiated “Implemented” markings fail audits.
  • Use Download as a report quarterly. Export assessment PDFs at the end of each quarter. Build a compliance evidence library that shows your trajectory over time. Auditors want to see improvement, not just a current score.
  • Don’t chase the score. 500 improvement actions exist. Focus on the ones that actually reduce your organization’s real risk, not the 27-point actions that require decommissioning legacy protocols your users don’t use anyway.
  • Check the regulation license usage. Premium regulation templates consume licenses. Don’t activate 20 premium templates you won’t actually use; you have a fixed number of purchased licenses.

MS-102 Exam Tips

Scenario you’ll likely see: “An organisation wants to measure their Microsoft 365 environment’s alignment with ISO 27001 controls and track improvement actions assigned to specific administrators. What feature should they use?”

Correct answer: Microsoft Purview Compliance Manager — create an ISO 27001 assessment, assign improvement actions to admins, track progress in the dashboard Not: Microsoft Secure Score (Secure Score measures security posture, not regulatory compliance) | Compliance Manager reports (reports are outputs, not the tracking tool itself) | Microsoft Defender for Cloud (cloud workload security, not M365 compliance assessments)

Remember: Microsoft Purview Compliance Manager = compliance posture. Secure Score = security posture. Both have scores. Both live in the Microsoft ecosystem. The exam distinguishes them based on context regulatory standards vs security best practices.

Also know for the exam:

  • Compliance score = your points + Microsoft managed points ÷ total possible
  • A high score does not mean your organisation is certified to any standard
  • Assessments map to regulations; Improvement actions are the tasks inside assessments
  • You can create custom templates from a blank start or by uploading a PDF
  • Microsoft managed points are handled automatically — you cannot fail them
  • Premium templates require regulation licences; Included templates are free
  • Improvement actions can be assigned to specific users and tracked with evidence

FAQ

Q: What is the difference between the compliance score and Microsoft Secure Score?

A: Microsoft Purview Compliance Manager’s compliance score measures your alignment with regulatory standards (ISO 27001, GDPR, NIST, etc.) it is about legal and regulatory risk. Microsoft Secure Score measures your security configuration against Microsoft’s security best practices — it is about attack surface reduction. Both use a points system, but they measure different things and live in different portals.

Q: Does a 100% compliance score in Microsoft Purview Compliance Manager mean my organization is certified?

A: No. The compliance score reflects how well your Microsoft 365 configuration aligns with a standard’s requirements, as interpreted by Microsoft. Actual certifications (ISO 27001, SOC 2, PCI DSS) require third-party audits, process documentation, and operational controls that Microsoft Purview Compliance Manager cannot verify. The score is a useful indicator and audit preparation tool, not a certification.

Q: How often does the compliance score update?

A: Improvement action scores update within 24 hours of a configuration change in Microsoft 365. Microsoft managed points update continuously. The overall score refreshes daily. If you implement a change and the score doesn’t update immediately, wait 24 hours before investigating.

Q: Can I create an assessment for a regulation not in the Regulations library?

A: Yes, use the custom template feature. Create a blank template, add your controls manually (or upload a PDF of your regulation and let Compliance Manager extract them), publish the template, then create an assessment based on it. This is the path for internal policy frameworks, industry-specific standards, or regulations newer than Microsoft’s library.

Q: Who can see and manage Microsoft Purview Compliance Manager?

A: The Compliance Administrator and Global Administrator roles have full access. The Compliance Data Administrator role can view assessments but has limited editing rights. Organization-specific improvement actions can be assigned to any user they receive a notification and can update their action’s test status and evidence without needing Compliance Administrator rights.


Conclusion

You’ve navigated the full Microsoft Purview Compliance Manager workflow from reading your compliance score and understanding the gap between your points and Microsoft-managed points, through working on improvement actions with evidence, to building a custom regulation template from scratch. These capabilities are tested directly in the MS-102 exam and are equally valuable in production for any organization managing regulatory obligations in Microsoft 365.


Related Posts in the MS-102 Series

Official Microsoft Reference: Get started with Microsoft Purview Compliance Manager, Microsoft Learn

Written by

Lokesh M

Senior Infrastructure Engineer with 10+ years of IT infrastructure experience across Microsoft 365 Administration, Microsoft Entra ID, Microsoft Intune, Microsoft Security, Windows Server, Active Directory, Azure, and enterprise infrastructure.

Focus areas: Microsoft Certifications, Microsoft 365, Windows Server, Azure, Microsoft Security, Endpoint Management, and Enterprise IT.

TechCertGuide is built from hands-on lab experience, enterprise administration, and official Microsoft documentation to help IT professionals understand concepts before implementing them.

1 thought on “Microsoft Purview Compliance Manager: Proven Lab (2026)”

Leave a Comment