Compliance Manager Overview

Earn 25 points (50 with Pro) in two steps

  1. ① Read through the lesson — each section gets a ✓ as you scroll through it.
  2. ② When every section has a ✓, tap Complete lesson.

0 of 11 read · keep scrolling

✦ See fewer ads and earn double points — 50 a lesson instead of 25 — with Pro

Compliance Manager Overview: Navigating Data Governance in Microsoft 365

Introduction: Why Compliance Matters in the Modern Workspace

In the contemporary digital landscape, organizations generate, store, and share massive volumes of data every single day. This data is the lifeblood of business operations, containing everything from intellectual property and financial records to sensitive customer personal information. As the complexity of this data grows, so does the regulatory burden placed on organizations. Governments and industry bodies worldwide have introduced stringent regulations—such as GDPR in Europe, HIPAA in the United States, and various regional privacy laws—to ensure that this data is handled with appropriate care and security.

For organizations utilizing Microsoft 365, the challenge lies in translating these high-level regulatory requirements into concrete, technical configurations. This is where the Microsoft Purview Compliance Manager becomes essential. Compliance Manager is not merely a checklist; it is a comprehensive, risk-based assessment tool that helps organizations track, implement, and monitor compliance across their cloud environment. It acts as a bridge between the legal department, which defines policy, and the IT department, which implements the technical controls necessary to adhere to those policies.

Understanding and effectively utilizing Compliance Manager is critical because it moves an organization from a reactive posture—where they scramble to explain how they handle data after a request or an audit—to a proactive posture, where compliance is built into the fabric of the digital workspace. By mastering this tool, you ensure that your organization can demonstrate its commitment to data protection, reduce the risk of costly data breaches, and avoid significant legal or financial penalties associated with non-compliance.


Not read yet

Understanding the Core Architecture of Compliance Manager

At its heart, Compliance Manager functions by organizing the complex world of regulatory requirements into a structured framework. It operates on three primary pillars: assessments, controls, and improvement actions. Understanding how these relate to one another is the foundation for managing any compliance program within Microsoft 365.

Assessments

An assessment is a grouping of controls that are specific to a particular regulation or industry standard. For example, you might create an assessment for "ISO 27001" or "GDPR." When you start an assessment, Compliance Manager pulls in the necessary requirements that you must satisfy to be compliant with that specific standard. These assessments are pre-built by Microsoft, which saves your team the immense effort of mapping thousands of regulatory clauses to specific technical settings.

Controls

Controls are the individual requirements within an assessment. A control might be a technical setting, such as "Enable multi-factor authentication," or it might be a process-based requirement, such as "Conduct annual security awareness training." Compliance Manager categorizes these into "Microsoft-managed controls" and "Customer-managed controls." Microsoft-managed controls are those where Microsoft takes responsibility for the underlying infrastructure, while customer-managed controls are the configurations that you, as the administrator, are responsible for implementing.

Improvement Actions

Improvement actions are the actual tasks that you must perform to satisfy a control. If a control requires that you restrict access to sensitive files, the improvement action might be to "Configure sensitivity labels for document encryption." This is the most practical part of the tool, as it provides step-by-step guidance on how to make the necessary changes in your Microsoft 365 tenant to meet the control's requirements.

Callout: The Shared Responsibility Model It is vital to understand that moving to the cloud does not absolve an organization of its compliance responsibilities. The "Shared Responsibility Model" dictates that while Microsoft manages the physical security of the data centers and the underlying hardware, the customer is responsible for the data itself, access management, and the configuration of the applications. Compliance Manager makes this distinction clear by showing you exactly which controls are handled by Microsoft and which are firmly in your court.


Not read yet

Step-by-Step: Setting Up Your First Assessment

To get started with Compliance Manager, you need to navigate to the Microsoft Purview compliance portal. Once inside, you will find the Compliance Manager dashboard, which provides a high-level view of your current compliance score. This score is a representation of how well you are performing against the regulations you have chosen to track.

Phase 1: Selecting Your Template

  1. Navigate to the Compliance Manager section in the Microsoft Purview portal.
  2. Select Assessments from the menu.
  3. Click on Add assessment.
  4. You will be presented with a list of templates. These templates range from global standards like ISO 27001 to region-specific requirements like the Australian Privacy Principles.
  5. Choose a template based on your organization's industry or geographic location.

Phase 2: Defining the Assessment Scope

After selecting a template, you must define the scope. This involves identifying the specific Microsoft 365 services that are relevant to your compliance goals. If you are only using Exchange Online and SharePoint Online, you should exclude services like Microsoft Teams or Yammer from that specific assessment to avoid cluttering your dashboard with irrelevant controls.

Phase 3: Assigning Improvement Actions

Once the assessment is created, you will see a list of controls. Click into a control to view the assigned improvement actions. You can assign these actions to specific members of your team. For example, you might assign an action related to "Password Complexity" to your Identity and Access Management team, while assigning a "Data Retention" action to your Legal or Records Management team.

Tip: Start Small It is a common mistake to try to tackle every single regulation at once. This leads to "compliance fatigue" and an overwhelming dashboard that is difficult to manage. Start with one core assessment—like the "Data Protection Baseline"—to get familiar with the workflow before expanding into more complex, niche regulatory frameworks.


Not read yet

The Role of Improvement Actions in Technical Governance

Improvement actions are the bridge between policy and technical execution. Each improvement action provides a detailed description of the risk, the recommended implementation steps, and the evidence required to verify compliance.

Example: Implementing Data Loss Prevention (DLP)

Imagine your organization needs to comply with a regulation that requires the protection of credit card numbers. The relevant control in Compliance Manager will point you toward an improvement action for Data Loss Prevention.

  1. Review the Guidance: The improvement action will explain why this is necessary (e.g., "Prevent unauthorized transmission of sensitive financial data").
  2. Technical Configuration: You will be provided with a direct link to the Data Loss Prevention policy section in the Purview portal.
  3. Execution: You create a policy that detects "Credit Card Numbers" and blocks the action if a user attempts to share this data externally.
  4. Evidence Collection: Once the policy is active, you can attach a screenshot of your policy configuration or a log file showing the policy in action directly to the improvement action in Compliance Manager. This serves as your audit trail.

Automating Evidence Collection

One of the most powerful features of Compliance Manager is its ability to automatically update your compliance score. When you implement a technical control—such as turning on Multi-Factor Authentication (MFA) for all users—the system detects this configuration change. It then automatically marks the corresponding improvement action as "Completed" and increases your score. This reduces the manual labor involved in gathering evidence for internal or external audits.


Not read yet

Best Practices for Compliance Management

Managing compliance is an ongoing process, not a one-time project. To be successful, you must integrate Compliance Manager into your standard operational procedures.

  • Assign Clear Ownership: Ensure every improvement action has a designated owner. If everyone is responsible, then no one is responsible. Use the assignment feature in the portal to hold departments accountable.
  • Establish a Regular Review Cadence: Schedule monthly or quarterly reviews of your compliance score. Use these meetings to discuss any dips in the score and identify which controls need immediate attention.
  • Keep Documentation Centralized: Use the document upload feature within each improvement action to store your policies, procedures, and evidence. This creates a single source of truth that you can provide to auditors.
  • Leverage Microsoft’s Guidance: Do not try to interpret complex regulations on your own. Use the guidance provided in the templates, which is written by legal and compliance experts, to understand exactly what the regulation requires.

Warning: Avoid Over-Engineering It is easy to get caught up in enabling every possible security feature. However, overly restrictive policies can hinder productivity. Always balance your compliance goals with the business's need to collaborate effectively. Test your configurations in a pilot group before applying them to the entire organization.


Not read yet

Common Pitfalls and How to Avoid Them

Even with a powerful tool like Compliance Manager, organizations often fall into traps that undermine their efforts.

The "Check-the-Box" Mentality

The most significant danger is treating compliance as a box-ticking exercise. If you simply turn on a setting to get a high score without understanding its impact on your workflows, you may end up with a system that is secure but unusable. Always evaluate the business impact of a control before implementing it.

Ignoring Non-Technical Controls

Many organizations focus entirely on the technical settings—the "easy" wins—and ignore the process-based requirements. A regulation might require you to have a written policy for incident response. If you don't have that document, you are not compliant, regardless of how robust your technical firewall is. Remember to use the "Notes" and "Document" fields in Compliance Manager to address these non-technical aspects.

Siloed Communication

Compliance is a cross-functional effort. If IT is working in a vacuum, they will implement controls that may not align with the legal department's interpretation of a regulation. Ensure that stakeholders from Legal, HR, Risk, and IT are all involved in the assessment process.


Not read yet

Comparison: Manual vs. Automated Governance

Feature Manual Governance Compliance Manager
Evidence Gathering Spreadsheet-based, time-consuming Automated tracking and status updates
Visibility Fragmented, hard to track progress Centralized dashboard, real-time scoring
Regulatory Knowledge Requires specialized legal research Pre-built, updated templates from experts
Accountability Difficult to track ownership Direct assignment to owners with notifications
Audit Readiness High effort to compile reports One-click report generation for auditors

Utilizing PowerShell for Compliance Auditing

While the portal is excellent for management, sometimes you need to pull data programmatically to perform deeper analysis or to integrate compliance data into your own custom reporting tools. You can use the Microsoft Graph API or the Exchange Online PowerShell module to inspect compliance-related configurations.

Code Example: Checking for MFA Status

Ensuring that Multi-Factor Authentication is enabled is a core requirement for almost every compliance standard. You can use the following PowerShell snippet to check the MFA status of your users.

# Connect to Microsoft Graph
Connect-MgGraph -Scopes "User.Read.All"

# Retrieve users and their authentication methods
$users = Get-MgUser -All -Property "DisplayName, UserPrincipalName, StrongAuthenticationRequirements"

foreach ($user in $users) {
    $mfaStatus = if ($user.StrongAuthenticationRequirements.Count -gt 0) { "Enabled" } else { "Disabled" }
    Write-Host "User: $($user.UserPrincipalName) - MFA Status: $mfaStatus"
}

Explanation: This script connects to the Microsoft Graph API, pulls a list of all users, and checks the StrongAuthenticationRequirements property. If the count is greater than zero, it implies that MFA is configured for that user. You can export this data to a CSV file and upload it as evidence to the relevant improvement action in Compliance Manager.


Not read yet

Integrating Compliance into the Development Lifecycle

If your organization develops custom applications or utilizes Power Platform, you must ensure that these solutions also adhere to your compliance standards. Compliance Manager provides guidance on how to manage these custom environments.

Power Platform Governance

When building apps, developers often have access to data connectors that could potentially leak sensitive information. You should:

  1. Restrict Connectors: Use Data Loss Prevention policies in the Power Platform Admin Center to restrict the use of certain connectors.
  2. Monitor Activity: Use the Microsoft 365 audit logs to track who is creating apps and what data they are accessing.
  3. Map to Controls: Link these administrative actions to the controls in Compliance Manager that require "Third-party application governance."

The Audit Experience: Preparing for the Big Day

Eventually, you will be audited. Whether it is an internal audit or a formal regulatory inspection, the goal of Compliance Manager is to make this process as painless as possible.

Preparing the "Evidence Locker"

In the months leading up to an audit, use the "Evidence" tab within your assessments to organize all your documentation. A well-organized evidence locker should include:

  • Policy Documents: Current versions of your security and privacy policies.
  • Configuration Snapshots: Screenshots or exported configuration files showing that security settings are active.
  • Training Records: Documentation showing that employees have completed mandatory training.
  • Access Reviews: Reports showing that you have performed periodic reviews of user permissions.

Generating Reports

Compliance Manager allows you to export your assessment data into a report format. This report provides a summary of your compliance posture, the status of individual controls, and the evidence you have collected. This is the primary document you will provide to your auditors to demonstrate your adherence to the chosen regulatory standards.

Callout: The Power of Continuous Monitoring The biggest mistake organizations make is treating compliance as a point-in-time event. Auditors prefer to see a history of continuous monitoring. By maintaining your Compliance Manager dashboard throughout the year, you demonstrate that compliance is a core part of your operational culture, which significantly increases auditor confidence.


Not read yet

Advanced Topics: Customizing Templates and Controls

While the pre-built templates are comprehensive, you may find that your organization has unique requirements or internal policies that aren't covered by standard regulations.

Creating Custom Controls

If you have a internal security requirement—for example, "All laptops must have disk encryption enabled"—you can create a custom control.

  1. Go to Compliance Manager > Assessments.
  2. Select your assessment and click Edit.
  3. Choose Create custom control.
  4. Define the requirement, the description, and the associated risk.
  5. Assign it to the relevant team.

This allows you to treat your internal company policies with the same rigor as external regulatory requirements, ensuring that nothing falls through the cracks.

Modifying Existing Controls

If a specific regulatory control does not perfectly align with how your organization operates, you can modify the implementation guidance or the assessment criteria. However, be cautious when doing this. Always ensure that your modifications still meet the spirit of the original regulation. If you are unsure, consult with your legal or compliance officers before making changes to the technical criteria of a control.


Not read yet

Addressing Common Questions (FAQ)

Is Compliance Manager free?

Compliance Manager is included in most enterprise Microsoft 365 licenses, but some advanced features—like premium assessment templates—may require additional licensing, such as the Microsoft Purview Compliance Manager Premium subscription.

Does Compliance Manager guarantee I am compliant?

No. Compliance Manager is a tool to help you manage and track your compliance, but it cannot make you compliant on its own. You are still responsible for the actual implementation, process management, and legal interpretation of the regulations.

How often should I update my assessments?

You should review your assessments whenever there is a major change in your IT environment, a change in the regulatory landscape, or at least annually. If your organization undergoes a significant merger or acquisition, you should perform an immediate review of all your assessments.

Can I share my compliance status with external partners?

You can export reports from Compliance Manager to share with auditors or partners. However, be mindful of the information contained in these reports. They may reveal technical details about your security configuration that you might not want to disclose to unauthorized parties.


Not read yet

Key Takeaways for Compliance Professionals

  1. Centralize Compliance Efforts: Use the Compliance Manager dashboard as your single source of truth. Moving away from scattered spreadsheets and emails is the first step toward effective governance.
  2. Prioritize Risk-Based Action: Use the risk scores provided in the tool to focus your efforts on the controls that offer the most protection against the highest-impact threats.
  3. Automate Where Possible: Leverage the automated evidence collection features to reduce the administrative burden on your IT team and ensure that your compliance status is always current.
  4. Foster Cross-Departmental Collaboration: Compliance is a shared responsibility. Ensure that Legal, IT, HR, and Risk departments are all involved in the assessment and implementation process.
  5. View Compliance as a Cycle, Not a Destination: Regulations change, and your business evolves. Treat compliance as an ongoing process of monitoring, adjusting, and improving.
  6. Maintain Rigorous Documentation: An audit is only as good as the evidence you provide. Keep your "evidence locker" updated with current policies, configuration logs, and records of training.
  7. Start Small and Scale: Don't let the scope of global regulations intimidate you. Begin with a baseline, master the workflow, and then expand your program as your organization matures.

By following these principles and deeply engaging with the features of Microsoft Purview Compliance Manager, you can transform compliance from a source of friction into a strategic advantage. You will be better positioned to protect your organization's data, respond to inquiries, and navigate the complex regulatory world with confidence and clarity.

Not read yet

Each section gets a ✓ as you scroll through it. Tap the button to jump to the next one.