Purview Communication Compliance
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Communication Compliance reviews emails, Teams chats, and Viva Engage messages against policy. Here's the model.
4 min read
Share as imagePNGMicrosoft Purview Communication Compliance is the policy engine for reviewing internal communications — emails, Teams chats, channel messages, and Viva Engage posts — against rules that detect harassment, regulatory violations, insider threats, or other policy concerns.
Communication Compliance is one of the Purview conduct solutions in What is Microsoft Purview, next to Insider Risk Management and Information Barriers; it overlaps with DLP on sensitive-information detection and depends on Teams chat retention for what it can review.
What it's for
The classic use cases:
- Financial services supervision — regulators (SEC, FINRA, FCA) require firms to review broker-dealer communications for misconduct.
- Code of conduct enforcement — detection of harassment, threats, discriminatory language.
- Information protection — sensitive data shared in chat that bypasses other controls.
- Internal investigations — suspected leaks, conflict-of-interest, regulatory violations.
It's different from eDiscovery: eDiscovery responds to specific legal requests; Communication Compliance runs continuously against defined patterns.
How a policy works
A policy bundles:
- Locations: Exchange mailboxes, Teams chats and channels, Viva Engage, third-party connected data via the Purview Communication Compliance connector library.
- Users: who's in scope (often a specific function, like all traders).
- Reviewers: who triages alerts.
- Conditions: pre-built templates (offensive language, regulatory keywords, money laundering patterns) and custom keyword lists and sensitive information types.
- Sample rate: random sampling for supervisory reviews where 100% review isn't required.
- Actions: route to reviewer queue, alert managers, escalate.
Pre-built classifiers
Microsoft ships trainable ML classifiers for:
- Offensive language and harassment.
- Threats.
- Discrimination.
- Regulatory compliance — financial misconduct, money laundering, customer complaints, market manipulation.
- Confidential information disclosure.
- Adult/racy content.
You can combine classifiers with custom keyword lists (your firm's own restricted terms).
Reviewer workflow
Reviewers see a queue of flagged messages with context — the surrounding conversation, the user's history, the policy that triggered. For each message they choose an outcome: Resolved, Escalated, Tagged with notes. Outcomes feed into reporting.
Privacy and ethics
Like Insider Risk Management, Communication Compliance has built-in privacy controls:
- Anonymised display by default.
- Role separation — reviewers can see content, escalation roles can see identities.
- Audit logs of every reviewer action.
Set policies with HR, Legal, and (in regulated industries) Compliance officer sign-off. Employees should be informed of communication monitoring as part of acceptable-use policies.
Role groups and separation of duties
Communication Compliance enforces its privacy model through dedicated Purview role groups, not the general Compliance Administrator role:
- Communication Compliance Admins — create and configure policies, but don't have to be reviewers.
- Communication Compliance Analysts — see flagged content pseudonymised; can resolve, tag, or escalate.
- Communication Compliance Investigators — can unmask the user identity behind an alert once it's escalated.
- Communication Compliance Viewers — read-only access to reports and dashboards, no content access.
Splitting these across different people (an HR analyst as Analyst, a named Legal or HR lead as Investigator) is what makes the "presumption of innocence" design actually hold — no single person can both triage anonymously and unmask at will without a second role assignment and a logged action trail.
Piloting a policy without drowning reviewers
The single most common rollout mistake is turning on a broad classifier (e.g., "Threat" or "Harassment") tenant-wide on day one. A few guardrails that keep the reviewer queue usable:
- Scope narrow first — one department or one classifier, not all classifiers across the whole tenant.
- Use sample rate for high-volume, lower-risk populations (e.g., 10% of all Teams chat in a large call-centre org) rather than reviewing everything.
- Watch the false-positive rate for the first two weeks before adding more classifiers or expanding scope — a queue reviewers can't keep up with erodes the whole programme's credibility.
- Combine keyword lists with classifiers rather than keywords alone; bare keyword matches on common words generate far more noise than the trainable classifiers, which weigh context.
Copilot and AI interactions as a location
Communication Compliance can review prompts and responses from Microsoft 365 Copilot and other AI apps as a distinct location type, using the same classifier and reviewer plumbing as chat and email. This closes a gap DLP alone doesn't cover well: DLP can block a file from being shared, but a user can still paste sensitive content into a Copilot prompt or have Copilot summarise something it shouldn't have surfaced. Adding AI interactions as a monitored location is increasingly a prerequisite compliance teams ask for before a wider Copilot rollout, alongside the labelling work in sensitivity labels.
Licensing
Communication Compliance requires Microsoft 365 E5 or the Purview Communication Compliance standalone licence (per-user).
When you need it
Mandatory in regulated financial services and increasingly common in healthcare and legal. Optional but useful in any organisation with strong code-of-conduct enforcement. Overkill in small businesses without specific obligations.
When deployed, treat it as an HR/Legal-owned process, not an IT one. Tooling is the easy part.
Frequently asked questions
- What is Communication Compliance in Purview?
- A solution that scans Teams, Exchange, Viva Engage, and connected third-party messages against policies — harassment, threats, sensitive information sharing, regulatory conduct — and routes matches to reviewers with remediation actions and an audit trail.
- How is it different from DLP?
- DLP acts on sensitive information at the moment of sending or sharing to prevent leaks. Communication Compliance reviews messages after the fact for conduct and policy violations, with human reviewers and case management. They overlap on sensitive information detection but serve different owners — security versus HR/compliance.
- Which licence includes Communication Compliance?
- Microsoft 365 E5, E5 Compliance, or the Insider Risk Management add-on. Users whose communications are monitored need the licence; reviewers need the Purview role group but not necessarily the licence themselves. Office 365 E5 also includes it.
- Does Communication Compliance review Copilot prompts and responses?
- Yes — interactions with Microsoft 365 Copilot and other supported AI apps can be added as a location, so a policy can flag a user pasting sensitive data into a Copilot prompt or a response surfacing something it shouldn't. It's the same reviewer workflow as chat and email, just a different location type.
- Who can see the content behind a flagged message?
- Nobody, by default, until it's necessary. Reviewers first see a pseudonymised alert (User 47, not a name); only after opening the item — an action that's itself logged — does the identity resolve, and only for role groups scoped to see it. Escalation to an investigator or a named individual requires a separate, more privileged role.
Was this useful?
Spot something wrong or want a topic covered? Send it through the contact form.