Orientation skill for the Microsoft Purview data security, governance, and compliance suite.

MITAuto-check passedData & Analytics

Install Purview General

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill purview-general -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills purview-general --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/purview-general .claude/skills/purview-general && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
purview-general
GitHub stars
175
Token cost
~2.4k tokens
SKILL.md length
1,017 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Orientation skill for the Microsoft Purview data security, governance, and compliance suite.

  • Works in 5 steps: Discovery first — Run the Content… → Confirm licensing before designing —… → Confirm roles, least privilege — Purview… → …
  • Tasks that involve Data governance
  • SKILL.md covers When to use, Map the goal to a solution, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Purview General is an agent skill from vinayaklatthe/microsoft-security-skills. Orientation skill for the Microsoft Purview data security, governance, and compliance suite. Helps choose the right Purview solution for a goal and understand the unified portal, roles, and licensing model. WHEN: Microsoft Purview overview, which Purview solution, Purview portal, data governance vs data security vs compliance, Purview roles and permissions, where to start with Purview, Purview licensing, I do not know which Purview feature to use, what does Purview cover, getting started with Purview, Purview…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Data governance. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Tasks that involve Data governance

Example prompts

  • “/purview-general”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Discovery first — Run the Content Explorer and Activity Explorer in the Purview
  2. Confirm licensing before designing — Many capabilities are gated. Check before promising
  3. Confirm roles, least privilege — Purview has its own role groups under
  4. Sequence the rollout — Build maturity in this order; each layer assumes the previous.
  5. Pilot before tenant-wide — Every Purview enforcement (DLP block, auto-label, retention

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Purview General loads about 2.4k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 1,017 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 1,017 words, ~2,359 tokens.

Download SKILL.mdSave it as .claude/skills/purview-general/SKILL.md (or your agent's skills folder).
name
purview-general
description
Orientation skill for the Microsoft Purview data security, governance, and compliance suite. Helps choose the right Purview solution for a goal and understand the unified portal, roles, and licensing model. WHEN: Microsoft Purview overview, which Purview solution, Purview portal, data governance vs data security vs compliance, Purview roles and permissions, where to start with Purview, Purview licensing, I do not know which Purview feature to use, what does Purview cover, getting started with Purview, Purview product overview, which compliance tool do I need. Use this skill first for Purview orientation, then follow up with the specific skill for your use case.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Purview (Overview)

Microsoft Purview is a unified suite for data security, data governance, and risk & compliance, managed from the Microsoft Purview portal. This skill is the router: it helps decide which Purview solution (and which deeper skill in this repo) addresses a goal, in what order, and what to verify before building anything.

When to use

Use this skill first when the user is unsure which Purview capability fits, is starting a Purview programme from scratch, is evaluating licensing, or asks "where do I begin". Once the route is clear, hand off to the specific skill (DLP, classification, eDiscovery, etc.).

Do not use this skill when the user already knows the solution they need - go straight to that skill (e.g. purview-dlp-policy, purview-ediscovery).

Map the goal to a solution

Pick the row that matches the question, then load the named skill.

If the goal is...Primary solutionDeeper skill
Find and tag sensitive dataInformation Protection + Data Classification (SITs, trainable classifiers, EDM)purview-data-classification
Stop sensitive data leaving M365, endpoints, or browsersData Loss Preventionpurview-dlp-policy, purview-advanced-dlp
Retain or delete content for legal / regulatory reasonsData Lifecycle Management, Records Managementpurview-data-lifecycle
Catalogue and curate enterprise data estate (lakehouses, DBs, SaaS)Unified Catalog + Data Mappurview-data-catalog, purview-data-map
Detect insider data theft, sabotage, or policy violationsInsider Risk Managementinsider-risk-baseline
Detect harassment, regulated comms, or info leakage in messagingCommunication Compliancepurview-communication-compliance
Run legal hold, collection, review for litigation/HReDiscovery (Premium for advanced)purview-ediscovery
Tenant-wide audit trail of user/admin activityPurview Audit (Standard or Premium)purview-audit
Understand AI prompt data flow (Copilot, custom agents)DSPM for AIpurview-dspm-ai
Fix oversharing before Copilot rolloutSAM + restricted content discovery + sensitivity labelspurview-copilot-oversharing
Govern data used by AI agents (Copilot Studio, custom)Agent security + classification + DLP for AIpurview-agent-365-security
Privacy programme (subject rights, GDPR)Microsoft Priva (separate product)microsoft-priva
Tour Purview for a specific workload (Exchange/SharePoint/Teams)Workload-scoped Purview controlspurview-for-m365
Information governance programme (Know→Protect→Govern→Manage)Cross-solution programmepurview-information-governance

Rule of thumb: if more than one row fits, start with classification - every other Purview capability is weaker without it.

Approach

A Purview programme dies fast when teams skip discovery and jump to enforcement. Follow this order; each step gates the next.

  1. Discovery first — Run the Content Explorer and Activity Explorer in the Purview portal to see what sensitive data already exists and how it moves. Without this, every downstream decision (labels, DLP rules, retention) is guesswork. Verify: Content Explorer shows non-zero items for at least 3 built-in SITs you expect to exist (e.g. credit card, national ID, IBAN).

  2. Confirm licensing before designing — Many capabilities are gated. Check before promising timelines.

    • Included in M365 E3: sensitivity labels (manual), basic DLP for SharePoint/OneDrive/ Exchange, Audit Standard, basic retention.
    • Requires M365 E5 / E5 Compliance: Advanced DLP, Endpoint DLP, Insider Risk, Comms Compliance, Records Management, eDiscovery Premium, Audit Premium, DSPM for AI.
    • Separate add-on/SKU: Microsoft Priva, Purview Data Governance for non-M365 sources.

    Verify: portal banner shows "Advanced features available" for E5; if missing, the feature will appear in UI but block at policy creation.

  3. Confirm roles, least privilege — Purview has its own role groups under Settings → Roles & scopes → Permissions. Do not assign Compliance Administrator or Organization Management wholesale; use scoped groups.

    • DLP work → Compliance Data Administrator + DLP Compliance Management
    • eDiscovery → eDiscovery Manager (not Admin) for case workers
    • Insider Risk → Insider Risk Management Investigators (separate from Analysts for SoD)
    • Read-only review → Compliance Reader

    Verify: a test account in a scoped role can perform the intended action and is blocked from other workloads.

  4. Sequence the rollout — Build maturity in this order; each layer assumes the previous. Classification → Sensitivity labels (manual) → Auto-labelling (simulation mode) → DLP audit-only → DLP block → Lifecycle / retention → Insider Risk → DSPM for AI. Skipping forward (e.g. auto-label without manual adoption first) creates user backlash and false positives that erode trust in the programme.

  5. Pilot before tenant-wide — Every Purview enforcement (DLP block, auto-label, retention delete) should run audit / simulation mode for 7-14 days on a pilot group before going live. Watch override counts and false-positive rates.

Show full SKILL.md (350 more words)Show less

Guardrails

  • Never enable enforcement before classification maturity. Auto-labelling or DLP-block without confidence in your SITs produces false positives at scale and destroys user trust. Run simulation mode for at least 7 days first.
  • Do not over-assign Compliance Administrator or Organization Management. These bypass scoped role groups and break separation of duties for eDiscovery and Insider Risk investigations.
  • Validate licensing before designing. Several solutions appear in the portal regardless of SKU and only fail at policy-creation time. Use the M365 service description as the source of truth, not the portal UI.
  • Do not scope by feature availability. Scope by data sensitivity and regulatory driver (GDPR, HIPAA, FINRA, PCI). Building "we have it, let's turn it on" creates noise without reducing risk.
  • Teams retention has limits. Teams chat retention applies forward only; historical chats are not back-filled. Communicate this before rollout.
  • eDiscovery holds are silent to users by design. Confirm legal/HR sign-off before placing a hold - inadvertent notification has happened via admin audit log access.

Common anti-patterns

  • "DLP first, classification later" — Rules fire on regex matches without label context, flooding the SOC with false positives. Always classify first.
  • "Turn on every Purview feature at once" — Overwhelms admins and users. Stick to the Sequence in Approach step 4.
  • "Use Org Management for the Purview admin team" — Grants tenant-wide rights including Exchange and SharePoint admin. Use scoped Purview role groups instead.
  • "Auto-label everything sensitive" — Without simulation, you will mislabel hundreds of documents and trigger access denials. Always run simulation mode and review the report before publishing.

Example prompts

  • Which Microsoft Purview solution should I use for my scenario?
  • Where do I start with Microsoft Purview for a new tenant?
  • What licence do I need for Insider Risk Management?
  • Explain data governance vs data security vs compliance in Purview.
  • What is the right order to roll out Purview features?
  • Which Purview role should I give my compliance team?

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/purview-general of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Purview General next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Purview General compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Purview General this skillvinayaklatthe/microsoft-security-skills175—~2.4kAutomated safety check: PassMIT
Jeecg Systemjeecgboot/skills239—~3.2kAutomated safety check: PassApache-2.0
Openalgo Chart Indicatormarketcalls/openalgo-charts146—~3.4kAutomated safety check: NotesApache-2.0
Data Quality Frameworkswshobson/agents40k11 repos~1.1kAutomated safety check: PassMIT
Research Data Feasibility and Leakage ChecksLight0305/Light-skills640—~4.9kAutomated safety check: PassMIT
Annotating Task Lineageastronomer/agents451—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Jeecg System

    jeecgboot/skills

    JeecgBoot 系统主数据查询与管理。Use when user asks to query/create/manage system master data, or says "查询角色", "查询用户", "查询部门", "查询字典", "创建字典", "创建角色", "查岗位", "查职务", "查租户", "查数据源", "查定时任务", "系统主数据", "query…

    239 GitHub stars~3.2k tokensUpdated 23 days ago
    Data & AnalyticsAuto-check passed
  • Openalgo Chart Indicator

    marketcalls/openalgo-charts

    Add a built-in openalgo-charts indicator, restyle it, build a settings UI from its descriptor, or author a custom indicator with registerIndicator or the Tier-2 external-data contract.

    146 GitHub stars~3.4k tokensUpdated 9 days ago
    Data & AnalyticsAuto-check: notes
  • Sets up data quality checks with Great Expectations, dbt tests and data contracts, with checkpoints and pass-fail reports for pipelines.

    40k GitHub starsUsed in 11 repos~1.1k tokens
    Data & AnalyticsAuto-check passed
  • Finds usable public datasets, judges whether the data can support a research idea, and checks train and test splits for leakage before results are trusted.

    640 GitHub stars~4.9k tokensUpdated 3 mo ago
    Data & AnalyticsAuto-check passed
  • Annotating Task Lineage

    astronomer/agents

    Annotate Airflow tasks with data lineage using inlets and outlets.

    451 GitHub stars~2.8k tokensUpdated 3 days ago
    Data & AnalyticsAuto-check passed
  • Data Catalog Entry

    nimrodfisher/data-analytics-skills

    Create standardized metadata for data assets. An agent skill from nimrodfisher/data-analytics-skills.

    470 GitHub stars~616 tokensUpdated 15 days ago
    Data & AnalyticsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Purview General

What does Purview General do?

Orientation skill for the Microsoft Purview data security, governance, and compliance suite. Purview General is an agent skill from vinayaklatthe/microsoft-security-skills. Orientation skill for the Microsoft Purview data security, governance, and compliance suite.

When should I use Purview General?

Purview General fits situations like: tasks that involve Data governance.

How do I install Purview General in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-general -a claude-code`. Or copy the skill folder (skills/purview-general in vinayaklatthe/microsoft-security-skills) into .claude/skills/purview-general in your project. Claude Code loads it when a task matches its description.

How do I install Purview General in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-general -a codex`. Or copy the skill folder (skills/purview-general in vinayaklatthe/microsoft-security-skills) into .agents/skills/purview-general in your project. Codex loads it when a task matches its description.

Can I use Purview General in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill purview-general -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/purview-general, .gemini/skills/purview-general, .github/skills/purview-general and .opencode/skills/purview-general in your project.

What does Purview General need to run?

SKILL.md names no scripts, command-line tools or credentials: Purview General is instructions for the agent only.

Does Purview General access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Purview General safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Purview General use?

Purview General is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Purview General use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Purview General?

Skills that share tags, products or a category with Purview General: Jeecg System (jeecgboot/skills, 239 stars), Openalgo Chart Indicator (marketcalls/openalgo-charts, 146 stars), Data Quality Frameworks (wshobson/agents, 40k stars) and Research Data Feasibility and Leakage Checks (Light0305/Light-skills, 640 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Purview General?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.