Sensitivity labels and encryption that travel with the file — and if you hold Microsoft 365 E3, you already own the foundation. In most estates we look at, it is sitting unconfigured. Check what you have before you buy anything else in this category.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — not the same question
Where data lives
India IS available — under Advanced Data Residency
India is an eligible Local Region Geography, and Information Protection is within ADR scope as of February 2026. In a category where most vendors have no India region at all, that is a real differentiator. The conditions are strict: ADR must be purchased for ALL users in the tenant, and the tenant default geography must be India.
Where it is processed
Microsoft’s cloud — unless you use DKE
Residency governs where data rests, not who can decrypt it. If your requirement is that Microsoft itself must not be able to read the content, that is Double Key Encryption — you hold one of two keys — and its functional costs are severe. See the FAQ before planning around it.
Residency and decryptability are two different questions, and buyers routinely settle the first while assuming they have answered the second. ADR puts in-scope data at rest in India; it does not mean Microsoft cannot read it. Double Key Encryption does, at the cost of co-authoring, SharePoint and OneDrive processing, search, eDiscovery and Copilot — which makes it right for a small set of genuinely critical documents and wrong as a default posture. Decide which question your regulator is actually asking before you scope either.
Quick answer
This page covers Microsoft Purview Information Protection — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Sensitivity labels plus encryption inside Microsoft 365 — a classification attached to the file itself, and protection enforced by Azure Rights Management wherever the file travels.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Microsoft Purview |
|---|---|---|
| Pricing axis | Per device or per user | Per GB ingested per day |
| Microsoft logs | Paid like any other source | Azure Activity, M365, XDR alerts free |
| High-volume logs | Full rate or drop them | Data lake tier at a fraction of analytics |
| Infrastructure | Servers, storage, upgrades | SaaS on Azure — nothing to run |
| Where protection stops | At your network boundary | It travels with the file |
| Retention | Priced from day one | 90 days included, then charged |
| Honest caveat | — | Third-party ingest escalates the bill |
| Best fit | — | Microsoft-standardised estates |
Rights management for Microsoft estates — for non-Microsoft log volume, on-prem or air-gapped, weigh Splunk or Elastic (TechBag sells Splunk).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A label records how sensitive something is and what may be done with it — and unlike a folder or a location, it stays attached to the file. Labels can be applied manually by users on any Microsoft 365 licence, or automatically on E5, and the difference between those two is most of whether a deployment succeeds.
The service that actually enforces a label's protection: encrypting the content and checking, each time someone opens it, whether that identity is still permitted. This is why the protection travels — the file carries its encryption, and the authorisation check happens wherever it is opened rather than at your network edge.
Labels applied by rule rather than by a person remembering, either in Office clients or at the service level across Exchange, SharePoint and OneDrive. This is the E5 feature that matters most, because manual labelling is applied rarely and inconsistently. If you buy only one thing above E3, this is the argument for it.
Machine-learning classifiers that recognise document types by example rather than by regular expression — contracts, source code, financial statements. Useful where sensitive content has no reliable pattern to match, which is most content that is not a card number or an identifier.
Two keys protect the content: one held by Microsoft in Azure, one held by you anywhere including on-premises. Neither party can decrypt alone. It is the strongest custody position Purview offers and it disables a substantial amount of functionality — see the FAQ, because the costs are severe and specific.
India is an eligible Local Region Geography, and Information Protection is in scope as of February 2026. The conditions are strict: ADR must be purchased for all users, and the tenant's default geography must be India. Establish both before treating residency as solved.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Purview attaches a sensitivity label to a document and enforces encryption that travels with it — so protection survives the file leaving your organisation, which is the one thing location-based security cannot do.
Attach a classification to a file or email that travels with it, rather than depending on where it is stored.
Users apply labels themselves — available on licences you very likely already hold, and applied about as often as you would expect.
Labels applied by rule in Office clients or service-side across Exchange, SharePoint and OneDrive, removing the dependency on users remembering.
Recognise document types by example rather than pattern — useful where sensitive content has no reliable regular expression.
Match against your actual sensitive values rather than a generic pattern, which cuts false positives sharply.
Encrypt the content and re-check authorisation each time it is opened, wherever it has travelled to.
Control whether a recipient can edit, copy, print or forward — not merely whether they can open it.
Hold one of two keys yourself, anywhere including on-premises, so Microsoft alone cannot decrypt the content.
Send protected email to external recipients who authenticate with a one-time passcode and need no software installed.
See who opened a document and attempt to revoke access after distribution — with real limits, set out in the FAQ.
Endpoint protection, XDR and Security Copilot.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Purview apart (and where it does not) — starting with the fact that you may already own the foundation.
This is the first thing to check and the reason this page exists before the ones that cost money. Manual sensitivity labels and Rights Management encryption are included in Microsoft 365 E3. If you hold E3 or above, that capability is already paid for, and in most organisations we look at, it is unconfigured. Before evaluating a dedicated rights-management product, find out what your existing licences entitle you to and whether anyone has switched it on. We would rather run that audit with you and sell you nothing than sell you a capability you were already paying Microsoft for — and it is a common enough situation that we raise it unprompted.
The reason rights management is a different category from encryption at rest: the protection is attached to the file rather than to where the file lives. A labelled and encrypted document that is emailed outside, copied to a personal drive or forwarded twice is still encrypted, and each attempt to open it triggers an authorisation check against the identity opening it. That is what makes it the right answer for documents shared outside your organisation, and it is precisely what key management and disk encryption cannot do.
Manual labelling depends on a user classifying a document correctly, every time, while doing something else. In practice that means it is applied to a minority of the documents that need it, inconsistently, with the most sensitive material no more likely to be labelled than anything else. Automatic labelling — E5, or the Purview add-on — applies labels by rule, in the Office client and service-side across Exchange, SharePoint and OneDrive. If you are deciding whether the step up from E3 is worth it, this is the argument, and it is a strong one.
India is an eligible Local Region Geography under the Advanced Data Residency add-on, and Information Protection is in scope as of February 2026. For a category where most vendors have no India region at all, that is a real differentiator. Read the conditions carefully though, because they are strict rather than nominal: ADR must be purchased for all users in the tenant, not a subset, and the tenant's default geography must be India. Confirm both before treating residency as solved, and get the position in writing if a regulator will ask.
Two limits that vendor material understates. Revocation is real but not absolute — a revoked document remains readable until the recipient's offline policy period expires, and files uploaded to SharePoint or OneDrive lose the tracking identifier and cannot be tracked or revoked at all. If your requirement is genuinely absolute revocation, test that specific scenario before you rely on it. Double Key Encryption's costs are severe and worth stating in full: it breaks co-authoring and AutoSave, SharePoint and OneDrive cannot process DKE-protected files, eDiscovery and search cannot read them, Copilot cannot use them, it does not apply to Teams meetings or chat, and it is Windows Office only. DKE is the right answer for a small set of genuinely critical documents and the wrong answer as a default posture.
Purview Information Protection is the right answer when you are already a Microsoft estate and the problem is documents leaving your organisation. The licensing you hold makes the starting point nearly free, the India residency story is real, and integration with the applications people actually use is something no third party can match. It is the wrong answer if you are not a Microsoft estate, because the value collapses outside it; if you need protection on file formats and workflows Microsoft does not cover well, where Seclore's format breadth including CAD is stronger; or if your problem is key custody for databases and applications rather than documents, which is Thales or Entrust. We sell all of them, and the licence audit comes first regardless.
Manual sensitivity labels and RMS encryption are in E3. Find out what your licences entitle you to and whether any of it is configured, before evaluating anything you would have to buy. In most organisations this step alone changes the shape of the project.
India is an eligible Local Region Geography under Advanced Data Residency, and Information Protection is in scope. The conditions are strict — ADR for all users, tenant default geography India — so confirm both, in writing if a regulator will ask.
Too few labels and nobody can classify accurately; too many and nobody classifies at all. Four or five is usually right. Get this wrong and you will re-label the estate later, which is considerably harder than getting it right first.
Manual labelling as a starting point trains users that classification is optional. Piloting automatic labelling first shows what the rules catch and what they miss, and that is the evidence that justifies the E5 or add-on spend.
Double Key Encryption disables co-authoring, SharePoint and OneDrive processing, search, eDiscovery and Copilot, and is Windows Office only. That is an acceptable trade for a small set of genuinely critical documents and an unacceptable one as a default. Decide the scope deliberately.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We were about to buy a rights-management product and discovered E3 already included the basics. Nobody had switched it on.”
“Auto-labelling is the whole product. Manual labelling got applied to maybe one document in ten.”
“Double Key Encryption works and it costs you co-authoring, search and Copilot. Use it on the few files that warrant it.”
“Advanced Data Residency answered our India question, but read the conditions — it has to be every user in the tenant.”
“Revocation is not what people assume. Test the SharePoint case specifically before you promise it to anyone.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Native to the estate; you may already own it.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Deepest inside Microsoft 365; narrower outside it.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The rights-management field — honest lanes; the edge is free first-party ingest + one incident queue with Defender. Deepest search, or on-prem? Splunk. We say so (and sell it).
| Dimension | Microsoft Purview | Seclore | Thales | Entrust | Trellix |
|---|---|---|---|---|---|
| What it actually is | Document rights management inside Microsoft 365 | India-built EDRM | Key management and hardware custody | HSM, private PKI and identity | Endpoint and database encryption |
| Protection travels with the file | Yes — label and encryption follow it | Yes, with stronger revocation | No — protects infrastructure, not documents | No | No — at rest on the device |
| Revocation after distribution | PARTIAL — offline window; lost on SharePoint upload | Documented | Not applicable | Not applicable | None |
| Already in your licences? | Manual labels + RMS are in E3 — check first | Separate purchase | Separate purchase | Separate purchase | Separate purchase |
| Published pricing | $12/user/mo add-on over E3; E5 $60 | Quote (INR) | Quote-only | Quote-only | Quote-only |
| Who holds the keys | Microsoft — unless you use Double Key Encryption | Either — SaaS or self-hosted | You, in hardware if you want | You, in hardware | You |
| India data residency | India is an ADR Local Region Geography | India-built; SaaS or self-hosted | On-premises — no India SaaS region | On-premises — no India SaaS region | Unverified |
| Format breadth | Strong on Office and PDF; narrower beyond | Office, PDF, CAD and arbitrary formats | Any — it encrypts storage, not documents | Any | Any |
| Best fit | Microsoft estates — start here, you may own it | Broad formats, India-built, stronger revocation | Key custody for databases and applications | Where BIS certification is a procurement gate | Endpoint and database encryption at rest |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Microsoft Purview Information Protection is one of 18 encryption & rights management products TechBag carries. The encryption & rights management guide narrows them to a shortlist and shows the reasoning. →
You already own manual labelling if you hold E3, so the only question worth modelling is whether automatic labelling justifies the step up. Move the second slider honestly: manual labelling typically reaches a small minority of the documents that need it, because it depends on a person classifying correctly while doing something else. The published rate is $12 per user per month for the Purview add-on over E3, against $60 for full E5. Indicative INR conversion at 83.
Free first-party sources — Azure Activity, Microsoft 365 audit logs and Defender XDR alerts — are excluded from both figures, so count only your billable GB. The commitment rate applies at 100 GB/day and above. Illustrative: your TechBag quote models your real sources.
Purview has published pricing, which is rare in this category: the Microsoft 365 E5 Compliance add-on is $12 per user per month over E3, and full E5 is $60 following the July 2026 increase. What matters more than either number is what you already hold — manual sensitivity labels and RMS encryption are in E3, so the real question is whether automatic labelling justifies the step up. TechBag runs that entitlement audit before quoting anything.
Best for starting out or low volume
Best above ~69 GB/day
Best for high-volume, low-value logs
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What do our existing Microsoft licences already include, and is any of it configured?
Do we need auto-labelling enough to justify E5 or the $12 add-on over E3?
Have we purchased ADR for ALL users, and is our tenant default geography India?
Have we tested revocation on a file uploaded to SharePoint, where tracking is lost?
Which specific documents warrant DKE, given it disables search, Copilot and co-authoring?
How many labels? Four or five usually works; more than that and nobody classifies.
Do our recipients need software? Email uses a one-time passcode; files need the viewer.
Does Microsoft cover the file types we actually need protected, including any CAD or engineering formats?
Is our problem documents leaving the organisation, or key custody for databases? Different products.
Who drives labelling — automation, or users remembering? The second one does not work.
Find out what your Microsoft licences already include before you buy anything. We will run the audit and tell you if the answer is that you need nothing.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.