Communication Compliance - Simply Explained
Business communication has evolved far beyond email. Employees collaborate through Microsoft Teams chats, Outlook emails, Viva Engage, Microsoft 365 Copilot, and other digital communication platforms every day. While these tools improve productivity, they also create new risks involving workplace misconduct, regulatory compliance, sensitive information, insider threats, and inappropriate communication. In this Microsoft Knowledge Nuggets episode, Mirko Peters explains Microsoft Purview Communication Compliance in plain English, showing how organizations can identify potentially risky workplace communications while balancing security, compliance, privacy, and fair human review. Whether you're an IT administrator, compliance officer, HR professional, security analyst, or Microsoft consultant, this episode explains how Communication Compliance helps organizations build safer and more compliant digital workplaces.
UNDERSTANDING MICROSOFT PURVIEW COMMUNICATION COMPLIANCE
Microsoft Purview Communication Compliance is designed to identify communications that may violate organizational policies, legal requirements, or regulatory obligations. Rather than monitoring every conversation indiscriminately, organizations create targeted compliance policies that define which users, communication channels, message directions, and risk scenarios require review. These policies can monitor Microsoft Teams conversations, Exchange Online email, Viva Engage discussions, Microsoft 365 Copilot prompts and responses, and supported third-party communication platforms connected through Microsoft Purview. The service detects potential policy matches while leaving the final decision to trained human reviewers who evaluate each situation within its full business context.
BUILDING TARGETED COMMUNICATION COMPLIANCE POLICIES
Communication Compliance policies form the foundation of every implementation. Organizations define specific business scenarios such as workplace harassment, inappropriate language, regulatory supervision, conflicts of interest, insider communications, customer interactions, or the exposure of sensitive information. Policies can target selected users, departments, security groups, external communications, internal conversations, or high-risk business units instead of monitoring the entire organization. Microsoft provides built-in templates that simplify deployment while allowing organizations to customize users, communication locations, reviewers, risk conditions, and compliance rules to match their own governance requirements and regulatory obligations.
HOW MICROSOFT PURVIEW IDENTIFIES RISKY COMMUNICATIONS
Microsoft Purview combines multiple detection technologies to identify communications that may require investigation. Sensitive Information Types detect structured information such as financial records, health data, personal identifiers, and confidential business information. Trainable Classifiers use machine learning to recognize communication patterns associated with harassment, threats, discrimination, and other behavioral risks beyond simple keyword matching. Organizations can further strengthen policies using custom keywords, phrase dictionaries, Optical Character Recognition (OCR) for text inside images, contextual conversation analysis, and configurable review sampling percentages. These technologies generate signals rather than conclusions, allowing reviewers to evaluate communications within their complete conversational context before determining whether any policy has actually been violated.
HUMAN REVIEW, PRIVACY, AND RESPONSIBLE GOVERNANCE
A fundamental principle of Microsoft Purview Communication Compliance is that technology supports human decision-making rather than replacing it. Messages that match compliance policies enter a secure review workflow where trained reviewers evaluate surrounding conversations, classify findings, document their decisions, and determine whether escalation is necessary. Potential issues may be dismissed, resolved through coaching, escalated to Human Resources, referred to compliance teams, or transferred into Microsoft Purview eDiscovery for formal legal investigations. Role-based access control, pseudonymization, reviewer accountability, privacy protections, and documented governance procedures help ensure investigations remain fair, proportionate, and aligned with applicable legal and organizational requirements.
HOW COMMUNICATION COMPLIANCE FITS INTO MICROSOFT PURVIEW
Microsoft Purview Communication Compliance operates alongside several complementary Microsoft Purview services. Microsoft Purview Audit records user activities and administrative actions across Microsoft 365. Content Search locates emails, documents, and messages relevant to investigations. Microsoft Purview eDiscovery manages legal cases, preserves evidence, and supports litigation workflows. Data Loss Prevention (DLP) helps prevent sensitive information from leaving the organization, while Communication Compliance focuses on reviewing communications that may indicate workplace misconduct, regulatory violations, or other organizational risks. Together, these services create a comprehensive Microsoft Purview compliance platform that helps organizations secure communications, protect sensitive information, maintain regulatory compliance, and strengthen enterprise governance across Microsoft 365.
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
00:00:00,000 --> 00:00:02,300
A team's chat might feel like a quick private note,
2
00:00:02,300 --> 00:00:03,800
an email might feel like a message
3
00:00:03,800 --> 00:00:05,960
that disappears into someone else's inbox.
4
00:00:05,960 --> 00:00:07,740
But when you're using company systems,
5
00:00:07,740 --> 00:00:09,840
those messages can carry business records,
6
00:00:09,840 --> 00:00:12,360
sensitive data, and real workplace risks.
7
00:00:12,360 --> 00:00:14,360
Microsoft Perview Communication Compliance
8
00:00:14,360 --> 00:00:17,200
helps an organization find messages that may need attention.
9
00:00:17,200 --> 00:00:19,920
Think of Microsoft 365 like an office building.
10
00:00:19,920 --> 00:00:21,840
Communication Compliance isn't a guard reading
11
00:00:21,840 --> 00:00:23,600
every conversation in every room.
12
00:00:23,600 --> 00:00:25,520
Instead, it's a security process set up
13
00:00:25,520 --> 00:00:28,120
to look for specific concerns in selected rooms
14
00:00:28,120 --> 00:00:29,320
based on clear rules.
15
00:00:29,320 --> 00:00:30,760
By the end of this knowledge nugget,
16
00:00:30,760 --> 00:00:32,200
you'll understand what it can watch,
17
00:00:32,200 --> 00:00:34,160
how a flagged message gets reviewed,
18
00:00:34,160 --> 00:00:36,200
and where privacy fits into the process.
19
00:00:36,200 --> 00:00:39,080
Why companies need it?
20
00:00:39,080 --> 00:00:40,880
Work used to happen mostly in email.
21
00:00:40,880 --> 00:00:42,840
You'd send a message, attach a document,
22
00:00:42,840 --> 00:00:44,280
and wait for a reply.
23
00:00:44,280 --> 00:00:45,560
Now work moves much faster.
24
00:00:45,560 --> 00:00:47,920
People talk in teams, chats, channel posts,
25
00:00:47,920 --> 00:00:50,400
meeting messages, and shared workspaces.
26
00:00:50,400 --> 00:00:52,840
They also ask AI tools to summarize documents,
27
00:00:52,840 --> 00:00:54,680
write drafts, or answer questions
28
00:00:54,680 --> 00:00:56,200
based on business information.
29
00:00:56,200 --> 00:00:58,200
That's useful, but it creates more places
30
00:00:58,200 --> 00:01:00,240
where a risky conversation can happen.
31
00:01:00,240 --> 00:01:02,120
Imagine a manager sends an aggressive message
32
00:01:02,120 --> 00:01:03,760
in a private chat.
33
00:01:03,760 --> 00:01:05,360
Or someone shares customer health details
34
00:01:05,360 --> 00:01:06,960
in a channel with the wrong people.
35
00:01:06,960 --> 00:01:08,600
Maybe a sales employee makes a promise
36
00:01:08,600 --> 00:01:11,080
to an external customer that the company can't support.
37
00:01:11,080 --> 00:01:12,880
These aren't always loud, obvious events.
38
00:01:12,880 --> 00:01:14,960
They can sit inside hundreds of normal messages
39
00:01:14,960 --> 00:01:16,320
moving through the business each day.
40
00:01:16,320 --> 00:01:18,640
That's the problem of communication compliance addresses.
41
00:01:18,640 --> 00:01:20,760
It helps an organization spot communications
42
00:01:20,760 --> 00:01:23,520
that may break a company rule, create a legal issue,
43
00:01:23,520 --> 00:01:26,960
expose sensitive information, or harm another employee.
44
00:01:26,960 --> 00:01:28,800
The word may matters here.
45
00:01:28,800 --> 00:01:30,160
The system looks for signals.
46
00:01:30,160 --> 00:01:31,960
It doesn't decide who's right, who's wrong,
47
00:01:31,960 --> 00:01:33,320
or what someone intended.
48
00:01:33,320 --> 00:01:35,600
A message might contain harassment, threatening language,
49
00:01:35,600 --> 00:01:37,160
or discriminatory wording.
50
00:01:37,160 --> 00:01:38,680
It might include personal details
51
00:01:38,680 --> 00:01:40,960
such as health information or financial data.
52
00:01:40,960 --> 00:01:42,840
It could suggest a conflict of interest,
53
00:01:42,840 --> 00:01:44,600
where someone discusses business decisions
54
00:01:44,600 --> 00:01:46,600
with a party they shouldn't be dealing with.
55
00:01:46,600 --> 00:01:49,120
In some industries, the concern is also record-keeping.
56
00:01:49,120 --> 00:01:50,560
Financial firms, for example,
57
00:01:50,560 --> 00:01:52,440
may need to supervise business communications
58
00:01:52,440 --> 00:01:54,200
and show that concerns were reviewed.
59
00:01:54,200 --> 00:01:55,560
This doesn't mean every company needs
60
00:01:55,560 --> 00:01:57,440
to watch every worker all the time.
61
00:01:57,440 --> 00:01:59,800
A sensible use starts with a real business reason,
62
00:01:59,800 --> 00:02:02,440
maybe a regulated sales team communicates with customers.
63
00:02:02,440 --> 00:02:04,840
Maybe HR needs a process for handling reports
64
00:02:04,840 --> 00:02:06,160
of workplace harassment.
65
00:02:06,160 --> 00:02:07,880
Maybe a company handles sensitive patient
66
00:02:07,880 --> 00:02:08,960
or customer information
67
00:02:08,960 --> 00:02:10,240
and needs to know when it appears
68
00:02:10,240 --> 00:02:11,640
in the wrong type of message.
69
00:02:11,640 --> 00:02:14,680
The goal is targeted review, not curiosity.
70
00:02:14,680 --> 00:02:17,840
Now AI brings another communication space into the picture.
71
00:02:17,840 --> 00:02:20,960
When someone types a prompt into Microsoft 365 Copilot,
72
00:02:20,960 --> 00:02:23,560
they may include names, financial details, project plans,
73
00:02:23,560 --> 00:02:25,960
or text from a confidential document.
74
00:02:25,960 --> 00:02:28,640
The response can also become part of how work gets done.
75
00:02:28,640 --> 00:02:30,760
So for many organizations, AI, prompts,
76
00:02:30,760 --> 00:02:33,440
and responses need the same careful thinking as email and chat.
77
00:02:33,440 --> 00:02:34,680
You might be thinking,
78
00:02:34,680 --> 00:02:37,360
does this tool block a message before anyone sees it?
79
00:02:37,360 --> 00:02:38,120
No.
80
00:02:38,120 --> 00:02:40,280
Communication compliance is mainly about finding
81
00:02:40,280 --> 00:02:41,720
and reviewing possible problems
82
00:02:41,720 --> 00:02:43,520
after the communication exists.
83
00:02:43,520 --> 00:02:45,560
Other Pervue tools can warn or block
84
00:02:45,560 --> 00:02:47,320
certain data sharing actions.
85
00:02:47,320 --> 00:02:49,920
This tool brings a potential concern to trained people
86
00:02:49,920 --> 00:02:51,920
who can examine the situation properly.
87
00:02:51,920 --> 00:02:54,880
That human step protects both the company and the employee.
88
00:02:54,880 --> 00:02:56,200
Words can mean different things
89
00:02:56,200 --> 00:02:57,800
depending on the conversation.
90
00:02:57,800 --> 00:02:59,120
A phrase might look threatening by itself,
91
00:02:59,120 --> 00:03:00,600
but turn out to be part of a quote,
92
00:03:00,600 --> 00:03:03,320
a joke or a discussion about a customer complaint.
93
00:03:03,320 --> 00:03:04,400
On the other hand,
94
00:03:04,400 --> 00:03:06,080
a short message may only make sense
95
00:03:06,080 --> 00:03:07,680
when you see what came before it.
96
00:03:07,680 --> 00:03:10,000
So communication compliance finds the smoke,
97
00:03:10,000 --> 00:03:11,840
people decide whether there's actually a fire.
98
00:03:11,840 --> 00:03:13,280
The next question is simple.
99
00:03:13,280 --> 00:03:15,040
Which workplace conversations can it look at?
100
00:03:15,040 --> 00:03:18,040
And how does an organization tell it where to focus?
101
00:03:18,040 --> 00:03:20,520
What it can watch and what a policy does?
102
00:03:20,520 --> 00:03:21,360
Here's the thing.
103
00:03:21,360 --> 00:03:23,000
Communication compliance policy
104
00:03:23,000 --> 00:03:26,040
is simply a set of written instructions you give to Pervue.
105
00:03:26,040 --> 00:03:28,240
It tells the service three basic things,
106
00:03:28,240 --> 00:03:31,000
whose communications to look at, which places to check,
107
00:03:31,000 --> 00:03:32,840
and what kind of content might need review,
108
00:03:32,840 --> 00:03:33,960
think of it like a rule card
109
00:03:33,960 --> 00:03:35,840
for a specific business concern.
110
00:03:35,840 --> 00:03:37,160
A policy might say,
111
00:03:37,160 --> 00:03:39,680
review messages from this customer facing team
112
00:03:39,680 --> 00:03:41,240
when they go outside the company
113
00:03:41,240 --> 00:03:43,160
and contain certain terms.
114
00:03:43,160 --> 00:03:44,000
Another might say,
115
00:03:44,000 --> 00:03:46,200
watch internal teams messages in this department
116
00:03:46,200 --> 00:03:48,320
for language linked to workplace conduct.
117
00:03:48,320 --> 00:03:49,280
And here's the key.
118
00:03:49,280 --> 00:03:51,080
The policy doesn't have to cover everyone.
119
00:03:51,080 --> 00:03:52,120
That distinction really matters
120
00:03:52,120 --> 00:03:54,080
because a company might have a narrow rule
121
00:03:54,080 --> 00:03:55,200
for financial advisors,
122
00:03:55,200 --> 00:03:57,360
another for people handling patient information
123
00:03:57,360 --> 00:03:59,080
and a separate rule for a small team
124
00:03:59,080 --> 00:04:00,760
working on a confidential project.
125
00:04:00,760 --> 00:04:02,040
Each group has different risks
126
00:04:02,040 --> 00:04:04,440
so each policy can fit the work they actually do.
127
00:04:04,440 --> 00:04:05,280
So where do you look?
128
00:04:05,280 --> 00:04:06,800
The first choice is location.
129
00:04:06,800 --> 00:04:09,160
Exchange online covers business email.
130
00:04:09,160 --> 00:04:10,640
If you use Outlook at work,
131
00:04:10,640 --> 00:04:12,040
that's the service behind the scenes,
132
00:04:12,040 --> 00:04:13,880
delivering and storing your email.
133
00:04:13,880 --> 00:04:16,080
Microsoft teams covers both one-to-one chats
134
00:04:16,080 --> 00:04:17,960
and team conversations in channels.
135
00:04:17,960 --> 00:04:20,320
Viva Engage, which you might remember as Yammer,
136
00:04:20,320 --> 00:04:21,760
covers posts and conversations
137
00:04:21,760 --> 00:04:23,320
in that social style company space,
138
00:04:23,320 --> 00:04:25,680
then there's Microsoft 365 co-pilot.
139
00:04:25,680 --> 00:04:27,760
A policy can include co-pilot interactions
140
00:04:27,760 --> 00:04:30,240
so your organization can review prompts and responses
141
00:04:30,240 --> 00:04:32,440
when they fall within its defined purpose.
142
00:04:32,440 --> 00:04:33,520
Notice what this means.
143
00:04:33,520 --> 00:04:35,720
The policy follows the communication type,
144
00:04:35,720 --> 00:04:38,000
not just the app someone prefers.
145
00:04:38,000 --> 00:04:40,920
Some organizations also use business communication tools
146
00:04:40,920 --> 00:04:42,600
outside Microsoft 365.
147
00:04:42,600 --> 00:04:45,040
Those records can come into purview through data connectors
148
00:04:45,040 --> 00:04:47,040
where supported and set up by the organization.
149
00:04:47,040 --> 00:04:48,680
The connector brings the communication record
150
00:04:48,680 --> 00:04:49,800
into the compliance process
151
00:04:49,800 --> 00:04:53,520
so it can sit alongside the company's Microsoft 365 communications.
152
00:04:53,520 --> 00:04:55,080
But that doesn't mean purview automatically
153
00:04:55,080 --> 00:04:56,960
sees every app on someone's phone.
154
00:04:56,960 --> 00:04:59,000
The organization needs to connect that source
155
00:04:59,000 --> 00:05:01,120
and decide why it belongs in the process.
156
00:05:01,120 --> 00:05:04,440
Next, a policy can focus on the direction of a message.
157
00:05:04,440 --> 00:05:07,800
Internal means a conversation between people inside the company.
158
00:05:07,800 --> 00:05:09,840
Inbound means a message arriving from outside,
159
00:05:09,840 --> 00:05:12,200
like an email from a customer or partner.
160
00:05:12,200 --> 00:05:15,560
Outbound means someone inside sends a message to someone outside
161
00:05:15,560 --> 00:05:17,720
and that direction can change the risk completely.
162
00:05:17,720 --> 00:05:20,400
For example, a company may care most about sensitive details
163
00:05:20,400 --> 00:05:22,160
leaving the business so it focuses
164
00:05:22,160 --> 00:05:24,640
on information policy and outbound communication.
165
00:05:24,640 --> 00:05:27,360
A support team may need to review incoming customer messages
166
00:05:27,360 --> 00:05:29,280
for threats or abusive behavior.
167
00:05:29,280 --> 00:05:31,160
A workplace conduct policy may focus only
168
00:05:31,160 --> 00:05:33,400
on internal messages because it deals with how employees
169
00:05:33,400 --> 00:05:34,360
speak to each other.
170
00:05:34,360 --> 00:05:36,800
You can also choose who belongs in the policy.
171
00:05:36,800 --> 00:05:38,360
Instead of applying it to every employee,
172
00:05:38,360 --> 00:05:40,600
you can select specific users or groups.
173
00:05:40,600 --> 00:05:42,680
A group might represent a department, a job role,
174
00:05:42,680 --> 00:05:45,120
or a team that handles a certain type of data.
175
00:05:45,120 --> 00:05:48,000
That makes the policy more focused and easier to explain.
176
00:05:48,000 --> 00:05:51,240
Imagine a company with a small, mergers, and acquisitions team.
177
00:05:51,240 --> 00:05:53,080
They may work with confidential deal information
178
00:05:53,080 --> 00:05:54,360
and external advises.
179
00:05:54,360 --> 00:05:56,520
A policy for that group can look for the project terms,
180
00:05:56,520 --> 00:05:58,120
the outside domains involved,
181
00:05:58,120 --> 00:06:00,920
and the communication directions that create a real concern.
182
00:06:00,920 --> 00:06:02,760
There's no need to apply that same policy
183
00:06:02,760 --> 00:06:05,440
to the facilities team or the lunchroom staff.
184
00:06:05,440 --> 00:06:08,120
Microsoft provides templates to help you get started.
185
00:06:08,120 --> 00:06:11,240
A template is a starting point, not a finished company policy.
186
00:06:11,240 --> 00:06:13,080
There are templates for inappropriate text,
187
00:06:13,080 --> 00:06:15,240
sensitive information, regulated communications,
188
00:06:15,240 --> 00:06:17,720
conflicts of interest, and co-pilot interactions.
189
00:06:17,720 --> 00:06:19,920
The template gives you a common use case,
190
00:06:19,920 --> 00:06:22,160
then you choose the user's locations, reviewers,
191
00:06:22,160 --> 00:06:23,960
and conditions that fit your own rules.
192
00:06:23,960 --> 00:06:25,920
For instance, an inappropriate text template
193
00:06:25,920 --> 00:06:28,960
might help an HR team set up a workplace conduct policy,
194
00:06:28,960 --> 00:06:30,520
while a sensitive information template
195
00:06:30,520 --> 00:06:33,720
can help a privacy team focus on personal or financial data,
196
00:06:33,720 --> 00:06:35,120
and a conflict of interest template
197
00:06:35,120 --> 00:06:37,480
can help a compliance team examine communication
198
00:06:37,480 --> 00:06:39,560
between groups that should remain separate.
199
00:06:39,560 --> 00:06:40,920
The template saves setup time,
200
00:06:40,920 --> 00:06:43,160
but the policy still needs careful choices.
201
00:06:43,160 --> 00:06:44,640
A broad policy with unclear purpose
202
00:06:44,640 --> 00:06:46,240
can create far too much review work,
203
00:06:46,240 --> 00:06:47,960
while a narrow policy with a clear reason
204
00:06:47,960 --> 00:06:49,120
gives reviewers a better chance
205
00:06:49,120 --> 00:06:51,040
of finding the items that deserve attention.
206
00:06:51,040 --> 00:06:53,640
So, the policy tells PerView where to look,
207
00:06:53,640 --> 00:06:55,800
and which communications belong in scope.
208
00:06:55,800 --> 00:06:58,600
The next piece decides how PerView recognizes
209
00:06:58,600 --> 00:07:00,760
a possible match in the first place.
210
00:07:00,760 --> 00:07:02,560
How PerView finds risky messages?
211
00:07:02,560 --> 00:07:04,960
So, how does PerView decide that a message
212
00:07:04,960 --> 00:07:06,200
deserves a closer look?
213
00:07:06,200 --> 00:07:08,200
It uses a mix of patterns, language signals,
214
00:07:08,200 --> 00:07:11,000
and the specific rules an organization puts into its policy.
215
00:07:11,000 --> 00:07:13,920
The first method is called sensitive information types.
216
00:07:13,920 --> 00:07:16,080
That name sounds technical, but the idea is simple.
217
00:07:16,080 --> 00:07:17,320
PerView can look for patterns
218
00:07:17,320 --> 00:07:20,320
that resemble personal, health, or financial information.
219
00:07:20,320 --> 00:07:22,080
Think of things like credit card numbers,
220
00:07:22,080 --> 00:07:25,000
national ID numbers, bank details, or health-related records.
221
00:07:25,000 --> 00:07:27,440
A policy can use Microsoft's built-in definitions
222
00:07:27,440 --> 00:07:28,720
for these types of data,
223
00:07:28,720 --> 00:07:30,800
or an organization can create its own definitions
224
00:07:30,800 --> 00:07:33,720
when it uses special customer numbers, internal codes,
225
00:07:33,720 --> 00:07:35,680
or records that have a clear format.
226
00:07:35,680 --> 00:07:36,960
The system isn't reading a number
227
00:07:36,960 --> 00:07:39,600
and automatically deciding someone did something wrong.
228
00:07:39,600 --> 00:07:41,760
It sees a pattern that matches the policy,
229
00:07:41,760 --> 00:07:43,880
then sends that message into the review process
230
00:07:43,880 --> 00:07:45,600
if the other conditions also fit.
231
00:07:45,600 --> 00:07:48,360
A customer number in a protected internal process may be normal,
232
00:07:48,360 --> 00:07:50,040
but the same number sent outside the company
233
00:07:50,040 --> 00:07:51,160
may deserve attention.
234
00:07:51,160 --> 00:07:53,320
Another method uses trainable classifiers.
235
00:07:53,320 --> 00:07:55,200
A classifier looks beyond one exact word
236
00:07:55,200 --> 00:07:57,200
and examines the wording and meaning of a message
237
00:07:57,200 --> 00:07:58,640
to look for a type of communication,
238
00:07:58,640 --> 00:08:01,160
such as harassment, a threat, or discrimination.
239
00:08:01,160 --> 00:08:04,120
That matters because people don't always use the same words.
240
00:08:04,120 --> 00:08:06,160
One person may write an obvious insult
241
00:08:06,160 --> 00:08:09,200
while someone else may use a quieter pattern of repeated putdowns.
242
00:08:09,200 --> 00:08:11,320
A simple keyword list can miss that difference,
243
00:08:11,320 --> 00:08:13,040
but a classifier tries to recognize
244
00:08:13,040 --> 00:08:14,560
the broader kind of language involved.
245
00:08:14,560 --> 00:08:16,280
Still, it isn't a mind reader.
246
00:08:16,280 --> 00:08:18,320
A classifier can find a possible concern,
247
00:08:18,320 --> 00:08:20,480
but it can't fully understand a relationship,
248
00:08:20,480 --> 00:08:22,680
a joke, a quoted customer message,
249
00:08:22,680 --> 00:08:24,600
or the history behind a conversation.
250
00:08:24,600 --> 00:08:26,680
That limitation is exactly why trained people
251
00:08:26,680 --> 00:08:28,240
remain part of the process.
252
00:08:28,240 --> 00:08:31,480
Organizations can also use keywords and phrase lists.
253
00:08:31,480 --> 00:08:33,520
This works well when the risk involves language
254
00:08:33,520 --> 00:08:35,160
that is specific to the business.
255
00:08:35,160 --> 00:08:37,040
A financial firm may watch for terms
256
00:08:37,040 --> 00:08:38,760
that suggest an improper promise,
257
00:08:38,760 --> 00:08:41,280
or a company protecting a confidential project
258
00:08:41,280 --> 00:08:43,440
may watch for its project code name.
259
00:08:43,440 --> 00:08:45,280
Keywords are direct and easy to explain,
260
00:08:45,280 --> 00:08:47,040
but they can also create a lot of noise.
261
00:08:47,040 --> 00:08:48,240
If the word is too common,
262
00:08:48,240 --> 00:08:50,560
reviewers may get a long list of ordinary messages
263
00:08:50,560 --> 00:08:51,920
that have nothing to do with the risk.
264
00:08:51,920 --> 00:08:54,080
That's why strong policies often combine phrases
265
00:08:54,080 --> 00:08:56,200
with other details such as the group involved
266
00:08:56,200 --> 00:08:58,400
or whether the message went outside the company.
267
00:08:58,400 --> 00:09:00,880
There's also a setting called optical character recognition,
268
00:09:00,880 --> 00:09:03,360
or OCR, OCR reads text inside an image.
269
00:09:03,360 --> 00:09:05,400
Imagine someone sends a screenshot of a document
270
00:09:05,400 --> 00:09:07,800
instead of copying the text into a team's chat.
271
00:09:07,800 --> 00:09:10,200
Without OCR, a policy may only see an image,
272
00:09:10,200 --> 00:09:12,480
but with OCR turned on where it makes sense,
273
00:09:12,480 --> 00:09:14,760
Perview can try to read the words in that screenshot
274
00:09:14,760 --> 00:09:17,080
and check them against the policy conditions.
275
00:09:17,080 --> 00:09:18,800
This can help with image-based messages,
276
00:09:18,800 --> 00:09:20,440
but it should fit the actual risk.
277
00:09:20,440 --> 00:09:22,520
You don't turn it on just because you can.
278
00:09:22,520 --> 00:09:23,360
Then there's context.
279
00:09:23,360 --> 00:09:24,760
When a message matches a policy,
280
00:09:24,760 --> 00:09:27,400
reviewers can see nearby messages from the same conversation.
281
00:09:27,400 --> 00:09:29,360
That helps them understand whether one sentence
282
00:09:29,360 --> 00:09:30,960
was part of a work discussion,
283
00:09:30,960 --> 00:09:33,480
a quote, a joke, or something more serious.
284
00:09:33,480 --> 00:09:35,840
Take the phrase, "I'm going to destroy you."
285
00:09:35,840 --> 00:09:37,080
On its own, that sounds alarming,
286
00:09:37,080 --> 00:09:39,520
but in a chat about a video game, it means something very different.
287
00:09:39,520 --> 00:09:41,520
In a message aimed at a colleague after an argument,
288
00:09:41,520 --> 00:09:43,240
it may need immediate attention.
289
00:09:43,240 --> 00:09:44,000
The words matter,
290
00:09:44,000 --> 00:09:46,400
but the surrounding conversation often changes the meaning.
291
00:09:46,400 --> 00:09:48,840
Not every match needs the same level of review.
292
00:09:48,840 --> 00:09:50,960
A policy includes a review percentage,
293
00:09:50,960 --> 00:09:53,880
which controls how many matching messages are sent to reviewers.
294
00:09:53,880 --> 00:09:57,200
A narrow policy for a small, high-risk group may review every match,
295
00:09:57,200 --> 00:09:58,400
while a much broader policy
296
00:09:58,400 --> 00:10:01,200
with a large volume of messages may use a sample instead.
297
00:10:01,200 --> 00:10:02,760
The right percentage depends on the risk
298
00:10:02,760 --> 00:10:04,680
and the people available to review it.
299
00:10:04,680 --> 00:10:06,080
Checking everything sounds safer,
300
00:10:06,080 --> 00:10:08,560
but it can bury reviewers in ordinary messages
301
00:10:08,560 --> 00:10:11,240
and checking too little can miss patterns that matter.
302
00:10:11,240 --> 00:10:14,640
The policy needs a level that the review team can actually handle well.
303
00:10:14,640 --> 00:10:17,400
Before a policy reaches a wider group, it should be tested.
304
00:10:17,400 --> 00:10:20,240
Teams can test sample text against the policy conditions
305
00:10:20,240 --> 00:10:22,320
and see whether the expected messages match.
306
00:10:22,320 --> 00:10:24,360
They can adjust phrases, classifiers,
307
00:10:24,360 --> 00:10:25,440
and the review percentage
308
00:10:25,440 --> 00:10:27,520
when the results create too many false matches
309
00:10:27,520 --> 00:10:29,680
or miss the messages they expected to find.
310
00:10:29,680 --> 00:10:30,800
Good tuning takes time.
311
00:10:30,800 --> 00:10:33,120
It's better to start with a clear, limited purpose,
312
00:10:33,120 --> 00:10:34,560
learn from the early results,
313
00:10:34,560 --> 00:10:38,720
and refine the policy than to create a huge queue nobody can review properly.
314
00:10:38,720 --> 00:10:40,000
A match is only a signal.
315
00:10:40,000 --> 00:10:41,600
The next step belongs to trained reviewers
316
00:10:41,600 --> 00:10:44,840
who can look at the message, its context, and the facts around it.
317
00:10:44,840 --> 00:10:46,360
The human review process.
318
00:10:46,360 --> 00:10:49,360
So when per view finds a message that matches a policy,
319
00:10:49,360 --> 00:10:50,600
it goes into a review queue.
320
00:10:50,600 --> 00:10:53,440
That's where a trained person steps in to take a closer look,
321
00:10:53,440 --> 00:10:55,280
but a match doesn't mean someone broke a rule.
322
00:10:55,280 --> 00:10:58,400
It just means the message hits certain conditions the organization set.
323
00:10:58,400 --> 00:11:01,200
Maybe it contains a specific phrase, a data pattern,
324
00:11:01,200 --> 00:11:03,400
or a type of language the policy flags.
325
00:11:03,400 --> 00:11:06,520
The reviewer has to figure out what that match actually means in context.
326
00:11:06,520 --> 00:11:08,200
That's an important safeguard for everyone.
327
00:11:08,200 --> 00:11:11,440
Imagine a team's message with a phrase that triggers a threat policy.
328
00:11:11,440 --> 00:11:12,840
The wording might look serious,
329
00:11:12,840 --> 00:11:16,080
but the reviewer needs to see the whole conversation before making a call.
330
00:11:16,080 --> 00:11:18,240
They don't judge a single line in isolation.
331
00:11:18,240 --> 00:11:19,920
The review screen shows the flagged message
332
00:11:19,920 --> 00:11:22,440
along with nearby messages from the same conversation
333
00:11:22,440 --> 00:11:25,120
and that surrounding context can completely change the picture.
334
00:11:25,120 --> 00:11:27,160
Maybe that phrase came from a customer complaint
335
00:11:27,160 --> 00:11:29,240
and employee paste it into the chat.
336
00:11:29,240 --> 00:11:30,760
Or it could be part of training material,
337
00:11:30,760 --> 00:11:34,840
or it might be a genuine concern that only becomes clear when you read the replies around it.
338
00:11:34,840 --> 00:11:36,400
Reviewers then classify the item,
339
00:11:36,400 --> 00:11:40,320
they can market as compliant, meaning the message matched the policy but didn't break a rule.
340
00:11:40,320 --> 00:11:42,280
Or non-compliant, meaning action is needed,
341
00:11:42,280 --> 00:11:43,680
or they can market as questionable.
342
00:11:43,680 --> 00:11:46,440
Questionable is a handy option when the reviewer needs more info,
343
00:11:46,440 --> 00:11:50,600
wants a second opinion, or sees something that doesn't fit neatly into a simple yes or no.
344
00:11:50,600 --> 00:11:53,240
Real workplace situations often need that middle ground.
345
00:11:53,240 --> 00:11:55,800
The reviewer also adds notes explaining what they saw,
346
00:11:55,800 --> 00:11:58,440
why they chose a classification and what action followed.
347
00:11:58,440 --> 00:12:02,480
That way, if another reviewer, HR, or legal needs to understand the decision later,
348
00:12:02,480 --> 00:12:05,320
they don't have to guess, they can read the investigation trail.
349
00:12:05,320 --> 00:12:09,840
For a harmless match, the reviewer can dismiss it and record why it wasn't a concern.
350
00:12:09,840 --> 00:12:13,320
That feedback helps the organization improve the policy later,
351
00:12:13,320 --> 00:12:16,120
especially when the same harmless messages keep popping up.
352
00:12:16,120 --> 00:12:19,000
For a low-level issue, the response might be coaching.
353
00:12:19,000 --> 00:12:22,200
That could mean reminding someone about the right communication channel,
354
00:12:22,200 --> 00:12:27,000
explaining how to handle customer info, or pointing them to a company policy.
355
00:12:27,000 --> 00:12:29,400
Not every incident needs a formal case,
356
00:12:29,400 --> 00:12:33,080
when the message points to possible harassment, a serious threat, regulated conduct,
357
00:12:33,080 --> 00:12:35,880
or a sensitive data issue, the reviewer can escalate it.
358
00:12:35,880 --> 00:12:40,120
HR handles workplace conduct, legal examines, regulatory or contractual issues,
359
00:12:40,120 --> 00:12:42,920
and if it becomes a formal investigation, it moves into e-discovery
360
00:12:42,920 --> 00:12:44,680
where legal teams manage the case.
361
00:12:44,680 --> 00:12:47,320
The reviewer doesn't have to solve every problem alone.
362
00:12:47,320 --> 00:12:49,880
Their job is to make a sound first decision, document it,
363
00:12:49,880 --> 00:12:51,720
and bring in the right people when needed.
364
00:12:51,720 --> 00:12:53,160
Here's another important detail.
365
00:12:53,160 --> 00:12:55,080
If someone deletes a message after sending it,
366
00:12:55,080 --> 00:12:57,880
but that message matched a communication compliance policy,
367
00:12:57,880 --> 00:13:01,080
the organization can preserve a copy for the review period.
368
00:13:01,080 --> 00:13:03,320
So the message disappears from the user's view,
369
00:13:03,320 --> 00:13:06,280
but the review record stays available for the case handlers.
370
00:13:06,280 --> 00:13:09,720
That prevents an investigation from losing the communication it needs to examine.
371
00:13:09,720 --> 00:13:11,080
You might also hear about alerts.
372
00:13:11,080 --> 00:13:12,920
An alert calls attention to a pattern,
373
00:13:12,920 --> 00:13:15,800
like repeated matches or activity that reaches a certain level.
374
00:13:15,800 --> 00:13:18,760
It notifies the right people that something may need attention.
375
00:13:18,760 --> 00:13:21,640
But most day-to-day work happens in the policy review queue.
376
00:13:21,640 --> 00:13:25,320
That's where reviewers open matches, read context, record decisions,
377
00:13:25,320 --> 00:13:28,280
and decide if the item ends there or moves further.
378
00:13:28,280 --> 00:13:32,200
Giving reviewers access to real messages creates a second concern, though.
379
00:13:32,200 --> 00:13:36,040
Who gets to see this information and what stops that access from being misused?
380
00:13:36,040 --> 00:13:39,400
Privacy, access, and fair use.
381
00:13:39,400 --> 00:13:42,200
Now, reading real workplace messages is sensitive work.
382
00:13:42,200 --> 00:13:45,560
A chat might mention a personal problem, a customer situation,
383
00:13:45,560 --> 00:13:47,960
or a difficult conversation between colleagues.
384
00:13:47,960 --> 00:13:50,360
That's why an organization needs a clear business reason
385
00:13:50,360 --> 00:13:53,080
before creating a communication compliance policy.
386
00:13:53,080 --> 00:13:55,400
We want to see what people are saying isn't a good reason.
387
00:13:55,400 --> 00:13:57,400
A real risk, like a conduct concern,
388
00:13:57,400 --> 00:13:59,960
a regulatory duty, or handling sensitive data,
389
00:13:59,960 --> 00:14:01,640
gives the policy a defined purpose.
390
00:14:01,640 --> 00:14:04,360
The policy should stay as narrow as that purpose allows.
391
00:14:04,360 --> 00:14:07,400
For example, if the concern is a regulated sales group sending messages
392
00:14:07,400 --> 00:14:08,600
to external customers,
393
00:14:08,600 --> 00:14:11,560
focus the policy on that group and those outgoing communications.
394
00:14:11,560 --> 00:14:14,040
If its workplace conduct in a certain department,
395
00:14:14,040 --> 00:14:16,280
focus on internal messages in those channels.
396
00:14:16,280 --> 00:14:18,280
This keeps the policy tied to a known risk
397
00:14:18,280 --> 00:14:21,160
and reduces the number of ordinary messages that enter review.
398
00:14:21,160 --> 00:14:24,360
Less unnecessary review means less exposure to private information
399
00:14:24,360 --> 00:14:25,800
and a more manageable queue.
400
00:14:25,800 --> 00:14:27,160
Access needs the same care.
401
00:14:27,160 --> 00:14:30,120
Communication compliance uses a role-based access.
402
00:14:30,120 --> 00:14:33,000
In plain English people only get the permissions they need for their job.
403
00:14:33,000 --> 00:14:34,520
An administrator sets up policies
404
00:14:34,520 --> 00:14:36,440
but doesn't review every flagged item.
405
00:14:36,440 --> 00:14:39,000
A trained investigator reviews messages assigned to them
406
00:14:39,000 --> 00:14:40,520
but can't change the whole setup.
407
00:14:40,520 --> 00:14:41,960
Different jobs need different doors
408
00:14:41,960 --> 00:14:43,880
and not everyone needs a master key.
409
00:14:43,880 --> 00:14:45,880
Reviewers should understand the company rules,
410
00:14:45,880 --> 00:14:49,000
the review process and when to involve HR, legal or compliance.
411
00:14:49,000 --> 00:14:52,200
They also need to know their access carries responsibility.
412
00:14:52,200 --> 00:14:55,000
Reading a flagged message out of curiosity is never the purpose.
413
00:14:55,000 --> 00:14:57,000
Review activity can be tracked,
414
00:14:57,000 --> 00:15:00,600
creating accountability for how this sensitive information is handled.
415
00:15:00,600 --> 00:15:03,960
Per view can also hide people's real names during the first review stage.
416
00:15:03,960 --> 00:15:06,600
Instead, reviewers see pseudonymized identities
417
00:15:06,600 --> 00:15:08,920
like a label that lets them follow the conversation
418
00:15:08,920 --> 00:15:10,840
without immediately seeing who the person is.
419
00:15:10,840 --> 00:15:12,520
They assess the content first,
420
00:15:12,520 --> 00:15:15,560
then identity is revealed when needed for a proper response.
421
00:15:15,560 --> 00:15:19,080
That reduces unnecessary exposure and can help limit bias.
422
00:15:19,080 --> 00:15:22,040
Fannas also means separating roles where possible.
423
00:15:22,040 --> 00:15:24,360
The reviewer shouldn't be the manager involved in the dispute
424
00:15:24,360 --> 00:15:26,600
or someone with a personal interest in the outcome.
425
00:15:26,600 --> 00:15:29,480
A separate trained review group gives the process more distance
426
00:15:29,480 --> 00:15:32,360
and makes it easier to apply the same rules consistently.
427
00:15:32,360 --> 00:15:34,840
People should know the rules before a problem appears.
428
00:15:34,840 --> 00:15:38,360
Clear policies and notices should explain which channels may be monitored,
429
00:15:38,360 --> 00:15:40,680
the reasons and how information is handled.
430
00:15:40,680 --> 00:15:45,000
HR, legal compliance and privacy teams need to be involved early
431
00:15:45,000 --> 00:15:48,120
because rules and privacy requirements differ by country,
432
00:15:48,120 --> 00:15:49,720
region and industry.
433
00:15:49,720 --> 00:15:52,120
No software setting replaces that planning
434
00:15:52,120 --> 00:15:54,520
and remember a policy match is a lead not a verdict.
435
00:15:54,520 --> 00:15:55,880
Language changes with context.
436
00:15:55,880 --> 00:15:58,200
A phrase can be quoted, misunderstood,
437
00:15:58,200 --> 00:16:01,000
or part of a conversation that tells a very different story
438
00:16:01,000 --> 00:16:02,360
than one sentence alone.
439
00:16:02,360 --> 00:16:04,200
Once those guardrails are in place,
440
00:16:04,200 --> 00:16:08,040
communication compliance becomes one part of a larger per view process
441
00:16:08,040 --> 00:16:10,440
with other tools handling other parts of the investigation.
442
00:16:10,440 --> 00:16:13,080
Where it fits in Microsoft Per view,
443
00:16:13,080 --> 00:16:16,440
so where does communication compliance fit inside Microsoft Per view?
444
00:16:16,440 --> 00:16:17,800
Here's the simplest definition.
445
00:16:17,800 --> 00:16:19,960
Think of Microsoft Per view as a connected platform
446
00:16:19,960 --> 00:16:21,880
with different rooms for different jobs.
447
00:16:21,880 --> 00:16:25,160
Communication compliance is the room that focuses on the words people use,
448
00:16:25,160 --> 00:16:28,120
the messages they send and the surrounding conversation.
449
00:16:28,120 --> 00:16:30,520
It helps reviewers assess whether communication
450
00:16:30,520 --> 00:16:33,720
might create a conduct, data or regulatory concern.
451
00:16:33,720 --> 00:16:35,400
Now let's talk about the other rooms.
452
00:16:35,400 --> 00:16:37,960
Audit looks at actions, things like who accessed something
453
00:16:37,960 --> 00:16:40,120
who changed the setting or when an activity happened.
454
00:16:40,120 --> 00:16:41,640
Audit records the action
455
00:16:41,640 --> 00:16:44,600
while communication compliance looks at the content of a conversation.
456
00:16:44,600 --> 00:16:48,600
Next up is content search, which helps find messages and files using search terms.
457
00:16:48,600 --> 00:16:52,600
Picture a legal or compliance team that needs to locate emails containing a project name
458
00:16:52,600 --> 00:16:54,120
or files that mention a customer.
459
00:16:54,120 --> 00:16:58,440
Content search helps them find those items across the places included in the search.
460
00:16:58,440 --> 00:17:02,200
Then there's eDiscovery, which supports formal legal investigations.
461
00:17:02,200 --> 00:17:03,640
When a matter needs a legal case,
462
00:17:03,640 --> 00:17:05,880
eDiscovery provides a place to manage that case,
463
00:17:05,880 --> 00:17:07,320
preserve relevant information,
464
00:17:07,320 --> 00:17:08,920
and prepare material for legal review.
465
00:17:09,720 --> 00:17:12,440
Communication compliance can uncover the first concern,
466
00:17:12,440 --> 00:17:15,960
but eDiscovery handles the deeper legal process when one is required.
467
00:17:15,960 --> 00:17:19,000
Data loss prevention, often called DLP, has a different job.
468
00:17:19,000 --> 00:17:22,120
DLP can warn someone or block an action when sensitive information
469
00:17:22,120 --> 00:17:23,880
tries to leave through supported channels.
470
00:17:23,880 --> 00:17:25,960
It acts closer to the moment of sharing,
471
00:17:25,960 --> 00:17:29,400
while communication compliance reviews possible concerns in communications
472
00:17:29,400 --> 00:17:32,440
after the fact with a person deciding what the match means.
473
00:17:32,440 --> 00:17:33,960
Here's a real-world example.
474
00:17:33,960 --> 00:17:37,880
Imagine a team's discussion includes language that concerns a reviewer.
475
00:17:37,880 --> 00:17:40,120
The reviewer reads the context and adds notes.
476
00:17:40,120 --> 00:17:41,880
If it's harmless, the review ends there,
477
00:17:41,880 --> 00:17:44,920
but if it points to workplace misconduct, HR may take over.
478
00:17:44,920 --> 00:17:47,080
And if the discussion relates to a legal matter,
479
00:17:47,080 --> 00:17:49,880
the information may move into an eDiscovery case.
480
00:17:49,880 --> 00:17:51,400
Each tool has its own job,
481
00:17:51,400 --> 00:17:53,560
but they can support the same investigation.
482
00:17:53,560 --> 00:17:55,560
That's the practical picture of purview,
483
00:17:55,560 --> 00:17:57,960
connected rooms, clear responsibilities,
484
00:17:57,960 --> 00:18:01,800
and a record of what happened when a workplace communication needs closer attention.
485
00:18:01,800 --> 00:18:04,280
Use it with purpose.
486
00:18:04,280 --> 00:18:06,840
Communication compliance is a targeted review tool
487
00:18:06,840 --> 00:18:09,320
for workplace messages that can create risk.
488
00:18:09,320 --> 00:18:11,400
It isn't an automatic judge of people,
489
00:18:11,400 --> 00:18:13,960
and a policy match isn't a finding of misconduct.
490
00:18:13,960 --> 00:18:16,840
That distinction needs to stay at the centre of every setup.
491
00:18:16,840 --> 00:18:20,360
The software can spot a pattern, a phrase, or content that fits a rule,
492
00:18:20,360 --> 00:18:23,400
but only trained people following a fair process
493
00:18:23,400 --> 00:18:25,320
can decide what the communication means
494
00:18:25,320 --> 00:18:27,320
and whether any responses needed.
495
00:18:27,320 --> 00:18:29,560
If you're starting with communication compliance,
496
00:18:29,560 --> 00:18:31,720
don't begin by trying to cover every message,
497
00:18:31,720 --> 00:18:33,480
every channel, and every employee.
498
00:18:33,480 --> 00:18:36,600
Instead, pick one real risk your organization can clearly explain.
499
00:18:36,600 --> 00:18:39,400
Maybe it's a regulated team communicating with customers,
500
00:18:39,400 --> 00:18:42,520
a defined concern around sensitive data leaving through email
501
00:18:42,520 --> 00:18:44,200
or a workplace conduct process
502
00:18:44,200 --> 00:18:47,400
that needs a better way to bring possible concerns to the right people.
503
00:18:47,400 --> 00:18:49,080
Keep the first policy small.
504
00:18:49,080 --> 00:18:50,040
Choose a focused group,
505
00:18:50,040 --> 00:18:52,840
the communication locations that truly relate to that risk,
506
00:18:52,840 --> 00:18:55,800
and reviewers who know how to handle sensitive information,
507
00:18:55,800 --> 00:18:59,000
then test the conditions before you depend on the policy in real work.
508
00:18:59,000 --> 00:18:59,960
Look at what it finds.
509
00:18:59,960 --> 00:19:01,160
Are the matches useful?
510
00:19:01,160 --> 00:19:03,400
Are reviewers seeing too many ordinary messages?
511
00:19:03,400 --> 00:19:06,520
Or is the policy missing the types of communication it was built to catch?
512
00:19:06,520 --> 00:19:10,200
Those answers help you adjust the policy based on evidence instead of guesswork,
513
00:19:10,200 --> 00:19:14,280
a thoughtful setup protects more than company data or regulatory obligations.
514
00:19:14,280 --> 00:19:16,840
It also protects employees from unfair assumptions,
515
00:19:16,840 --> 00:19:18,280
unnecessary exposure,
516
00:19:18,280 --> 00:19:21,160
and a process that treats a machine signal like a final decision.
517
00:19:21,160 --> 00:19:23,720
That's the Knowledge Nugget.
518
00:19:23,720 --> 00:19:27,480
Communication Compliance helps people review risky workplace communication
519
00:19:27,480 --> 00:19:30,280
with purpose, boundaries, and human judgment.
520
00:19:30,280 --> 00:19:32,280
Subscribe on your favorite podcast platform,
521
00:19:32,280 --> 00:19:34,120
then continue with the next Knowledge Nugget
522
00:19:34,120 --> 00:19:38,120
on how Microsoft PerView protects work across email, files, teams and AI.