Microsoft Purview Retention at Scale
Design and operate enterprise-grade retention across Microsoft 365
Translate Privacy Act 1988 record-keeping obligations and OAIC guidance into a defensible Microsoft Purview retention programme that scales across SharePoint, OneDrive, Teams, and Exchange without breaking collaboration.

At a Glance
Who it's for
- SharePoint and Teams governance leads operating Microsoft 365 at enterprise scale
- Records managers translating retention and disposal schedules into Purview policy
- Compliance officers aligning the organisation to Privacy Act 1988 and OAIC APP 11
- Microsoft 365 administrators rolling out retention labels, auto-apply, and records management
Course Details
Course Overview
Microsoft Purview Retention at Scale is a two-day intensive that takes governance and compliance practitioners from retention fundamentals to an operating model that holds up under audit, e-discovery, and regulator scrutiny. You will design a defensible retention taxonomy for an Australian organisation, deploy auto-apply rules using KQL, sensitive information types, and trainable classifiers, and stand up records management with declaration, disposition review, and event-based retention. The programme is grounded in Microsoft Learn guidance for Purview Data Lifecycle Management and Records Management, OAIC retention and destruction advice, and the record-keeping expectations of the Privacy Act 1988. Microsoft Purview Retention at Scale is Module 3 of 6 in the EDUC4TE Purview Training Track, complementing Module 2 (Data Protection Practitioners) and feeding into Module 6 (Enterprise Architecture).
What You'll Learn
Course Curriculum
Module 1: Retention concepts in Microsoft Purview
180 min- Retention labels versus retention policies and when to use each
- Supported locations: SharePoint, OneDrive, Teams chats and channel messages, Exchange, Microsoft 365 Groups
- Policy precedence and conflict resolution (retain wins, longest wins, explicit over implicit, label over policy)
- Adaptive versus static policy scopes and what they mean operationally
- Reference: Microsoft Learn — Learn about retention policies and retention labels (updated 2025)
Module 2: Designing the retention taxonomy for an Australian organisation
180 min- Mapping business functions and record classes to a Purview label taxonomy
- Aligning labels to Privacy Act 1988 record-keeping obligations and OAIC APP 11 destruction guidance
- Working with state and territory public records schedules where relevant
- Taxonomy patterns that avoid label sprawl and remain usable in Teams and SharePoint
- Reference: OAIC — Australian Privacy Principles guidelines, Chapter 11 (Security of personal information), current edition
Module 3: Auto-apply rules with KQL, sensitive info types, and trainable classifiers
240 min- Authoring KQL queries for auto-apply policies across SharePoint and Exchange
- Choosing built-in versus custom sensitive information types for Australian data (TFN, Medicare, ABN, driver licence)
- Training and validating Purview trainable classifiers for organisation-specific content
- Pilot rollout, simulation mode, and measuring precision and recall before enforcement
- Reference: Microsoft Learn — Apply a retention label to content automatically (updated 2025)
Module 4: Records management: declaration, disposition, and event-based retention
180 min- Records versus regulatory records and the implications of each
- Label-based and user-driven declaration patterns
- Disposition review workflows with multi-stage reviewers and proof of destruction
- Event-based retention for contracts, employee records, and project closeout
- Reference: Microsoft Learn — Learn about records management in Microsoft Purview (updated 2025)
Module 5: Audit, eDiscovery readiness, and Privacy Act 1988 alignment
180 min- Using Purview Audit (Standard and Premium) to evidence retention activity
- Content search and eDiscovery (Premium) workflows that respect holds and retention
- Mapping the operating model to OAIC APP 11, Privacy Act 1988, and ACSC ISM data retention guidance
- Notifiable Data Breaches scheme implications when retained data is in scope
- Reference: OAIC — Notifiable Data Breaches scheme guidance; ACSC Information Security Manual (current release)
- Track positioning: handover into Module 4 (Insider Risk) and Module 6 (Enterprise Architecture) for end-to-end data protection coverage
Who Should Attend
- SharePoint and Teams governance leads
- Records managers and information governance specialists
- Compliance, privacy, and risk officers
- Microsoft 365 administrators with a compliance remit
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Practical Microsoft 365 administration experience
- • Exposure to the Microsoft Purview compliance portal
- • Awareness of Australian privacy and records-keeping obligations
Delivery, Format and Logistics
Delivery Mode
Two-day intensive (virtual)
Two-day intensive — virtual cohort with hands-on labs and live Q&A
What You'll Need
- Working knowledge of Microsoft 365 (SharePoint, Teams, Exchange, OneDrive)
- Familiarity with Microsoft Purview compliance portal
- Access to a Microsoft 365 E5 (or Compliance add-on) tenant for labs
- Basic understanding of Australian privacy and records obligations
What You'll Receive
- 16 hours of instructor-led training across two consecutive days
- Hands-on labs in a Microsoft 365 compliance tenant
- Retention taxonomy worksheet aligned to Australian record classes
- KQL and sensitive information type pattern library
- Disposition review and event-based retention playbook
- Certificate of completion suitable for CPD claims
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Two-day intensive (virtual)
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 16 hours of instructor-led training across two consecutive days
- Hands-on labs in a Microsoft 365 compliance tenant
- Retention taxonomy worksheet aligned to Australian record classes
- KQL and sensitive information type pattern library
- Disposition review and event-based retention playbook
- Certificate of completion suitable for CPD claims
Have questions about this course?