Compliance Manager
Microsoft Purview Compliance Manager is your compliance command center—providing a risk-based compliance score, pre-built regulatory assessments, and actionable improvement recommendations. Track your organization's progress toward meeting regulatory requirements like FERPA, HIPAA, and NIST.
What is Compliance Manager?
Compliance Manager provides:
| Feature | What It Does |
|---|---|
| Compliance Score | Overall measure of your compliance posture (0-100%) |
| Assessments | Pre-built templates for regulations and standards |
| Improvement Actions | Specific steps to improve compliance |
| Evidence Management | Store documentation for audit readiness |
Compliance Score
Your score represents progress toward compliance goals:
| Component | Impact |
|---|---|
| Microsoft-managed controls | Actions Microsoft takes (infrastructure security) |
| Customer-managed controls | Actions you take (policies, configurations) |
| Improvement actions | Completing actions increases score |
| Failed assessments | Reduce score until remediated |
The compliance score is a relative measure of your configuration against Microsoft's recommendations. It doesn't guarantee regulatory compliance—that requires legal and compliance review.
Assessment Templates
| Regulation | Relevance |
|---|---|
| FERPA | Student educational records protection |
| HIPAA | Health information (campus health services) |
| NIST 800-171 | Controlled unclassified information (CUI) |
| NIST CSF | General cybersecurity framework |
| CMMC | Defense contractor requirements |
| GDPR | EU data protection (international students/staff) |
| Microsoft 365 Baseline | General security best practices |
Key Capabilities
Dashboard
At-a-glance view of:
- Overall compliance score
- Top improvement actions
- Assessment progress by regulation
- Trend over time
Improvement Actions
Each action includes:
- Description and business value
- Implementation guidance
- Points value toward score
- Testing status
Evidence Management
Upload documentation proving control implementation:
- Policy documents
- Configuration screenshots
- Audit reports
- Training records
Assessment Reports
Export assessments for:
- Audit preparation
- Leadership reporting
- Third-party verification
Getting Started
| Step | Action |
|---|---|
| 1 | Review Microsoft 365 baseline assessment |
| 2 | Add assessments for applicable regulations |
| 3 | Assign improvement actions to owners |
| 4 | Implement actions and mark complete |
| 5 | Upload evidence for completed actions |
| 6 | Review and retest periodically |
Quick Links
| Resource | Description |
|---|---|
| Purview Compliance Manager | Assessment dashboard |
| Compliance Manager Overview | Microsoft documentation |
| Implementation Guide | Enterprise deployment guide |
Related Solutions
- Audit — Activity logging for compliance evidence
- Information Protection — Controls assessed by Compliance Manager
- Data Loss Prevention — Controls assessed by Compliance Manager