Microsoft Purview Compliance Manager: Track Compliance Score, Assessments, and Improvement Actions
Compliance requirements are still complex, but the Microsoft compliance experience has changed significantly since the old Office 365 Compliance Manager days. In 2026, Microsoft Purview Compliance Manager helps organizations using Microsoft 365 understand their compliance posture, map controls to regulations, assign improvement work, collect evidence, and prepare for audits—without treating the tool as a legal guarantee of compliance.
What Microsoft Purview Compliance Manager does today
Microsoft Purview Compliance Manager is now part of the broader Microsoft Purview compliance and data governance ecosystem. It provides a centralized place to create assessments, review regulatory and standards-based templates, track improvement actions, document evidence, and monitor your Compliance Score. It is designed to help compliance, security, IT, legal, risk, and audit teams work from the same control framework instead of managing compliance tasks in spreadsheets and disconnected document libraries.
How Compliance Manager fits into Microsoft Purview
Compliance Manager is one component of Microsoft Purview. It works alongside services such as Microsoft Purview Data Loss Prevention, Microsoft Purview Information Protection, Microsoft Purview Audit, Microsoft Purview eDiscovery, Insider Risk Management, Communication Compliance, and retention capabilities. Compliance Manager helps you measure and document control implementation, while those other Purview solutions help you enforce policies, protect sensitive information, investigate activity, retain records, and respond to legal or regulatory requests.
Compliance Score: useful risk signal, not a certification
Compliance Manager uses Compliance Score to help you understand progress against selected assessments. Points are associated with improvement actions and controls. Some actions are Microsoft actions, where Microsoft provides implementation details and responsibility information for Microsoft cloud services. Others are customer actions, where your organization must configure settings, implement policies, document procedures, train users, or provide evidence. A higher Compliance Score can indicate that more recommended actions have been completed, but it does not certify that your organization is compliant with a law, regulation, or standard.
Assessments, templates, controls, and regulations
A practical way to use Compliance Manager is to start with an assessment template that maps controls to a regulation, standard, or internal framework. Depending on your licensing and availability in your tenant, templates may include Microsoft-provided options for privacy, security, and industry requirements. Each assessment organizes controls and actions so teams can see what Microsoft manages, what the customer manages, and what evidence or testing is needed. Organizations can use this structure to prioritize the most important compliance gaps and create a repeatable compliance workflow.
Improvement actions and evidence management
Improvement actions are the operational work items that help raise your Compliance Score and improve readiness. Teams can assign actions, review implementation guidance, track implementation status, record testing status, and attach evidence such as policy documents, screenshots, reports, configuration exports, or audit notes. This is especially useful when multiple teams share responsibility for compliance—for example, IT may configure Microsoft 365 controls, legal may review policies, HR may own training records, and security may validate monitoring or incident response processes.
Audit-ready documentation and reporting
Compliance Manager can help organize the documentation needed for audits or internal reviews by keeping control details, action status, testing notes, and evidence in one place. Export and reporting options may vary by current Microsoft Purview experience and licensing, but the goal remains the same: make it easier to show which controls were reviewed, what was implemented, who owns the action, what evidence supports the implementation, and what still needs remediation. For formal audits, this documentation should be reviewed by your compliance, legal, or audit advisors.
Permissions and least-privilege access
Access should be managed through Microsoft Purview role groups and the principle of least privilege. Instead of making compliance data broadly available to any user, organizations should grant access only to the stakeholders who need it, such as compliance managers, security administrators, legal reviewers, auditors, or action owners. Microsoft Entra ID should be used to manage identity, conditional access, multifactor authentication, privileged access processes, and governance for the accounts that administer Microsoft Purview and Microsoft 365 compliance settings.
Licensing considerations in 2026
Compliance Manager availability and capabilities depend on your Microsoft 365, Office 365, Enterprise Mobility + Security, and Microsoft Purview licensing. Some assessment templates or advanced compliance capabilities may require specific plans or add-on licensing. If you buy Microsoft cloud subscriptions through the Cloud Solution Provider program, Microsoft NCE terms, commitment periods, and add-on compatibility should be reviewed before making licensing changes. The safest approach is to confirm the required features, template availability, and user licensing before launching a compliance program.
Shared responsibility still matters
Compliance Manager is built around the shared responsibility model. Microsoft operates and documents many controls for Microsoft cloud services, but your organization remains responsible for customer-managed controls, tenant configuration, identity governance, data classification, endpoint and device policies, retention decisions, user training, business processes, and legal interpretation. Compliance Manager can help you manage and document those responsibilities, but it does not replace legal advice, risk management, or an audit program.
A practical 2026 starting point
If your organization already uses Microsoft 365, start by identifying the regulations or internal frameworks that matter most, confirming the required Purview licensing, creating a small number of priority assessments, assigning clear owners for improvement actions, and collecting evidence as work is completed. From there, use Compliance Score trends and unresolved actions to guide your roadmap for Microsoft Purview Data Loss Prevention, Information Protection, Audit, eDiscovery, Defender for Cloud Apps, and Microsoft Entra ID security improvements.
Key takeaways
- Microsoft Compliance Manager is now part of Microsoft Purview and is accessed through the modern Purview compliance experience.
- Compliance Score helps track progress against assessments and improvement actions, but it is not a guarantee or certification of compliance.
- Assessments, templates, controls, improvement actions, evidence, implementation status, and testing status help teams organize compliance work.
- Permissions should be managed with Microsoft Purview role groups and least-privilege access, supported by Microsoft Entra ID security controls.
- Licensing varies by Microsoft 365 and Microsoft Purview plan, and some templates or advanced capabilities may require additional licensing.
Need help turning Microsoft Purview Compliance Manager into a working compliance program? IT Partner can review your Microsoft 365 tenant, validate licensing, configure Purview roles, create priority assessments, and build a practical improvement-action roadmap for your compliance and security teams.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.