Microsoft Purview Communication Compliance Implementation
Microsoft Purview Communication Compliance Implementation is a fixed-price, two-week engagement that puts supervision on what people actually say in Microsoft Teams, Exchange email, Viva Engage and Microsoft 365 Copilot and Copilot Chat prompts and responses — and gives your compliance, HR and IT leads a review process they can defend. IT Partner verifies licensing for every supervised user, designs up to five policies from Microsoft's templates and your own keyword, sensitive-information and classifier conditions (financial regulatory conduct, harassment and threats, sensitive-information sharing, conflict-of-interest walls between two groups, Copilot interactions), configures the reviewer role groups with pseudonymized usernames on by default, builds the escalation path — notify the user, escalate to an investigator, remove a Teams message, open an eDiscovery Premium case — pilots it on agreed groups, and hands over the reports and audit trail that show supervision happened. $3,950 per project for one tenant, two weeks. We configure the platform and teach your reviewers to run it; the employee notice, what your organization may lawfully monitor and what happens after a confirmed violation belong to your HR and counsel, and the Microsoft licensing every supervised user needs is yours.
What this engagement is
Every organization already records what its people say in Teams and email; almost none of them review it until something has gone wrong. A broker-dealer's written supervisory procedures require review of correspondence and internal communications under FINRA Rule 3110. An HR department that learns a harassment complaint was preceded by weeks of visible messages has a duty-of-care problem, not a technology problem. A finance team pasting customer data into a group chat, or a user asking Microsoft 365 Copilot to summarize a document they should never have had, is a data-handling violation nobody sees because nobody is looking. Microsoft Purview Communication Compliance is the Purview solution built for exactly this: it evaluates messages against policies you define and routes the matches to named reviewers, with a record of what was reviewed, by whom, and what was done — supervision in the regulatory sense of the word, on the platform you already pay for. A policy is a scope plus conditions plus reviewers. The scope is a set of users or groups and the channels to evaluate: Teams 1:1 and group chats and standard, private and shared channels; Exchange Online mailboxes; Viva Engage private messages and community conversations for networks in native mode; and Microsoft 365 Copilot and Copilot Chat prompts and responses. Conditions are keyword dictionaries, Purview sensitive information types, and Microsoft's trainable classifiers — Discrimination, Profanity, Threat and Targeted harassment on the conduct side, and the financial-conduct classifiers behind the regulatory template — plus image classifiers for adult and racy content, applied inbound, outbound or internally with a review percentage you choose. Microsoft ships templates for the common cases (inappropriate text, inappropriate images, financial regulatory compliance, conflict of interest between two groups, sensitive information, and a dedicated Microsoft 365 Copilot interactions template); we start from those and tune them to your vocabulary and your risk. Review is privacy-aware by design: usernames are pseudonymized for analysts by default, investigators are the only role that sees real names, every reviewer action lands in the Purview audit log, and the actions themselves — resolve, notify with a template you approve, escalate, remove a message in Teams, or open an eDiscovery Premium case — are the same whether the trigger was a threat, a stock tip or a Copilot prompt. The engagement runs two weeks and is deliberately sequenced around the people who own the policy rather than the console. Day one is licensing: Communication Compliance requires a Microsoft 365 E5-level license or the E5 Compliance or E5 Insider Risk Management add-on for every user whose communications are in scope, and we put in writing exactly who is covered before a single policy exists. Days two and three are the design session with your compliance, HR and, where you want them, legal stakeholders: which populations, which channels, which of the up-to-five policies, who reviews, and the pseudonymization decision. Then we build, pilot with seeded test messages across every channel in scope (including Copilot prompts), tune the noise down, exercise every remediation action once, and walk your reviewers through the reports and audit entries an examiner or an HR case file will ask for. You leave with a running queue, a runbook, and the technical description of what is collected that your counsel needs to write the employee notice. What this is not. It is not a monitoring service IT Partner operates for you — your reviewers work the queue after handover, and the page says so plainly. It is not employment-law or regulatory advice: what your organization may lawfully monitor, in which jurisdictions, with what disclosure, and whether FINRA or SEC supervision obligations apply to you are questions for your counsel; we build the controls counsel decides on. It is not Insider Risk Management, which scores what people do with files rather than what they say. And it does not capture channels outside Microsoft 365 — WhatsApp, SMS and Bloomberg chat need Purview data connectors and partner-vendor licensing that we design in the FINRA and SEC 17a-4 engagement and quote separately.
Success criteria
What you receive
How the work unfolds
Confirm the in-scope population against licensing user by user, verify Purview audit and Viva Engage network mode, check Microsoft 365 Copilot licensing where Copilot prompts are in scope, assign the role groups, and agree the pilot groups and test plan.
Working session with your compliance, HR and (where you want them) legal stakeholders: populations, channels, the policy list (up to five), conditions and review percentage per policy, who reviews, the pseudonymization decision, notice wording ownership, and what the escalation path looks like for a confirmed violation. Scheduling this session is the critical path of the two weeks.
Configure the privacy setting, build the policies from templates and custom conditions, set reviewers and notice templates, and connect the Copilot and Viva Engage locations. Policies take up to an hour to activate and up to a day to begin capturing; nothing sent before activation is evaluated, so the pilot starts the following business day.
Seed test messages for every policy across Teams, email, Viva Engage and Copilot prompts as agreed; review the resulting alerts with your reviewers; count false positives; tune keywords, sensitive-information thresholds, classifier conditions, direction and exclusions; and exercise each remediation action once — including a Teams message removal and an eDiscovery Premium case created from an alert.
Walk through the built-in reports and the Purview audit-log entries for reviewer actions, document the procedure for producing them on request, and deliver the runbook and the employee-notice input pack.
Recorded training for reviewers and admins, the configuration summary, the open-decisions list with owners, and the queue handed to your named reviewers. Success is your team working the next real alert without calling us.
Prerequisites
Who does what
IT Partner
- Verify licensing, audit and role-group prerequisites user by user before building anything, and state coverage and gaps in writing.
- Facilitate the design session and produce the design document your stakeholder signs off.
- Configure the privacy setting, role groups, policies, conditions, reviewers, notice templates and workload coverage.
- Run the pilot with seeded messages, review the alerts with your reviewers, count false positives and tune.
- Exercise every remediation action in the runbook once, including Teams message removal and eDiscovery Premium case creation.
- Deliver the reports and audit walkthrough, the runbook, the employee-notice input pack, the handover session and the configuration summary.
- Say plainly which channels, users and message types are not covered under your licensing and configuration.
Your team
- Provide licensing and administrative access, and remediate licensing gaps identified on day one or accept a narrower scope.
- Make the compliance or HR stakeholder and the reviewers available for the design session, the pilot review and the handover.
- Decide the policy list, conditions, review percentage, reviewers, the pseudonymization setting and the notice wording — with counsel where appropriate.
- Own the employee-notice and monitoring-disclosure position, and the lawfulness of monitoring in each jurisdiction where you operate.
- Work the alert queue after handover and act on confirmed violations — HR action, regulatory escalation or legal action are your decisions.
- Purchase and maintain Microsoft licensing for supervised users, and pay Microsoft's pay-as-you-go meters where you enable coverage of Copilot Studio agents or other AI applications.
- Revisit conditions, reviewer assignments and populations as staff and risks change.
What's not included
Limitations & technical notes
Frequently asked questions
What is Communication Compliance, and how is it different from Insider Risk Management?
Communication Compliance evaluates what people say — Teams messages, email, Viva Engage posts, Copilot prompts and responses — against policies for regulatory conduct, harassment and threats, sensitive-information sharing and conflicts of interest, and routes matches to named reviewers with an audited workflow. Insider Risk Management scores what people do with data over time — downloads, uploads to personal cloud, USB copies — into a per-user risk level. They are separate Purview solutions with separate role groups and separate policies; many regulated firms run both. This engagement is the communications half; the Insider Risk Management half is its own two-to-four-week project.
What licensing do we need, and do the reviewers need it too?
Every user whose communications are in scope of a policy — senders and in-scope recipients — needs Microsoft 365 E5, A5, F5 or G5, or an E3-level license with the E5 Compliance add-on or the E5 Insider Risk Management add-on. That is the rule we verify user by user on day one, and it is why regulated firms often license the supervised population — registered representatives, traders, client-facing staff — rather than everyone. Whether the reviewers themselves need the license depends on whether their own communications are in scope; we check that with you at design rather than assuming. Licensing is purchased from Microsoft or your CSP and is not part of this fee.
Can it monitor Microsoft 365 Copilot prompts? Which Copilot surfaces are covered?
Yes. Communication Compliance policies can evaluate the prompts users type into Microsoft 365 Copilot and Copilot Chat and the responses they get back, and Microsoft ships a dedicated Microsoft 365 Copilot interactions template for it; Microsoft states there is no additional Purview pay-as-you-go charge for Microsoft 365 Copilot data. Copilot Studio agents and other connected AI applications can also be brought under a policy, but that coverage runs on Microsoft Purview pay-as-you-go billing against an Azure subscription in your tenant — a metered charge from Microsoft to you, which we enable only with your written go-ahead. The list of covered AI surfaces is one of the fastest-moving parts of Purview, so we confirm it in your tenant during the licensing review rather than promising it here.
Which Teams conversations are covered — private channels, shared channels, group chats?
Policies cover 1:1 and group chats and standard, private and shared channels for users in scope; Microsoft documents that shared channels are handled without extra configuration and that modern attachments in private chats and private channels can be analyzed. What is not covered is anything outside the tenant — a personal WhatsApp group, SMS, a consumer Teams account — unless a Purview data connector is licensed and configured for that source, which this engagement designs only as a follow-on.
Are Viva Engage private messages in scope?
Microsoft documents that Communication Compliance supports both private messages and community conversations in Viva Engage, with one condition: the network must be in native mode. We check the network mode on day one; if your Viva Engage is still in a legacy mode, the conversion is a separate decision with its own implications for the network, and we say so rather than quietly leaving Viva Engage out.
Does it scan messages we have already sent? How quickly does it detect new ones?
No — policies evaluate communications from the point they are active, not historically. Microsoft documents up to an hour for a policy to activate and up to 24 hours for it to begin capturing, and about a day for email to process; Microsoft has been reducing detection-to-investigation time and we tell you the current figure at handover. If you need to search what was said last quarter, that is an eDiscovery question, and eDiscovery Search Assistance is the right tool.
What can a reviewer actually do with an alert?
Resolve it, tag it (compliant, non-compliant, questionable), notify the sender with a template your HR or compliance team approved, escalate it to an investigator, remove the message from Teams (the message is replaced with a policy tip), escalate it for investigation — which creates an eDiscovery Premium case from the selected messages — or trigger a Power Automate flow, for example to notify a manager. Every one of those actions is recorded in the Purview audit log with the reviewer's identity, and every one is exercised at least once during the pilot so the runbook describes something your team has done, not read about.
How is employee privacy protected?
Three controls, configured from day one: usernames are pseudonymized for analysts by default, so the first tier of review sees patterns rather than names and only the Investigators role sees who sent what; access to alerts and messages is limited to the named role groups we configure; and reviewer actions are themselves audited. Whether to keep pseudonymization on, and who holds the Investigators role, are decisions your stakeholder makes in the design session and we record — and we would rather that conversation happen with your HR and counsel in the room than after the first alert.
Is it legal to monitor our employees' messages, and do we have to tell them?
That depends on your jurisdictions, your employment agreements and, in some countries, employee-representative consultation — which is exactly why we do not answer it for you and why legal advice is explicitly out of scope. What we do provide is the precise technical description counsel needs: what is collected, from which channels, who can see it, how long review evidence is kept and what happens on an alert. Most US organizations proceed with a written policy and a notice; multinational tenants usually scope policies by country after taking advice. The controls are ours to build; the disclosure is yours to make.
We are a broker-dealer. Does this satisfy FINRA Rule 3110 supervision?
It gives you the supervisory review workflow inside Microsoft 365 — a defined population, a defined review percentage, documented reviewers, and an audit trail of what was reviewed and what was done — which is the mechanism most written supervisory procedures describe. Whether it satisfies your obligations is your compliance officer's and counsel's determination, not ours, and we will not put 'compliant' in writing. Supervision is one control of several a regulated firm needs; retention with Preservation Lock, regulatory records and the evidence pack are the FINRA and SEC 17a-4 Compliance for Microsoft 365 engagement, and this service is the supervision layer of that design.
What about WhatsApp, SMS and Bloomberg chat?
Out of scope here, and important enough to say twice. Communication Compliance can evaluate third-party sources — WhatsApp, SMS, Bloomberg and others — only once a Purview data connector and its partner-vendor capture service are licensed and configured; that is separate licensing, a separate design and a separate quote. For regulated firms it is designed inside the FINRA and SEC 17a-4 engagement. And no connector fixes off-channel behaviour: conduct rules and device policy do that, which is a conversation for your compliance officer rather than a console.
Why up to five policies? What does one policy look like?
Five is what the fixed fee is sized for, and it covers the great majority of first deployments: for example, one regulatory-conduct policy for client-facing staff, one inappropriate-content policy for everyone, one sensitive-information policy for finance and HR, one conflict-of-interest policy between two named groups, and one Microsoft 365 Copilot interactions policy for a pilot group. A policy is a population, a set of channels, a direction, a review percentage, conditions — keywords, sensitive information types, classifiers — and named reviewers. Everything about a policy after handover is yours to adjust, and additional policies are quoted in writing if you want us to build them.
How noisy will the alert queue be?
Honestly, noisy at first if it is tuned badly and manageable if it is tuned well — which is what the pilot is for. Keyword lists catch context they should not, classifiers have confidence thresholds, and the review percentage on a regulatory policy sets how much of the population's mail your supervisors actually see. We seed test messages, count false positives with your reviewers, and adjust conditions and exclusions before handover. Alert volume is also why we insist on named reviewers from compliance or HR rather than an IT mailbox: the queue needs people who can judge context.
Can it block a message before it is sent?
No. Communication Compliance evaluates messages after they are sent and gives reviewers actions to take, including removing a Teams message after the fact. Preventing a message from leaving in the first place — blocking a credit card number in chat, warning before an external email with a client list — is data loss prevention, a different Purview solution with a different design; that is Configure and Enable DLP Policies. The two are complementary: DLP stops the obvious, Communication Compliance supervises the rest.
Who watches the queue after the two weeks?
Your reviewers, using the runbook and the recorded handover — the service deliberately builds an in-house capability rather than a dependency on us. If you want help later with a stuck case, a new condition or a reviewer change, our published hourly rate covers it; if you also need monthly evidence collection for a compliance framework, the Compliance Evidence and Audit Readiness Retainer does that — though it does not review your messages, and neither, after handover, do we.