Get started with content explorer
Microsoft 365 compliance is now called Microsoft Purview and the solutions within the compliance area have been rebranded. For more information about Microsoft Purview, see the blog announcement and the What is Microsoft Purview? article.
Content explorer allows you to natively view the items that were summarized on the overview page.
For licensing requirements, see Information Protection: Data Classification Analytics: Overview Content & Activity Explorer
In order to get access to the content explorer tab, an account must be assigned membership in any one of these roles or role groups.
Microsoft 365 role groups
- Global administrator
- Compliance administrator
- Security administrator
- Compliance data administrator
Membership in these role groups does not allow you to view the list of items in content explorer or to view the contents of the items in content explorer.
Only Global admins can manage or assign permissions to other users in the compliance portal. For more information, see Permissions in the Microsoft Purview compliance portal.
Required permissions to access items in content explorer
Access to content explorer is highly restricted because it lets you read the contents of scanned files.
These permissions supercede permissions that are locally assigned to the items, which allows viewing of the content.
There are two roles that grant access to content explorer and it is granted using the Microsoft Purview compliance portal:
Content Explorer List viewer: Membership in this role group allows you to see each item and its location in list view. The
data classification list viewerrole has been pre-assigned to this role group.
Content Explorer Content viewer: Membership in this role group allows you to view the contents of each item in the list. The
data classification content viewerrole has been pre-assigned to this role group.
The account you use to access content explorer must be in one or both of the role groups. These are independent role groups and aren't cumulative. For example, if you want to grant an account the ability to view the items and their locations only, grant Content Explorer List viewer rights. If you want that same account to also be able to view the contents of the items in the list, grant Content Explorer Content viewer rights as well.
You can also assign either or both of the roles to a custom role group to tailor access to content explorer.
A Global admin, can assign the necessary Content Explorer List Viewer, and Content Explorer Content Viewer role group membership.
Roles and Role Groups in preview
There are roles and role groups in preview that you can test out to fine tune your access controls.
Here's a list of applicable roles that are in preview. To learn more about them, see Roles in the Security & Compliance Center
- Information Protection Admin
- Information Protection Analyst
- Information Protection Investigator
- Information Protection Reader
Here's a list of applicable role groups that are in preview. To learn more, see Role groups in the Security & Compliance Center
- Information Protection
- Information Protection Admins
- Information Protection Analysts
- Information Protection Investigators
- Information Protection Readers
Content explorer shows a current snapshot of the items that have a sensitivity label, a retention label or have been classified as a sensitive information type in your organization.
Sensitive information types
A DLP policy can help protect sensitive information, which is defined as a sensitive information type. Microsoft 365 includes definitions for many common sensitive information types from across many different regions that are ready for you to use. For example, a credit card number, bank account numbers, national ID numbers, and Windows Live ID service numbers.
A sensitivity label is simply a tag that indicates the value of the item to your organization. It can be applied manually, or automatically. Once applied, the label gets embedded in the document and will follow the document everywhere it goes. A sensitivity label enables various protective behaviors, such as mandatory watermarking or encryption.
Sensitivity labels must be enabled for files that are in SharePoint and OneDrive in order for the corresponding data to surface in the data classification page. For more information, see Enable sensitivity labels for Office files in SharePoint and OneDrive.
A retention label allows you to define how long a labeled item is kept and the steps to be taken prior to deleting it. They're applied manually or automatically via policies. They can play a role in helping your organization stay in compliance with legal and regulatory requirements.
How to use content explorer
- Open Microsoft Purview compliance portal > Data classification > Content explorer.
- If you know the name of the label, or the sensitive information type, you can type that into the filter box.
- Alternately, you can browse for the item by expanding the label type and selecting the label from the list.
- Select a location under All locations and drill down the folder structure to the item.
- Double-click to open the item natively in content explorer.
The export control will create a .csv file that contains a listing of whatever the focus of the pane is.
It can take up to seven days for counts to be updated in content explorer.
When you drill down into a location, such as an Exchange or Teams folder, or a SharePoint or OneDrive site, the Filter tool appears.
The scope of the search tool is what is displaying in the All locations pane and what you can search on varies depending on the selected location.
When Exchange or Teams is the selected location, you can search on the full email address of the mailbox, for example
When either SharePoint or OneDrive are selected location, the search tool will appear when you drill down to site names, folders and files.
You can search on:
|full site name||
|text at the beginning of file name||
|text after an underscore character ( _ ) in file name||
Submit and view feedback for