A unified data governance solution that helps manage, protect, and discover data across your organization
Use UAT to validate the configuration and process, not to prove coverage of sensitive data that does not exist there.
Recommended approach:
- Keep the current UAT scan and validate the scan pipeline end to end
- In Purview, confirm the Dataverse source is registered, the scan runs successfully, and the assets appear in the Unified Catalog.
- For the Dataverse scan, use Data Map > Sources, select the Dataverse source, create or review the scan, choose the correct integration runtime, credential, collection, run Test connection, and then Save and run.
- After the run, check Last run status, scanned asset counts, and classified asset counts.
- This validates connectivity, scan scope, scheduling, and catalog ingestion.
- Configure classification deliberately before relying on scan results
- In Purview Data Map, classifications can be assigned automatically through the scan rule set or manually after metadata ingestion.
- Before scanning, define which classifications are actually needed. Microsoft recommends avoiding unnecessary labels because they create noise and can mislead data consumers.
- If the goal is to detect more sensitive patterns, configure the appropriate scan rule set with relevant system or custom classifications before the next scan.
- Do not expect UAT to validate discovery of data patterns that are not present
- Purview classification depends on the data that is scanned. If a sensitive data type is absent from UAT, it will not be discovered there.
- For complete validation of classification outcomes, a representative sanitized or masked production-like dataset in UAT is the practical approach, because it allows the scan to encounter the same kinds of values and structures expected in production.
- Separate metadata classification in Purview from protective labeling
- For scanned data sources in Purview, such as registered sources in the Data Map, Purview can apply metadata-only sensitivity labels to catalog entries.
- These labels do not encrypt or restrict the source data. They indicate sensitivity in the catalog and can support governance workflows.
- For Microsoft 365 data, protective labels are applied through Microsoft Purview Information Protection.
- The context provided does not establish that Dataverse scan classification directly auto-applies protective sensitivity labels back into Dataverse records. What is supported here is classification in Data Map and metadata labeling of scanned assets.
- Plan production validation as a controlled rollout
- Use UAT to validate:
- source registration
- scan scope
- credentials and connectivity
- collection placement
- scan schedules
- scan rule sets and expected classifications on available test data
- catalog visibility of assets and classifications
- Use a production-like sanitized dataset in UAT, if possible, to validate broader classification coverage.
- Then enable scanning on the full production Dataverse source and review the resulting asset and classification coverage in the Unified Catalog.
- Use UAT to validate:
- Keep classification current with recurring scans
- Classification should be maintained operationally. Microsoft recommends regular review because stale metadata can lead to incorrect outcomes.
- For Dataverse, set up scheduled scans so schema and content changes are re-evaluated over time.
- Power BI reporting
- The provided context supports that scan results, assets, and classifications are visible in the Unified Catalog and that Dataverse assets can be browsed and searched there.
- The provided context does not contain a documented method for connecting Purview scan/classification/label results directly to Power BI for graphical reporting.
Practical decision for this scenario:
- Yes: use the current UAT environment to validate the Purview setup and scan behavior.
- Best next step: obtain a sanitized or masked production-like copy for UAT if complete classification validation is required before production.
- Then: configure and test scan rule sets and metadata labeling in UAT, and finally run the full scan in Production to validate actual coverage against the real dataset.
This is the clearest split between environments:
- UAT: validate configuration, scan execution, rule sets, and expected classification behavior on available or sanitized representative data.
- Production: validate actual enterprise-wide discovery and final classification coverage on the full Dataverse dataset.