From discovery
to automation.
DataMapper finds sensitive data across Outlook, OneDrive and SharePoint — then applies Microsoft Purview sensitivity labels through the Graph API. Purview takes it from there: retention, encryption, deletion, movement. Two systems, one closed loop. Live in weeks, not quarters.
The classification problem is solved. The labelling problem is solved. The enforcement engine exists in every Microsoft 365 tenant. What's been missing is the layer that connects them — at a price and a pace your business can absorb.
— The thesis behind DataMapper × Microsoft Purview
The visibility gap
CPRs, passport numbers, health records, financial details — all drifting across Outlook, OneDrive, SharePoint and shared mailboxes, attached to files no one has opened in five years. Manual audits can't keep pace.
The action gap
Microsoft Purview is a powerful enforcement engine — but it relies on labels someone has to assign. Without an accurate, automated source of labels, Purview policies have nothing to act on.
The expensive-project trap
Most data-governance programmes are 12–18 month consulting engagements that produce a strategy deck and a six-figure invoice. We've yet to meet a CISO who wants another one. This integration delivers running policies in weeks.
See it in two minutes.
A short walkthrough of how DataMapper finds sensitive data and hands it to Microsoft Purview for enforcement.
Three stages.
One closed loop.
DataMapper discovers what's there. The Graph API labels it. Purview decides what happens next. Each step is auditable and reversible.
Find what's hiding in plain sight.
DataMapper scans across the entire Microsoft 365 estate — every mailbox, every SharePoint site, every OneDrive — at machine speed. The detection engine combines RegEx pattern matching and machine learning to surface candidate findings, then uses Azure OpenAI's embedding model to vectorize each candidate's surrounding context and classify it against a curated taxonomy of sensitive concepts. Vectors are discarded after classification, keeping sensitive data from being copied across systems.
- All file types — PDF, Word, Excel, PowerPoint, images, emails, attachments. OCR for scanned documents is built in.
- Multilingual — Danish, English, German, Swedish, Norwegian and more, with regional risk patterns recognised natively.
- Risk taxonomy — CPR, passport, driver's licence, bank card, health records, union membership, sexual orientation.
- Clean review UI — end users triage findings in minutes, no compliance training required.
Speak Purview's native language.
Every finding is translated into a Microsoft Purview sensitivity label and written back to the file or email through the Microsoft Graph API. Use the labels you've already published in your tenant, or import our GDPR-aligned recommended set as a starting point.
- Bring your own labels — DataMapper maps to any sensitivity label your organisation already runs in Purview.
- Or start clean — deploy our recommended GDPR-aligned label set in under a day.
- 24/7 monitoring — new files are labelled as they appear, not on a quarterly sweep.
- No E5 across every seat — labelling runs server-side. End users keep the licences they already have.
assignSensitivityLabel — 200 OK
Let Purview do the work.
Once the label is on the file, Microsoft Purview's policy engine takes over. Encryption, retention, deletion, conditional access — every action your DPO or CISO has already designed kicks in automatically. No new tooling, no new dashboards to learn.
- Predefined templates — deploy common GDPR retention and protection rules via script in minutes.
- Granular control — act on label + location + age + user attributes.
- Auditable — every enforcement event is recorded in Purview's compliance centre. Your DPO's evidence trail builds itself.
- Reversible — labels and actions can be tuned, suppressed or rolled back from the same Purview admin surface.
Not a slide.
A track record.
Numbers from a live deployment on a Nordic mid-market customer — a comparable Microsoft 365 estate to most enterprises evaluating this integration today.
30M+ files. 3 weeks.
One Nordic customer. Across Outlook, OneDrive and SharePoint — every mailbox, every site, every drive — scanned, classified and labelled in under a month. Then handed back to the business with an interface their staff actually wanted to use.
Eighty per cent of the cleanup workload disappears into automation. The remaining twenty per cent is what the business actually wants to decide on — recent, high-stakes, contextual. That ratio is what makes data governance survive past month three.
Observation · DataMapper deployment, Nordic enterprise · 2026
A path you can stop at any time.
Four phases. The first one costs you almost nothing and proves the rest. Most customers run the pilot inside three weeks and decide on the back of evidence, not a slide deck.
A handful of mailboxes, one OneDrive, one SharePoint site. Real findings on real data, with a small ruleset. No commitment beyond the pilot.
- Read-only Graph authorisation
- 3–5 sensitivity labels live
- First Purview policy enforcing
- Go / no-go decision in week 3
Outlook, OneDrive and SharePoint across the tenant. Starter policy templates for GDPR retention, encryption and movement.
- Full M365 coverage
- Department-level dashboards
- End-user review interface live
- First measurable risk reduction
Network drives, shared mailboxes, on-premise file shares. Brought in as named paths, each with an accountable owner.
- Network drive scanning
- Path-level ownership
- Migration-aware policies
- Quarterly reporting cadence
Azure Logic Apps connectors wire findings into Dynamics 365, ServiceNow, ITSM and the rest of your stack. Continuous tuning of rules as your taxonomy matures.
- Logic Apps event triggers
- Dynamics 365 / ERP feed
- Custom workflow templates
- Continuous tuning
What this looks like
Built so the business can drive it.
- ✓End-users see only what concerns them — their files, their findings, decisions in minutes.
- ✓Department leaders get tailored dashboards. IT stays in control, the business stays accountable.
- ✓Predictable scan price. No surprise consulting hours.
- ✓Live policies inside the first month. Measurable risk reduction inside the first quarter.
What this is NOT
And what you've already paid for before.
- ✕Not a 12-month consulting engagement ending in a strategy deck.
- ✕Not an IT-only initiative the business will quietly ignore.
- ✕Not E5 licensing across every employee just to enable auto-labelling.
- ✕Not a rip-and-replace of your existing Microsoft governance stack.
Four outcomes.
First quarter.
Not year three. Not after a steering committee. The first three months.
Context-aware embeddings classify each candidate against its surrounding text — not just keyword matches. Calibrated on real GDPR-labelled corpora and tuned to minimise false positives — the metric that decides whether your team actually uses the system.
The people who know what a file means decide its fate. IT keeps oversight and reporting; the business does the calls. The result is adoption that survives the first hard quarter.
No need to roll E5 out to every employee just to enable auto-labelling. DataMapper provides the labels server-side at a fixed scan price — you keep your existing licence mix.
Days for the pilot, weeks for the first production rollout, not months. Authorise the Graph connection, choose or import your labels, run a first scan. Most customers see live enforcement inside the first week.
Beyond the Microsoft estate.
Your governance story doesn't end at Microsoft 365. Native connectors and partnerships let DataMapper feed classification events into the systems that already run your business.
Azure Logic Apps
DataMapper ships as a first-class Logic Apps connector — opening the door to over 1,050 pre-built Azure connectors. Any classification event in DataMapper can trigger any flow you can build in Logic Apps, against the systems your organisation already runs.
- Event triggersNew finding · risk-level change · label applied · user-triaged · enforcement executed.
- DestinationsTeams, ServiceNow, Jira, Salesforce, SAP, SQL, Power BI — and the rest of the Logic Apps catalogue.
Dynamics 365 Business Central
Surface sensitive-data findings directly inside Dynamics 365 Business Central — the ERP that runs your finance and operations. Compliance stops being a separate department and starts being a property of every record.
- Business Central use casesFlag customer records with high-risk data · enforce retention on invoices · automate DPIA for new vendor onboarding.
- Workflow automationDataMapper events trigger Business Central workflows: hold high-risk invoices for review, route compliance tasks to the right owner, pause vendor onboarding on red flags.
Where Purview stops on its own.
Once architects have seen the flow, the same two questions come up every time — and they're the right ones to ask. Both are about the edges of Microsoft Purview: the file types it can't classify on its own, and the admin effort of standing up its policies. Here's how DataMapper closes each gap.
What about files Purview can't label itself?
Microsoft Purview's classification engine is built around Microsoft file formats. Word, Excel, PowerPoint, Outlook — these it handles well. But the moment you step outside those formats — scanned PDFs, images with embedded text, exports from third-party systems, non-Microsoft file formats — Purview's ability to detect and label sensitive content falls off sharply.
And this matters, because Purview DLP only works on files it has labelled. No label, no enforcement.
DataMapper doesn't have the same limitation. It classifies every file type — scanned documents via OCR, images with text, PDFs from any source, non-Microsoft exports — and writes a standard Microsoft Purview sensitivity label into each one.
- All file types — PDFs from any source, images (JPG/PNG), scanned documents, third-party exports, archive formats.
- OCR built in — images and scanned pages are read like any other document.
- Standard Purview labels — the same taxonomy your existing Purview policies already act on.
- The label triggers DLP — Purview doesn't care where the label came from, only that it's there.
Net effect: Purview DLP now enforces on file types it could never have labelled itself.
Restricted — CPR
Restricted — Identity
Confidential — Financial
Once DataMapper has written the label, Purview DLP enforcement is identical — regardless of file type.
Do we have to build every Purview policy by hand?
The Microsoft Purview admin surface is powerful, but manual. A single GDPR use case — say, "retain personal health data for five years, then delete" — isn't one setting. It's a coordinated bundle of a sensitivity label, an auto-labelling policy, a retention rule, and a DLP guardrail. Building each one from scratch through the Purview portal takes hours. Building six of them takes days.
DataMapper ships with production-tested PowerShell templates that provision entire policy stacks in minutes.
Example: the CPR Strict Isolation template creates the sensitivity label, the auto-labelling trigger, the DLP policy blocking external transmission with no override, and a retention rule that archives inactive CPR content after 36 months — in one command, tested end-to-end, with rollback documented for every step.
- Idempotent — safe to re-run. Skips resources that already exist.
- Reversible — every script ships with a rollback block. Uninstall is one command.
- Readable — every line is documented. Your Purview admin reviews before running. No black-box automation.
- Reviewed — templates reviewed by Microsoft Purview specialists at Arrow before customer distribution.
Net effect: the customer's Purview admin goes from "weeks to configure" to "an afternoon to deploy, an hour to audit."
Same principle in both answers: DataMapper does the work Purview can't — labelling the file types it doesn't reach, and provisioning the policies its admin surface makes tedious.
See it on your data.
A 2–3 week pilot on a sample of your Microsoft 365 tenant. We authorise a read-only Graph connection, run a real scan, show you where the labels would land — and let your architects and security team look under the hood. No deck, no theory.


