An organization's security team has configured sensitivity labels and wants to ensure that documents stored on-premises (Windows file servers and SharePoint Server 2019) that contain AI model weights and research data are automatically classified before the data is migrated to Azure. Which Purview tool scans and classifies on-premises repositories?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because the Microsoft Purview Information Protection scanner (formerly the Azure Information Protection unified labeling scanner) is specifically designed to scan on-premises file servers (SMB/UNC paths) and SharePoint Server repositories. It can automatically classify files using sensitive information types and trainable classifiers, and optionally apply sensitivity labels to files based on the classification rules configured in Microsoft Purview.
Full explanation below image
Full Explanation
A is correct because the Microsoft Purview Information Protection scanner (formerly the Azure Information Protection unified labeling scanner) is specifically designed to scan on-premises file servers (SMB/UNC paths) and SharePoint Server repositories. It can automatically classify files using sensitive information types and trainable classifiers, and optionally apply sensitivity labels to files based on the classification rules configured in Microsoft Purview. B is wrong because the Microsoft Purview Data Map automated scanning is designed for Azure data sources (Azure Blob, Azure SQL, ADLS) and some on-premises connectors, not specifically for Windows file server and SharePoint Server local repositories in the same way as the AIP scanner. C is wrong because Microsoft Defender for Identity sensor monitors Active Directory domain controllers for identity threat detections; it does not scan file content for classification. D is wrong because Defender for Endpoint's information protection integration enforces labeling actions on endpoints when users handle files, not for bulk scanning and classification of file servers.