A unified data governance solution that helps manage, protect, and discover data across your organization
Thank you for the detailed information.
The scan results you see in UAT are expected because Microsoft Purview can only classify and label the data that actually exists in the environment being scanned. If certain sensitive data types are not present in UAT, Purview will not be able to discover or classify them.
My recommendation would be:
- Use the current UAT environment to validate:
- Dataverse connectivity and scanning
- Classification rules
- Sensitivity label policies
- Auto-labeling behavior
- Catalog and reporting functionality
- For complete validation, populate UAT with either:
- A sanitized/masked copy of Production data, or
- Synthetic test data that contains all expected sensitive information types (PII, financial data, IDs, etc.)
- Before enabling auto-labeling in Production, run scans against the Production Dataverse environment, review the discovered classifications, and verify that labels are being applied as expected.
- For reporting, you can use Microsoft Purview Data Estate Insights and connect the metadata to Power BI to build dashboards showing:
- Scanned assets
- Classifications detected
- Sensitivity labels applied
- Classification trends
- Unclassified assets
- Label coverage
In short, UAT is the right place to validate the configuration and policies, but to validate full classification coverage, you will need representative data (sanitized Production data or synthetic test data). The final confirmation of classification and auto-labeling effectiveness should be performed against the Production dataset before broad rollout.