Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Before you enforce an auto-labeling policy, run it in simulation mode. Simulation shows which items the policy would label without changing them. Review the match results and source distribution to decide whether the policy is ready for enforcement.
This article describes the simulation overview page. To review policy results after you turn on a policy, see Monitor your auto-labeling policy.
Important
Before you begin, make sure that you have the required roles and permissions. For more information, see Policy-level labeling activity for SharePoint and OneDrive.
To view matched text in a file on Items to review, you also need the Data Classification Content Viewer role.
Review the simulation overview
Make sure the policy is in simulation mode (Test with notifications or Test without notifications) and has started scanning the configured locations. Then follow these steps:
- Sign in to the Microsoft Purview portal.
- Select Solutions > Information Protection > Policies > Auto-labeling policies.
- Select the name of a policy that is running in simulation mode.
- In the policy details panel, select Summary > View details to open the Simulation overview page.
On the Simulation overview page, the following key metrics about the policy are available:
| Field | Description |
|---|---|
| Label | The sensitivity label that the policy applies to matched items. |
| Status | Simulation status: In progress, Completed, Almost complete (safe to enforce), or Expired. |
| Duration | The length of time the simulation has been running in days and hours. |
| Matched items | The total number of items that matched the policy conditions across all workloads. |
| Sample items | The number of sampled items available for review. Samples are retained for 30 days. |
| Policy matches per rule | Shows details about the policy rules that produce the most matches, specifically: - Total Rules: the number of rules that matched the policy. - Total Matches: the number of items that matched rules. - Rule name: the name of the rule in the policy. - Matches: the number of items that matched this rule. - Location: The workload where matches occurred (Exchange, SharePoint, or OneDrive). Review these results to confirm that each rule produces the expected matches and to identify rules that might be too broad or too narrow. |
| Matches by source | A donut chart showing matches distributed across workloads, with an item count and percentage for each of the following workloads: - Exchange: Email messages that matched the policy. Matched Exchange items are based on sampled data and might not represent all mailboxes in the policy scope. - SharePoint: Files in SharePoint sites that matched. - OneDrive: Files in OneDrive accounts that matched. |
| Sensitive info types | This table lists the sensitive information types (SITs) detected across the matched items and the number of matches for each type. Use it to identify which SITs produce the most matches. |
| Review sample items | Select Review sample items to open Items to review. For each item, you can: - Preview the file or email content, where supported. - View properties such as the file location, modified date, and detected SITs. - Read a contextual summary that explains in plain language why the item matched. |
Note
The Matched items count is an estimate. During simulation, the service samples content across your configured locations. The actual enforcement count might differ slightly.
Next steps
Based on the simulation results, choose the appropriate next step:
- Turn on policy when the match distribution is correct.
- Edit the policy when the policy produces too many false positives (match count is high) or too few matches. Edit the conditions, and then restart the simulation to get updated results.
Important
If you configure a scheduled turn-on date, the policy automatically takes effect on that date, even if you haven’t reviewed the results. Cancel the scheduled turn-on date if you need more time.