
Microsoft Purview Is Not Your Data Governance Strategy
ByJJordan Whiting on 18th August 2026
Microsoft Purview can catalogue metadata, expose lineage, organise data products, support quality controls and make governed data easier to find. It still cannot decide which data matters, who is accountable for it or what risk your organisation will accept.
Buying or configuring Purview is a platform decision. Data governance strategy is a set of business decisions, accountabilities and operating practices. Confusing the two creates a polished catalogue that few people trust or use.
What Purview actually gives you
Microsoft describes two primary data governance solutions in Purview: Data Map and Unified Catalog.
Data Map scans supported analytics, SaaS, operational, on-premises and multicloud sources to capture metadata. Unified Catalog uses that metadata to help people find and understand data, organise it into governance domains and data products, connect it to business concepts, monitor quality and manage aspects of access.
That is useful infrastructure. It can make a governance operating model visible and repeatable. It does not create the model.
Microsoft makes one boundary especially clear: the information held in Data Map and Unified Catalog is metadata, not the underlying business data. Catalog roles and permissions do not themselves grant access to the underlying data. Access policies can be configured for supported assets, but discovery, cataloguing and universal access enforcement are not the same thing.
The decisions no tool can make for you
A working governance strategy should settle at least six questions before a broad Purview rollout.
1. Which outcomes deserve governance effort?
Not every table needs the same attention. Start with business outcomes where unreliable, misunderstood or inappropriately accessed data has a material consequence.
Examples include the monthly financial pack, customer retention reporting, workforce planning, regulatory reporting or an AI assistant retrieving customer information. Each outcome gives governance work a reason to exist.
Without this priority, teams often scan everything and curate nothing. Asset counts rise while the important decisions remain unsupported.
2. Who owns each important data product?
A system administrator is not automatically the business owner of customer, revenue or workforce data.
The owner needs authority to approve definitions, set acceptable quality thresholds, decide appropriate use and resolve conflicts. A steward can run the day-to-day work, but unresolved decisions still need one accountable person.
Purview governance domains can represent ownership boundaries such as finance, sales or supply chain. The platform cannot decide whether those boundaries fit your organisation or persuade an overloaded executive to accept accountability.
3. What does trustworthy mean?
A quality score without business context can be misleading. Ninety-five per cent completeness may be acceptable for a marketing preference field and unacceptable for a payment amount.
For each critical element, define:
- The business rule and expected threshold.
- The source considered authoritative.
- The person who reviews exceptions.
- The time allowed to correct a failure.
- The decision or process affected when the threshold is missed.
Purview data quality capabilities can profile data, apply rules and aggregate scores across assets, data products and domains. People must still choose rules that reflect real use.
4. What use is permitted?
Access is not only a technical permission. A person may be able to open a dataset while still lacking a valid reason to use it for a new analysis, export it or provide it to an AI agent.
Define permitted purposes, restricted uses, approval conditions, retention requirements and the evidence required for an exception. For personal information, this must align with applicable obligations. In Australia, APP 11 guidance from the OAIC covers reasonable technical and organisational steps to protect personal information and when it should be destroyed or de-identified. New Zealand organisations should also account for Privacy Principle 5 on storage and security.
Purview can help expose classification, ownership and access workflows. It does not provide legal interpretation or approve a new business purpose.
5. How will issues be resolved?
Governance becomes real when two departments disagree about a metric, a quality rule fails or access is urgent.
Set a simple escalation path:
- The steward investigates and records the issue.
- The data owner decides within an agreed service level.
- A cross-functional governance group resolves material conflicts or accepts risk.
- The executive sponsor decides only when the matter crosses risk appetite, budget or organisational boundaries.
If every question goes to a committee, decisions stall. If no question can reach one, local workarounds become policy by default.
6. How will value be measured?
Catalogued assets are an implementation measure, not a business result.
Better measures include:
- Time required to find and gain approved access to a priority data product.
- Percentage of critical data elements with an owner and tested rule.
- Time to resolve material quality incidents.
- Number of recurring reports using the agreed definition.
- Percentage of access reviews completed on schedule.
- Use of governed data products in nominated reporting or AI outcomes.
Choose a small set linked to the starting outcome. A mid-market organisation does not need an enterprise scorecard before it has one functioning governance loop.
Why tool-first governance fails
The usual failure pattern is predictable.
First, a technical team connects sources and runs scans. The catalogue fills with names that make sense to engineers but not to business users. Ownership is assigned to whoever administers the source. Glossary workshops produce definitions without decision authority. Quality rules measure what is easy to profile. Users continue asking colleagues where the useful data lives.
The platform is not the cause. The rollout has treated metadata capture as governance adoption.
A better test is whether a finance manager, operations analyst or AI product owner can answer five questions about a priority dataset:
- What business purpose does it serve?
- Who is accountable for it?
- How current and reliable is it?
- What am I permitted to do with it?
- What happens when it is wrong?
Purview can present much of this context. Your operating model must supply it and keep it current.
Put strategy before configuration
Use this sequence before committing to a wide implementation.
Define one governed outcome
Choose a decision, report, process or AI use case that matters and has an available owner. Keep the first boundary narrow enough to complete.
Map the minimum data chain
Identify the source systems, transformations, semantic models, reports and consumers required for that outcome. This establishes what must be scanned, classified and documented first.
Assign decision rights
Name the executive sponsor, data owner, steward, technical custodian and privacy or security adviser. State what each role can approve and when escalation is required.
Write the minimum policy set
Document ownership, quality, access, acceptable use, retention and issue management in practical terms. Avoid a policy library that no delivery team can apply.
Configure Purview against the model
Create the relevant governance domain, connect and scan the required sources, curate a useful data product, link business terms, configure quality rules and establish access handling where supported.
Prove the operating loop
Run a real access request, quality failure, definition dispute and scheduled review. If the owner cannot make the required decisions, more scanning will not fix the problem.
When Purview is the right investment
Purview is worth serious consideration when the organisation has data spread across systems, needs stronger discovery and lineage, operates within a Microsoft security environment and is prepared to fund ongoing ownership and stewardship.
It is not the first answer when the business problem is still vague, no owner will accept accountability or the immediate need is one contained report over manageable source data. In those cases, clarify the outcome and operating model before expanding the platform.
A Data Discovery & AI Readiness Roadmap can resolve priorities, ownership, architecture and governance requirements before implementation. Where the use case and decision rights are already clear, Microsoft Fabric consulting and implementation can build the governed data foundation that Purview helps make visible and usable.
Book a 30-minute fit call to decide whether the next move is governance design, platform implementation or a narrower working outcome.
About the author
Jordan WhitingFounder and CEO, DataMust
Jordan leads DataMust's client work with a practical, commercial lens. He helps teams turn Microsoft Fabric, Power BI and AI-ready data foundations into decisions people can use in production.
Keep reading
- Microsoft Fabric Pricing in Australia: Capacity, Licensing and Commercial SizingUnderstand Microsoft Fabric capacity, Power BI licensing and the delivery costs Australian mid-market organisations should include when sizing an investment.
- Preparing for a Synapse to Microsoft Fabric MigrationA practical readiness guide for moving Azure Synapse workloads to Microsoft Fabric, covering dependencies, governance, capacity, testing and migration risk.
- Microsoft Fabric vs Power BI: What Do You Need?A practical decision guide for mid-market leaders: when Power BI is enough, and when a governed Microsoft Fabric foundation is the better investment.