MCSB DP-2: Data Protection
16 Senserva Microsoft 365 security checks provide evidence for Microsoft Cloud Security Benchmark control DP-2 (Data Protection). Each is checked against your tenant, ranked by Severity, with validated remediation.
What MCSB DP-2 covers
The Microsoft Cloud Security Benchmark is Microsoft's own security baseline for Azure and Microsoft 365, organized into control domains. DP-2 sits in the Data Protection domain. Senserva evidences it with the 16 checks below, so you can see, per tenant, whether the control is actually met rather than assumed.
Ask your own AI about this control
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
The 16 checks that evidence MCSB DP-2
Click any row for why it matters and how to fix it, with a link to the full check page.
| Senserva check | Severity | What it verifies |
|---|---|---|
| Purview Label Mandatory Labeling Disabled | High | Mandatory sensitivity labeling is disabled in the tenant label policy settings. |
| Purview Retention Label Delete Only | High | A retention label deletes content with no preceding retention period. |
| Purview SRR Stalled Request | High | A Subject Rights Request is approaching its internal due date. |
| Purview Label Manual Only | Medium | All sensitivity labels are configured for manual application only with no automatic or recommended labeling. |
| Purview Label No Assigned Policies | Medium | A sensitivity label is not included in any label policy. |
| Purview Label No Downgrade Justification | Medium | Users can downgrade or remove sensitivity labels without providing a justification. |
| Purview Label No Tenant Default | Medium | No tenant-default sensitivity label is configured. |
| Purview Label Policy Settings Not Configured | Medium | No tenant-wide sensitivity label policy settings are configured. |
| Purview Retention Label Event Based No Event Type | Medium | An event-based retention label is not bound to a retention event type. |
| Purview Retention Label No Behavior | Medium | A retention label has no retention or deletion behavior configured. |
| Purview Retention Label Short Duration | Medium | A retention label has a very short retention duration. |
| Purview Retention No Labels Configured | Medium | No Microsoft Purview retention labels are configured in this tenant. |
| Purview Retention Permission Check Skipped | Medium | Purview retention label checks were skipped because the scanning credential lacks a required directory role or the RecordsManagement.Read.All permission. |
| Purview SRR Long Running Request | Medium | A Subject Rights Request has been open for more than 90 days. |
| Purview SRR Overdue Request | Medium | A Subject Rights Request is past its due date. |
| Purview SRR Permission Check Skipped | Medium | Purview Subject Rights Request checks were skipped because the scanning credential lacks SubjectRightsRequest.Read.All or a required directory role. |
Also evidences
The same checks provide evidence for these frameworks, so one fix counts across your obligations:
Evidence this control in your own Microsoft 365
This page maps Microsoft Cloud Security Benchmark control DP-2 (Data Protection) to the checks that prove it. Siemserva by Senserva runs those checks, and 650+ others, against your own tenant: it shows exactly where this control is met or failing, ranks the gaps by Severity, and produces the audit-ready evidence and validated fixes to close them.
Built for the people who own this outcome: security and IT teams closing gaps, auditors and compliance teams gathering evidence, and MSPs and MSSPs running it across every client tenant.
Every MCSB control and the checks that evidence it: the control reference. The full benchmark crosswalk: MCSB for Microsoft 365.
