Filtering Sensitivity Labels by Sub‑Domain in Microsoft Purview Reports

Donita Retaw 40 Reputation points
2026-06-28T23:50:01.1933333+00:00

Hello,

Our client’s environment is configured with one main domain name and then multiple sub‑domains under it. We are building custom Posture Reports in Microsoft Purview to track Sensitivity Labels (e.g., Confidential, Highly Confidential).

I would like to set up filters so that the report can show sensitivity label usage per sub‑domain rather than just at the main domain level.

  1. How can I configure filters in Posture Reports to separate sensitivity label counts by sub‑domain?
  2. Is there a recommended way to structure these filters so that each sub‑domain’s labeled item can be compared side by side?
  3. Are there limitations in Purview reporting when filtering by sub‑domain, or do I need to use Power BI for more granular breakdowns?

Any guidance or examples would be greatly appreciated.

Thank you!

Microsoft Security | Microsoft Purview

Answer accepted by question author

JimmySalian-2011 45,871 Reputation points Volunteer Moderator
2026-06-30T10:16:26.38+00:00

Hi Donita,

As far as I know there is no built-in capability to filter or group posture reports by email sub-domain. Can you try Audit logs and export the logs files to filter out the SubDomain info? Or the other option is PowerBI like you suggested so I agree that is the way forward.

Hope this helps.

JS

==

Please Accept the answer if the information helped you. This will help us and others in the community as well.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. SAI JAGADEESH KUDIPUDI 3,640 Reputation points Microsoft External Staff Moderator
    2026-07-01T07:32:46.3933333+00:00

    Hi @Donita Retaw ,

    Based on the information in the provided docs, Purview’s sensitivity labeling reports/insights are filterable, but there isn’t any documented way to specifically break sensitivity label counts by sub-domain (i.e., treating sub-domains as a first-class dimension the way “label name, subscription name, source type” are).
    What Purview reporting supports (per the docs)

    In the Sensitivity labeling insights drilldown experience (Unified Catalog / classic sensitivity labels report), you can filter using items like:

    • label name
    • subscription name
    • source type

    …and then drill into Label by source for the selected label, which shows counts by source name, source type, subscription ID, etc.

    So, Purview can filter at the reporting “grid” level across the dimensions it exposes (like label and source), but sub-domain-specific filtering/counting is not described.
    What this likely means for sub-domain reporting

    If your “main domain + multiple sub-domains” are represented in Purview only as part of a larger identifier (for example, included in a dataset name, a URL, or some field), then Purview reports won’t automatically aggregate on “sub-domain” unless that sub-domain is already part of the dimensions the reports filter on (such as a field Purview indexes into the reportable model).
    When you may need Power BI (or another approach)

    The provided documentation doesn’t explicitly say “you must use Power BI,” but it does indicate that Purview’s built-in reporting filters are limited to the dimensions presented in the reports (label name, subscription name, source type, etc.). If you need a side-by-side comparison per sub-domain, that’s typically where customers either:

    • model the sub-domain as a distinct attribute that ends up in a reportable dimension, or
    • use Power BI for more granular breakdowns beyond what the standard report dimensions provide.

    Quick sanity checks that can impact what you see

    If your report doesn’t show labels you expect (even before worrying about sub-domains), the docs call out common causes like:

    • assets weren’t scanned successfully
    • the data source doesn’t contain classified content
    • label/policy configuration prerequisites aren’t met (and the label definition is properly associated and published)
    • re-run a full scan if labels are missing

    Reference

    Hope this helps. If you have any follow-up questions, please let me know. I would be happy to help.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.