Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

Cyberhaven vs Microsoft Purview

Check differences in scope, deployment and cost. Use the evaluation questions to resolve what the sources leave open.

Read each action with its limits. General capability and environment marks do not establish a specific workflow. Unconfirmed means support was not established in our research.

Capabilities, coverage, deployment, pricing and evaluation questions for Cyberhaven and Microsoft Purview
CompareCyberhavenUpdated Microsoft PurviewUpdated
ApproachCyberhaven combines endpoint and cloud discovery with data lineage and DLP. Its DSPM adds origin and movement context to classification and flags excessive repository permissions. [1]Purview combines Microsoft 365 DLP with endpoint, browser and data-governance capabilities. Coverage, prerequisites and billing differ by workload. A Data Map connector is not evidence of DLP enforcement. [1] [2] [3]
Restrict file sharing in Microsoft 365

This workflow has not been established in our research.

DLP policies can restrict access to sensitive SharePoint and OneDrive files for external users or for everyone. [5]

Blocking behavior depends on the rule. Microsoft documents a short guest-access window for the combination of externally shared content and Block everyone. Test the exact condition and action. [5]

Find sensitive data in S3

This workflow has not been established in our research.

Data Map documents automatic classification for Amazon S3. [2]

The S3 connector does not apply sensitivity labels to Data Map assets or data policies. Classification alone does not establish transfer prevention. [2]

Find sensitive data in BigQuery

This workflow has not been established in our research.

The Data Map BigQuery connector provides metadata and lineage. [2]

The connector does not support automatic classification, sensitivity labels or data policies in the published capability matrix. [2]

Classify Snowflake data

This workflow has not been established in our research.

Purview Data Map documents automatic classification of Snowflake tables and views using a scan rule set. [2] [6]

Classification skips tables or views when their object, schema or database names contain special characters. Self-hosted scanning requires a supported integration runtime and JDK 11. Confirm warehouse access and key-pair authentication for the scan. [6]

Mask sensitive columns in Snowflake

This workflow has not been established in our research.

The Data Map Snowflake connector does not apply data policies in Microsoft's capability matrix. [2]

This limit concerns the Data Map connector. Its classification results do not establish Snowflake masking or other Purview workloads. Require a separate enforcement component if the evaluation needs query-time masking. [2]

Classify on-prem file shares

This workflow has not been established in our research.

The Information Protection scanner can discover, classify and protect files on local and network shares. [4]

Discovery needs read permission. Applying classification and protection needs read, write and modify permissions. The scanner requires Windows Server, SQL Server and an information protection license for the service account. [4]

Discovery & classificationDocumented [1]Documented [1]
Access governanceDocumented [1]Unconfirmed
Data loss preventionDocumented [1]Documented [1]
Detection & responseUnconfirmedUnconfirmed
Encryption & tokenizationUnconfirmedUnconfirmed
Microsoft 365◐ Partial

Cloud APIs connect to Office 365 for visibility into content created and shared in the cloud. Confirm workload-level at-rest scans separately. [2]

◐ Partial

DLP supports Exchange, SharePoint, OneDrive and Teams. Confirm licensing and access-governance requirements separately. [1]

AWS? Unconfirmed◐ Partial

Data Map supports classification in Amazon RDS. Redshift metadata support does not include automatic classification in the reviewed matrix. [2]

Google Cloud? Unconfirmed◐ Partial

Data Map lists BigQuery metadata and lineage but not automatic classification. Do not equate cataloging with content inspection. [2]

Snowflake / Databricks? Unconfirmed◐ Partial

Data Map classifies Snowflake and Azure Databricks Unity Catalog data with connector-specific limits. These connectors do not apply data policies. [2]

On-prem shares? Unconfirmed◐ Partial

DLP for on-prem file shares uses the Information Protection scanner. Deployment and supported file types need checking. [1]

SaaS apps◐ Partial

Cloud APIs connect to Google Workspace. Endpoint and cloud lineage provide different views of data movement. [2]

◐ Partial

Connected non-Microsoft apps include Box, Dropbox, Google Workspace and Salesforce in preview. Browser and network controls have separate prerequisites. [1]

Deployment and data handling

Cyberhaven combines cloud API connectors with an endpoint agent to follow data movement. [2]

Cloud visibility
APIs observe content created and shared in sanctioned applications, including access through unmanaged devices.
Endpoint visibility
The endpoint component follows data movement on managed devices. Confirm supported operating systems and browser requirements.

Purview deployment requirements differ by workload. The Information Protection scanner for on-prem files runs on customer-managed infrastructure. [4] [6]

On-prem infrastructure
The scanner requires Windows Server, a SQL Server configuration database and the Information Protection client.
Scanner identity
The documented setup uses an Active Directory service account synchronized to Microsoft Entra ID. Microsoft provides alternative configurations when this is prohibited.
Read versus change
Discovery-only scans need read access. Applying classification and protection to file shares requires read, write and modify permissions.
Snowflake scanning
The Snowflake Data Map connector needs warehouse USAGE and access to the scanned databases. Microsoft documents key-pair authentication with a self-hosted integration runtime. Confirm the current authentication requirements before provisioning the scan.
Pricing

Pricing was not established in the reviewed sources.

Purview uses complementary per-user and pay-as-you-go billing models. [3]

Per user
Microsoft 365 and Windows/macOS endpoint capabilities depend on the licensed plan.
Consumption
Non-Microsoft 365 sources and certain other capabilities use Azure-linked consumption billing.
Test in the evaluation
  1. Separate stored-content scanning from observing a user download or upload in each required application.
  2. Which device agent, browser extension and API connections does the proposed deployment need?
  3. Test copy-pasted and transformed data, including offline devices and unsupported browsers.
  1. For each required control, identify the workload, licensed plan and enforcement component. Demonstrate the action on that workload.
  2. For on-prem scanning, show the service account permissions in discovery mode and protection mode. Identify the Windows and SQL infrastructure the team must operate.
  3. Separate existing entitlements, additional licenses and consumption charges in the quote. Repeat the estimate for a larger data estate and more frequent scans.

Full refers to the documented scope above. It does not establish every control in every store. How coverage is assessed. Turn a coverage claim into an evaluation test.

Change platforms