A Purview scan labels a storage container: regulated data, correctly classified, neatly cataloged. The same container is reachable through a shared access signature created for a one-off analytics job — broad permissions, long expiry, no owner. The catalog entry is accurate. It is also not the finding. The finding is the pair.
Sensitive-data discovery in Azure has to meet identity and network reality. A catalog tells you where data may live. Sensitive data matters most where an access path can actually reach it.
Use Microsoft Purview to scan and classify data sources, apply labels, and maintain source metadata. That is a far better starting point than guessing where regulated or high-value data sits.
Then connect classification to access paths: Azure RBAC, Entra groups, service principals, managed identities, storage account keys, SAS tokens, Key Vault permissions, and public exposure.
Defender for Cloud helps prioritize posture and attack paths, while Defender for Storage adds storage-focused threat and sensitivity context. Both are strongest when joined to ownership and a remediation workflow.
Storage deserves particular attention. Blob containers, file shares, analytics exports, and temporary transfer locations accumulate sensitive content. The question is not just whether the data is labeled. It is whether the path to that data is controlled.
Keys can turn a narrow path into a wide one. Review Key Vault access, storage account key use, shared access signatures, and which workloads can retrieve secrets. Classification without key review leaves a major blind spot.
Network controls matter too. Private endpoints, firewall rules, public network access, and trusted-service exceptions decide whether a sensitive store is reachable from a compromised workload.
Ownership and retention finish the loop. Sensitive data without an owner becomes permanent risk. Old exports, abandoned analytics copies, test data, and unneeded backups should be assigned, reduced, masked, moved, or deleted.
What to check now: Purview coverage and labels, Defender for Cloud attack paths, Defender for Storage findings, RBAC scope, SAS usage and expiry, account keys, Key Vault access, private endpoints, public access, owners, and retention rules.
Classification should feed remediation, not sit apart from identity and network review. The useful output is a list of reachable data paths to close or narrow. Classification is the starting signal. Reduced reachability is the security outcome.