Every sensitive information type pattern is built around one core item to detect. That item can be a regex (validator optional), keyword list or dictionary, or a function; for exact data match, it is the searchable column picked up by an existing SIT.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Primary element in context, with comparison tables and the common traps.
Terms in this definition
- Sensitive information type
Classifier based on patterns, such as credit card numbers, that policies and labels rely on to spot sensitive content. You can also define custom ones.
- Pattern
A reusable answer to a recurring problem that places building blocks in context, explaining when, how and why to apply them and what compromises are involved.
- Validator
A test applied to a regular expression match in a sensitive information type before the match is accepted, for example a checksum, Luhn check, date check or built-in function.
- Keyword list
Words typed straight into a sensitive information type to act as its primary or supporting element. Compared with a keyword dictionary, it holds far fewer terms.
- Exact data match
A custom kind of sensitive information type that looks up the real values held in a table your organisation supplies, such as a customer list, rather than matching a generic pattern. Data loss prevention can then flag only those precise records.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID.
Related terms
- Keyword dictionary
A big, easy-to-maintain collection of keywords, limited to 1 MB compressed for each tenant, that a sensitive information type can use as its primary element or a supporting one.
- SIT pattern
A sensitive information type can define several of these. Each combines a confidence level, a primary element, optional supporting elements and how close they must be (proximity).