MICROSOFT PURVIEW · AUSTRALIA

Your tenant already shows what it exposes. We read it, fix it, and prove it.

LensIQ is a Microsoft Purview consultancy for Australian regulated organisations. We read what your Microsoft 365 tenant enforces today, configure Purview so labels, DLP and retention act in production, and hand you the evidence when an auditor, insurer or board asks.

Request configuration review
Sample tenant readSix Microsoft 365 controls read one at a time: Exchange Online DLP policy enforcing; unified audit log enforcing; SharePoint sensitivity labels not applied; OneDrive retention not mapped; Teams DLP policy simulation only; Endpoint DLP policy simulation only. Summary: 6 controls read, 2 enforcing, 4 exceptions. Sample data, not a real tenant.TENANT READSAMPLE DATAEXCHANGE ONLINEDLP POLICY· · ·ENFORCINGAUDITUNIFIED AUDIT LOG· · ·ENFORCINGSHAREPOINTSENSITIVITY LABELS· · ·NOT APPLIEDONEDRIVERETENTION· · ·NOT MAPPEDTEAMSDLP POLICY· · ·SIMULATION ONLYENDPOINTDLP POLICY· · ·SIMULATION ONLY6 CONTROLS READ · 2 ENFORCING · 4 EXCEPTIONSEACH READING TIMESTAMPED AND TRACEABLE TO ITS SETTING
SAMPLE TENANT READ · EACH TILE RESOLVES ONCE, THEN HOLDS

The licence is not the control.

E5 includes Microsoft Purview. It does not configure it. Most tenants we open have sensitivity labels nobody applies, DLP policies left in simulation mode, and retention settings never mapped to an obligation.

Simulation mode is a test harness, not a control. Microsoft’s own documentation says a policy in simulation mode is “run as if it were being enforced, without any actual enforcement.” The report looks healthy. Nothing is blocked. 1

The gap stays invisible until an audit or a breach. We make it visible first.

1 · MICROSOFT LEARN, LEARN ABOUT DLP SIMULATION MODE

From licence to controlThree bars. Licensed: full width. Configured: a little over half. Enforcing: about a quarter, highlighted. Proportions are illustrative, not measured.FROM LICENCE TO CONTROLILLUSTRATIVE01LICENSEDE5 includes Purview02CONFIGUREDPolicies exist in the tenant03ENFORCINGPolicies act in productionTHE GAP BETWEEN 01 AND 03 IS WHERE AUDITS AND BREACHES FIND YOU

Two ways in. One standard of evidence.

Each engagement reads from your tenant or your records, not from a questionnaire. Each ends with artefacts you keep.

Tranche 2 is in force. The evidence clock is running.

From 1 July 2026, accountants, lawyers, conveyancers and real estate professionals who provide a designated service are reporting entities under AUSTRAC. Enrolment is due within 28 days of first providing that service, which for most firms was 29 July 2026. 2 3

The obligations are live now: an AML/CTF program approved by senior management, a business risk assessment that reflects your actual clients, due diligence before service, ongoing monitoring, reporting inside fixed windows, and seven years of records. 3

Tranche 2 timeline1 July 2026: commencement. 29 July 2026: enrolment due, 28 days after first providing a designated service. Ongoing: customer due diligence and reporting. 7 years: records kept for most obligations.1 JUL 2026COMMENCEMENTTranche 2 entities comeunder AUSTRAC regulation29 JUL 2026ENROLMENT DUE28 days after first providinga designated serviceONGOINGCDD AND REPORTINGDue diligence before service,then ongoing monitoring7 YEARSRECORDS KEPTFor most obligations, perthe AUSTRAC factsheet

2 · AUSTRAC, AML/CTF REFORM

3 · AUSTRAC, AML/CTF OBLIGATIONS FACTSHEET FOR TRANCHE 2 REPORTING ENTITIES

What the work returns

Every engagement ends with artefacts, not slides. When AUSTRAC, an insurer, a tender panel or your board asks, the answer already exists in writing.

  1. 01

    Configuration baseline

    A dated record of every setting we read, where it was read from, and its value.

  2. 02

    Control-to-obligation map

    Each control mapped to the obligation it satisfies: APP 11, Essential Eight, AML/CTF Rules, or your own policy.

  3. 03

    Policy rationale

    Why each label, DLP rule and retention period is set the way it is, in language an auditor can follow.

  4. 04

    Change record

    When each control moved from simulation to enforcement, who approved it, and what it has blocked since.

Four deliverablesFour stacked documents: configuration baseline, control-to-obligation map, policy rationale and change record. The top sheet shows rows marked read, mapped, set, applied and kept.CONFIGURATION BASELINECONTROL-TO-OBLIGATION MAPPOLICY RATIONALECHANGE RECORDREADMAPPEDSETAPPLIEDKEPT

How an engagement runs

  1. 01

    Assess

    We read your tenant as deployed. You receive the readout whether or not you engage us further.

  2. 02

    Prioritise

    We map each failure to the obligation it affects and order the work by the risk it removes.

  3. 03

    Configure

    We build in your tenant, in production, alongside your team. Simulation is a step, not the destination.

  4. 04

    Evidence

    You keep the baselines, the rationale and the record.

Built for Australian regulated organisations

We work with organisations that answer to a regulator, an insurer or a board: financial services, health, professional services, education, and suppliers to government. Most run Microsoft 365 E3 or E5 and have Purview licensed but not fully configured.

If you already have an MSP, we sit alongside them. They run the service catalogue. We do the configuration depth, hand back a documented baseline, and leave.

We map to Australian obligations first. We do not translate a US control catalogue.

OBLIGATIONS WE MAP TO

  • Privacy Act 1988 · APP 11
  • AUSTRAC · AML/CTF Act and Rules
  • ASD · Essential Eight
  • PSPF · where it applies

Why this matters now

Start with what your tenant enforces.

Request configuration review

Questions about LensIQ.

Which Purview areas do you cover?

Sensitivity labels, data loss prevention, retention and records, audit, insider risk, and data security posture management.

We provide a designated service but did not enrol by 29 July. What now?

Enrol. The obligation is to enrol within 28 days of providing a designated service, so the exposure grows while the gap stays open. Enrolling late is better than not enrolling.

Our accountant sent us a policy template. Is that an AML/CTF program?

No. A program has two parts: a risk assessment specific to your firm, and policies suited to its nature, size and complexity. A senior manager must approve both, and any updates to either.

Are you Australian based?

Yes. Australian owned, Australian staffed, and the work is done here.