Data Security Governance
Microsoft Purview Data Security
Microsoft Purview Data Security unifies sensitive data discovery, classification, and protection across Microsoft 365, Azure, and multi-cloud/on-prem data estates. It applies information-protection labels and data loss prevention policies through Microsoft Entra and Defender integrations, enforcing controls at access, egress, and usage points. Its operating model is a policy-driven governance plane built on the Microsoft data and identity graph.
Azure
Service information
Shortname: Purview Data Security
Huawei equivalent shortnames: DSC
Keywords: data security, classification, governance, protection
Differences vs Huawei
Huawei Data Security Center (DSC) is scoped primarily to Huawei-native data sources (OBS, RDS, CSS, Hive, HBase) and centres on classification/grading, masking, and watermarking within Huawei Cloud; it offers an API Data Security component for HTTP/HTTPS traffic protection. Microsoft Purview Data Security spans Microsoft 365 workloads, Azure, and registered multi-cloud/on-prem sources via a unified catalog and atlas, with labels enforced through Entra identity at access time. DSC's catalog and policy plane are narrower and region-bound to Huawei Cloud, with no published equivalent for cross-tenant Microsoft 365 label enforcement.
DSC's enforcement is data-plane masking and watermarking applied at export/access, plus API Data Security for inline API traffic. It exposes dynamic masking/watermarking APIs only on the Professional edition (1 million API calls, 2 databases, 100 GB OBS by default). Purview Data Security integrates policy enforcement with Defender for Cloud, Purview DLP, and Microsoft Information Protection labels enforced across endpoints and services via the Microsoft graph. Huawei has no single equivalent control plane; you compose DSC with DBSS for database audit, WAF/CFW for edge/flow control, DEW for key/encryption, and SecMaster for SIEM-style orchestration. Treat these as distinct, non-interchangeable services rather than a bundled replacement.
Operational responsibility diverges: Purview's catalog, scans, sensitivity labels, and DLP policies are managed centrally and propagated by Microsoft services across the tenant; DSC requires Huawei account-level provisioning, edition-quota sizing (Standard lacks API calls; masking/watermarking needs Professional), and manual asset registration per database/OBS bucket. Regional availability and quotas for DSC differ from Azure's global Purview footprint; validate target regions and edition limits against your asset count before cutover. Neither service offers published feature parity, and no automated conversion of Purview labels or DLP rule sets to DSC classification rules exists.
Migration to Huawei
Start with an assessment: inventory Purview sources, sensitivity labels, DLP policies, and scan schedules, and map each to Huawei's composed target—DSC for classification/masking/watermarking, DBSS for database audit, WAF/CFW for API/edge protection, DEW for keys, and SecMaster for operations. Because DSC Professional is required for masking, watermarking, and API calling, size edition against your database count, used OBS capacity, and projected API call volume. No automated Purview-to-DSC importer exists; recreate classification rules and asset registrations manually.
Migrate configuration, not data: Purview operates on metadata and does not store source data, so the migration payload is policy definitions, label taxonomies, scan rulesets, and DLP conditions. Recreate sensitive-data identification rules in DSC using preset and user-defined algorithms, then register equivalent Huawei data sources (RDS instances, OBS buckets, CSS/Hive/HBase). Where Purview protected Microsoft 365 endpoints or labels enforced via Entra, identify a target enforcement point—DSC masking at export, plus WAF/CFW or API Data Security for inline API traffic—since DSC has no Microsoft 365 or identity-label equivalent.
Validate per-source: run parallel classification scans against representative tables and buckets, compare sensitive-data discovery results and risk grading with Purview output, and confirm masking/watermarking behaves as expected on the Professional edition. Replace Defender/Entra alerting with SecMaster correlation and DBSS audit feeds, and verify alert routing and response playbooks. No performance parity is claimed; benchmark scan duration and API throughput against your SLA before relying on DSC for production scans.
Plan for cost and gap changes: DSC bills by edition, database count, OBS capacity, and API calls (Professional), while API Data Security bills by instance edition, applications, and traffic. Purview billing is typically per capacity unit and protected resource. Recalculate TCO with peak scan frequency, API call volume, OBS used capacity, and cross-region traffic. Explicit gaps include Microsoft 365 label enforcement, cross-tenant governance, and Purview's business glossary/lineage—none of which have a Huawei equivalent; retain Purview or a third-party catalog for those workloads or accept reduced scope.
Official Huawei Cloud documentation
Huawei Cloud
Huawei equivalent service
Shortname: DSC
General function: Data Security Governance
Data security governance and risk control service.
Keywords: data security, classification, protection