What to Create First to Review GDPR Compliance in Compliance Manager?
You have a Microsoft 365 E5 subscription. You need to review the compliance of the subscription with the General Data Protection Regulation (GDPR) by using Compliance Manager. The solution must minimize administrative effort. What should you create first?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the order of operations inside Compliance Manager — an assessment must exist before any compliance score, improvement action, or score-change alert is meaningful; the trap is selecting "a template" because templates appear to be the starting point.
Compliance Manager measures regulatory compliance by scoring the controls of an assessment that is built from a Microsoft-provided template. The correct first action for reviewing GDPR compliance in a Microsoft 365 E5 subscription is to create a GDPR assessment (A), not a template, an alert policy, or a review of existing assessments.
Selecting "a template" on the assumption that you must build the GDPR framework yourself. Microsoft already ships a ready-made GDPR template, so the only thing an administrator creates is the assessment that binds that template to the M365 E5 tenant.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Compliance Manager separates the reusable content (templates, which Microsoft supplies for regulations such as GDPR) from the tenant-specific object (assessments, which bind a template to your Microsoft 365 E5 environment and start generating a compliance score). Option A, an assessment, is therefore the object you create first: it applies the Microsoft GDPR template, maps its controls to your tenant, and produces the compliance score and improvement actions you need for the review. This also satisfies "minimize administrative effort", because the built-in template is used as-is rather than authored from scratch. As Amin4799 put it, "The first step you should take is to create an assessment in Compliance Manager." Once that assessment exists, reviewing the score and working improvement actions is the follow-up activity, not the first step.Why the Other Options Are Wrong
Option C, a template, is wrong because Microsoft already publishes the GDPR template inside Compliance Manager; creating your own template would add administrative effort rather than reduce it, and a tenant-specific template alone produces no score until an assessment uses it. Option B, an alert policy to monitor for score changes, is a monitoring convenience that presupposes an assessment and a changing score — it cannot perform the GDPR review itself. Option D, review assessments, describes the Compliance Manager page where existing assessments are listed; it is not an artifact you create, and with no GDPR assessment present there would be nothing relevant to review.Community Comment Notes
Every recorded vote went to A, and the comments converge on the same reasoning. thetootall simply states "A is correct" and links Microsoft's GDPR regulatory documentation, which describes creating an assessment to evaluate GDPR compliance. CheMetto agrees and points out that you first create an assessment in which you'll pick the Microsoft-provided template — "you'll choose the template created by microsoft" — which is exactly why option C is the distractor and not the answer. No commenter argued for an alert policy or for merely reviewing the assessments list.Official Reference
Exam Strategy
When a question says "minimize administrative effort" in Compliance Manager, prefer the action that reuses Microsoft's built-in templates rather than one that creates new content. Remember the sequence: template (provided by Microsoft) → assessment (created by you) → score and improvement actions → optional alerts on score changes.
Frequently Asked Questions
Why can't I just create a template instead of an assessment in Compliance Manager?
Templates are the prebuilt regulatory frameworks Microsoft provides, including GDPR. An assessment is what binds that GDPR template to your Microsoft 365 E5 tenant and produces the compliance score and improvement actions.
Does an alert policy for compliance score changes satisfy the GDPR review requirement?
No. An alert policy only notifies you after a score changes; it performs no evaluation. It also depends on an assessment already existing, so it cannot be the first thing you create.