
Explanation:
Box 1: Data Map
To apply custom Sensitive Information Types (SITs) to files in storage blobs with Microsoft Purview, create the custom SIT in the Purview portal, then connect your Azure storage account to the Microsoft Purview Data Map and scan it to detect the custom SIT. The custom SIT will then be used by Microsoft Defender for Storage to identify sensitive data in storage accounts, triggering alerts and other actions based on your sensitive data threat detection configurations.
Box 2: The Information Protection Scanner
To apply custom Sensitive Information Types (SITs) to on-premises files, you need to use the Microsoft Purview Information Protection Scanner to scan the files on your on-premises servers.
First, you create your custom SITs in the Purview portal. Then, you configure a Data Loss Prevention (DLP) policy that utilizes these custom SITs and deploy it to the scanner, which then discovers and classifies sensitive information in your on-premises file shares, enabling you to enforce protection actions.
Reference:
https://learn.microsoft.com/en-au/azure/defender-for-cloud/enable-defender-for-storage-data- sensitivity
https://learn.microsoft.com/en-us/purview/deploy-scanner