14.2 Auto-Apply Retention Labels

Key Takeaways

  • An auto-apply policy stamps exactly one retention label using sensitive info types, a KeyQL query, trainable classifiers, or cloud attachments; it does not support regulatory records or SharePoint/Outlook defaults
  • Simulation is optional and only for SIT or keyword/property conditions; results expire within seven days, with a maximum of 30 simulation jobs in 12 hours and 100 item samples per mailbox
  • When the policy is turned on, only unlabeled content is eligible; an auto-apply policy never replaces an existing retention label
  • Exchange SIT auto-apply labels mail in transit, not mailbox items at rest; trainable classifiers cannot use adaptive scopes, need at least 10 MB, and auto-label existing items from only the last six months
  • Cloud-attachment auto-apply labels a hidden Preservation Hold copy of the shared file and requires the label to start retention when items were labeled
Last updated: August 2026

Auto-apply is service-side labeling: Microsoft 365 applies one retention label when content matches conditions you specify, so people in the organization do not have to classify each item. Microsoft highlights three operational reasons to use it. You do not need to train users on every classification. You do not need to rely on users to classify all content correctly. Users no longer need to know the data-governance catalog—they can focus on their work.

What auto-apply is not

Microsoft documents that this scenario is not supported for regulatory records, and not supported for default labels on an organizing structure such as a document set or library in SharePoint or a folder in Exchange. Those scenarios require a published retention label policy. Auto-apply also does not replace the published-label paths for a Microsoft Syntex model, a SharePoint or Outlook default, or an Outlook rule.

Each auto-apply policy carries exactly one retention label. If two conditions should produce two different labels, you create two policies. A single label can still be used by more than one auto-apply policy if you need different locations or queries.

Conditions you can select

In the Purview portal, open Label policies and choose Auto-apply a label (under Records Management or Data Lifecycle Management, matching the solution you use). After the name and description, Choose the type of content you want to apply this label to offers:

  • Specific types of sensitive information (the same template list you see in DLP; you can add or remove SITs and change confidence level and instance count)
  • Specific keywords or searchable properties that match a query you create (Keyword Query Language / KeyQL against the same search index as eDiscovery content search)
  • A match for trainable classifiers (pre-trained or custom)
  • Newly shared cloud attachments (a compliance copy of the shared file is labeled; the message and the original file are not)

You can extend auto-labeling of retention labels to images with Microsoft Purview optical character recognition. That is additional coverage on matching content, not a fifth policy type.

SharePoint items that are in draft or that have never been published are not supported for auto-apply based on SITs, keywords, or classifiers.

Keep Full directory on Assign admin units; Microsoft currently documents that admin units are not supported. Then choose Adaptive or Static. Trainable classifiers for auto-labeling cannot be used with adaptive scopes—use a static scope instead. Adaptive location choices still follow scope type (a User scope can select Exchange mailboxes but not SharePoint sites).

What gets labeled in Exchange versus SharePoint and OneDrive

Microsoft publishes the following matrices. Do not invent extra Yes cells on the exam.

Exchange:

ConditionItems in transit (sent or received)Existing items (data at rest)
Sensitive info typesYesNo
Specific keywords or searchable propertiesYesYes
Trainable classifiersYesYes (last six months only)

SharePoint and OneDrive:

ConditionNew or modified itemsExisting items
Sensitive info typesYesYes, but only content that is already classified (confirm with content explorer)
Specific keywords or searchable propertiesYesYes
Trainable classifiersYesYes (last six months only)

Additional published constraints:

  • Exact Data Match based sensitive information types and document fingerprinting are not supported for auto-apply retention labels.
  • Custom sensitive information types cannot auto-label existing items in SharePoint and OneDrive.
  • To auto-apply by trainable classifier, SharePoint sites and mailboxes must have at least 10 MB of data.
  • You cannot auto-label SharePoint and OneDrive items that are older than six months when the condition is a trainable classifier.

After content is labeled by an auto-apply policy, that applied label cannot be automatically removed or changed by changing the content, changing the policy, or creating a new auto-apply policy. Microsoft states an auto-apply retention label policy will never replace an existing retention label. If you need the new conditions to win, someone must manually remove the current label first (other documented overrides such as Power Automate Apply a retention label on the item are not auto-apply).

If multiple auto-apply policies could apply and the content meets more than one, you cannot control which retention label is selected. In some cases the label from the oldest auto-apply policy (by date created) is selected, and only when the matching policies do not include multiple instances of the same type of condition (sensitive information types, keywords or searchable properties, or trainable classifiers).

Simulation mode

You can run an auto-labeling policy in simulation mode when it is configured for specific types of sensitive information, or for specific keywords or searchable properties. Microsoft does not list trainable classifiers or cloud attachments in that simulation pair. Simulation reports results as if the selected label were applied, similar to a WhatIf parameter, so you can refine conditions and increase scope gradually (one library, then more sites, then another location such as OneDrive).

Typical workflow: create and configure the policy; run simulation and wait for it to complete; review results and rerun if needed; then turn the policy on.

Unlike simulation for automatically applying sensitivity labels:

  • Simulation is optional and not required before you turn the policy on. You can even turn the policy on while simulation is still running.
  • When simulation completes, the results automatically expire within seven days. To view samples again, restart the simulation.

Microsoft-published simulation considerations:

  • A maximum of 30 simulation jobs can be active in a 12-hour time period.
  • A maximum of 100 item samples can be collected per mailbox.
  • Adaptive scopes support a maximum of 20,000 locations (any combination of sites and mailboxes). Because adaptive membership queries run daily, wait and confirm membership before you start simulation.
  • For Microsoft 365 Group mailboxes & sites, items in AuxPrimary mailboxes are not supported for simulation. Arbitration mailboxes are not supported for simulation on Microsoft 365 Groups and OneDrive accounts.
  • Auditing for Microsoft 365 must be turned on. Viewing the sample list requires the Data Classification List Viewer role; viewing file or email contents in source view requires Data Classification Content Viewer.
  • Simulation counts all items matching the criteria at simulation time. When the policy is turned on, only content that is not already labeled is eligible.
  • Auto-labeling for sensitive information types applies to emails sent and received rather than emails stored in mailboxes, but simulation for Exchange locations runs against emails stored in mailboxes so you can assess SITs against historical data.
  • Simulation typically completes within one or two days and sends an email to the user configured to receive activity alerts. Status on Label policies shows In simulation. Open the policy flyout and choose View simulation to see samples, matching counts and locations, edit, turn on, or restart.

KeyQL, classifiers, and cloud attachments in practice

For keyword or property queries, use predefined managed properties. Crawled properties and custom properties are not supported unless you map them at tenant level to refiners such as RefinableString00-99; wait 24 hours after mapping before using the property in the label query. Do not use managed-property aliases—specify the actual name (for example, RefinableString01). Prefix wildcards such as cat* are supported; suffix and substring wildcards are not. Use DocumentLink instead of Path to match a URL, and ParentLink to include or exclude a document library. Quote phrases that contain spaces. A space between keywords is the same as AND; Microsoft recommends always writing the operators so you do not accidentally require every keyword.

Published query patterns you should recognize:

  • Teams meeting recordings and transcripts stored in OneDrive or SharePoint: ProgID:Media AND ProgID:Meeting
  • Files or emails that have a specific sensitivity label: InformationProtectionLabelId: followed by the GUID from Get-Label in Security & Compliance PowerShell

For cloud attachments (also called modern attachments), auto-apply creates a copy of the file at the time of sharing, stores that copy where users do not see it (the Preservation Hold library), and applies your selected retention label to the copy so eDiscovery can find it. The label is not applied to the message itself or to the original file. If the file is modified and shared again, a new copy is saved as a new version. Microsoft requires that the label setting Start the retention period based on is When items were labeled. Versioning is recommended so the version that was shared is captured; if versioning is not enabled, the last available version is retained. Draft or never-published documents are not supported.

Locations for cloud-attachment auto-apply are SharePoint classic and communication sites, Microsoft 365 Groups (group-connected team sites), and OneDrive accounts. You still need separate retention policies if you must retain or delete the original files or the Exchange, Teams, Copilot, or Viva Engage messages that contained the links. Support for cloud attachments shared in Viva Engage is documented as preview. Attachments must be shared by users or Copilot; bots are not supported. Microsoft also documents limits such as a total of 25 attachments in a single message (cloud attachments plus URL text links), URL text links not supported beyond 5,000 characters in the initial body, and current copies auto-labeled for a user added to a Teams conversation only when those attachments were shared within 48 hours.

How long auto-apply takes, and what you can change later

When you auto-apply based on sensitive information, keywords or searchable properties, or trainable classifiers, it can take up to seven days for the labels to be applied. If they do not appear, check Status. Off (Error) with a message that it is taking longer than expected to deploy (SharePoint) or to try redeploying (OneDrive) is the cue for Set-RetentionCompliancePolicy -Identity PolicyName -RetryDistribution.

For SIT, KeyQL, or classifier auto-apply policies, a later change to the selected label and policy is automatically applied to content already labeled by that policy and to newly identified content. For cloud-attachment policies, configuration changes apply to newly shared content only. Names, adaptive versus static, most retention settings except the period, and marking items as a record remain locked after save. Preservation Lock can later prevent anyone from turning the policy off, deleting it, or making it less restrictive; apply that lock only after the policy exists, and note that adaptive scopes currently do not support Preservation Lock.

Loading diagram...
Auto-apply policy flow including optional simulation
Test Your Knowledge

Which requirement cannot be met with an auto-apply retention label policy and instead needs a published retention label policy?

A
B
C
D
Test Your Knowledge

You want to test an auto-apply retention label policy before it stamps production items. When does Microsoft make simulation mode available?

A
B
C
D
Test Your Knowledge

A SharePoint file already has a standard retention label that a user applied. A new auto-apply policy matches the file's content. What happens when the auto-apply policy is turned on?

A
B
C
D