5.2 Define and Create Sensitivity Labels for Items and Containers
Key Takeaways
- A sensitivity label is the classification stamp and its protection settings; a label policy publishes labels to users; auto-labeling applies or recommends labels from conditions — policies are the next chapter
- Label scope controls both which settings you can configure and where users can select the label: Files & other data assets, Emails, Meetings, and Groups & sites
- Container labels for Teams, Microsoft 365 groups, SharePoint sites, Viva Engage, and Loop workspaces do not automatically label or encrypt items inside the container
- Enable container labeling in Microsoft Entra, then run Execute-AzureAdLabelSync in Security & Compliance PowerShell before Groups & sites settings can be configured
- Priority order matters: least restrictive labels at the top, most restrictive at the bottom; sublabels do not inherit protection settings from the parent except color
The second blueprint bullet is Define and create sensitivity labels for items and containers. Create the label object first. Publishing, default labels, mandatory labeling, and auto-labeling are label policy and auto-labeling policy work. This section stops at the boundary: you must know what those policy objects are so you do not dump encryption settings into the wrong wizard, but you do not design the policy yet.
Label versus label policy versus auto-labeling
Think of three objects:
| Object | What you configure on it | When users see an effect |
|---|---|---|
| Sensitivity label | Name, tooltip, color, scope, item protection (encryption, content marking), container protection (privacy, guests, external sharing, unmanaged devices), optional client-side auto-apply/recommend conditions | Never, until the label is published (or used by a service policy that already targets it) |
| Sensitivity label policy | Which labels are published to which users or groups; default label; mandatory labeling; justification for lowering a label; custom help URL | After publish; Microsoft says allow up to 24 hours for apps to show new labels |
| Auto-labeling policy (service-side) | Conditions (SITs, classifiers) that apply a label to content at rest in locations such as SharePoint, OneDrive, and Exchange | Separate from the label definition; next chapter |
A label is reusable. Microsoft's create article is explicit: define the label once, then include it in several policies for a pilot group versus the whole tenant. Creating the label does not publish it. The Labels page even warns you not to click Publish labels unless you truly need a new policy. Aim for as few policies as possible — one organizational policy is common.
Client-side Auto-labeling for files and emails checkboxes on the label itself are still label settings, but they only fire for users who receive that label through a policy, and they are a different mechanism from a service-side auto-labeling policy. Do not treat "I ticked recommend label on Confidential" as a substitute for a SharePoint auto-labeling policy.
Until you publish, the label is an admin-only object. That is the boundary for this chapter.
What a label is
Microsoft describes a sensitivity label as a stamp that is customizable, stored in clear text metadata (so other apps can read it), and persistent as the file roams. Guests and users in other tenants do not see your label names in Office apps. Each item supports one sensitivity label from your organization. The same document can also have a retention label; the two are not interchangeable. Do not confuse Purview sensitivity labels with Outlook's built-in sensitivity levels (Normal, Personal, Private, Confidential), which do not encrypt or watermark anything.
Portal path: Microsoft Purview portal > Solutions > Information Protection > Sensitivity labels. Classic tenants use + Create a label. Tenants created beginning October 1, 2025, or tenants that migrated, use the modern label scheme (+ Create > Label, plus Label group). A green message bar on the Sensitivity labels page confirms a successful modern-scheme migration.
Scopes: items versus containers
Scope decides which settings appear in the wizard and whether users can pick the label in a given app.
- Files & other data assets is selected by default for a new label. It covers Office files, Loop, Power BI, Microsoft Fabric items, and Data Map assets when you extend labeling beyond Microsoft 365. Encryption and content marking for files live here.
- Emails is usually selected with Files because attachments travel with messages. You can scope a label to email only; some features then disappear (for example user-defined permissions that prompt in Word).
- Meetings (calendar events, Teams meeting options, and chat) cannot be selected unless Files and Emails are also selected.
- Groups & sites appears and is selected by default only after you enable sensitivity labels for containers and synchronize them. It covers Microsoft Teams, Microsoft 365 groups, SharePoint sites, Viva Engage communities, and Loop workspaces.
If you leave a scope unchecked, you still see the first settings page for that scope, but the controls are unavailable. Use Next to skip or Back to change scope.
Item labels
Item labels classify and optionally protect content: documents, emails, meeting invites, Loop pages, Power BI artifacts, and (when enabled) Data Map assets. Protection settings you attach here — encryption, headers, footers, watermarks — travel with the item. They do not turn a SharePoint site private.
Power BI uses the same item labels after you turn on the capability. In the Power BI service, the label is visible, but access is still Power BI permissions. Encryption configured on the label is not enforced inside the service; it applies when data leaves on a supported export path (Excel, PowerPoint, PDF, or download to .pbix). In Power BI Desktop, saving a labeled .pbix applies the label and any encryption to that file. Power BI is not a Groups & sites container target; Microsoft's container-support list currently excludes Power BI.
Container labels
Container labels protect the workspace, not each file inside it. Microsoft is blunt: items in the container do not inherit the container label and therefore do not get the label's encryption or content markings. Users still need item labels (and you still need sensitivity labels for Office files in SharePoint and OneDrive if you want Word on the web to label library files).
Container settings you can define on the label (once Groups & sites is enabled) include:
- Privacy: Public, Private, or None (label protects other settings but users still set privacy)
- External user access (whether owners can add guests)
- External sharing from labeled SharePoint sites
- Unmanaged-device access and authentication contexts (both depend on Microsoft Entra Conditional Access)
- Private-team discoverability and Teams shared channel invitation controls
- PowerShell-only: default sharing link type for the site, and
MembersCanSharesite-sharing behavior - Optional default label for channel meetings when the label's scope also includes meetings
Privacy Public or Private locks the Teams/group privacy value. Changing it later requires removing the sensitivity label first; after removal, the last privacy value remains but can be edited again.
Enablement (one-time): follow Microsoft Entra instructions to assign sensitivity labels to Microsoft 365 groups, connect to Security & Compliance PowerShell, and run Execute-AzureAdLabelSync. Until that is done, Groups & sites settings are visible but not configurable.
Shared channels inherit the parent team's container label and cannot get a different label. Changing an already-applied container label is restricted: group-connected sites need the Microsoft 365 group Owners; other sites need a SharePoint site admin.
Priority, sublabels, and label groups
On the Labels page, order is priority. Put the least restrictive labels (Personal, Public) at the top (lowest order number). Put the most restrictive (Highly Confidential) at the bottom (highest order number). You can move a label to the top or bottom, move it one step, or assign a priority number. Only one sensitivity label applies to an item. The policy option that demands a justification to go to a lower sensitivity uses this list — and Microsoft documents that this justification option does not apply to sublabels that share a parent (or, in the modern scheme, sublabels in the same label group), does not apply to Data Map assets, and does not apply to container labels.
Sublabels (classic) or labels inside a label group (modern) give a two-tier picker: users see Confidential, then must choose All Employees or Trusted People. The applied label is Confidential \ All Employees. Second-tier labels do not inherit encryption or marking from the parent except color. The parent (classic) is a text grouping label and cannot be applied to content once it has sublabels. Do not set a parent as a default label and do not auto-apply a parent. Label groups themselves are not published; you publish the labels inside them.
Real-world guidance from Microsoft: effectiveness drops when users have more than five main labels or more than five sublabels per main label. A tenant can have a high number of labels (Microsoft cites 1,000+), with one published exception: if the label applies encryption that specifies users and permissions, the maximum is 500 such labels per tenant.
Create, edit, delete
Create the taxonomy names users will recognize (Microsoft's defaults are a reasonable start: Personal, Public, General, Confidential, Highly Confidential). Write a short tooltip; some apps truncate long ones. Test names with the people who will apply them.
After you create item and container labels, review order before anyone publishes a policy. Editing a published label does not require a new policy; allow up to 24 hours for apps to pick up the change. The version of the label that was applied to an item is what continues to enforce on that item until it is relabeled.
Deleting a label does not strip it from existing content; protection settings continue. Deleted names can show as GUIDs in content explorer and activity explorer. For containers, Microsoft documents that removing the label's settings can take 48–72 hours for SharePoint sites and can be faster for Teams and Microsoft 365 groups; until that finishes, users might not open previously protected content. For container labels, remove the label from all policies, wait at least an hour, confirm it no longer appears on create-team/create-site, then delete. New container labels: wait at least one hour before testing (wait 24 hours if the label includes Teams shared-channel controls). Existing container labels: wait at least 24 hours after changes.
If a labeled file with a higher priority than the site's container label is uploaded, SharePoint does not block the upload. It raises a Detected document sensitivity mismatch audit event and emails the uploader and site owners (capped at 100 recipients). A lower-priority file on a higher-priority site does not send that mail. Keep container-only labels ordered carefully if you split item labels from container labels.
When the label exists, scopes are correct, priority is bottom-heavy for Highly Confidential, and you have not yet designed the publishing policy, you have this bullet. The next chapter publishes those labels to people, auto-applies them, and covers applying them to Teams, groups, SharePoint, Power BI, and Defender for Cloud Apps.
An admin creates a Highly Confidential sensitivity label with encryption but does not add it to a label policy. What can users do in Word the next day?
You apply a container-scoped Confidential label to a Microsoft Team so that privacy is Private and guests cannot be added. What happens to Word files already in the team's SharePoint library?
You are ordering sensitivity labels and creating a Confidential parent with All Employees and Trusted People sublabels. Which design is correct?