6.4 Apply Sensitivity Labels with Microsoft Defender for Cloud Apps

Key Takeaways

  • Microsoft Defender for Cloud Apps applies published Purview sensitivity labels as a file-policy governance action, not as a Purview auto-labeling policy.
  • Supported Office extensions plus PDF (unified labels) can be labeled in Box, Google Workspace, SharePoint Online, and OneDrive.
  • Direct apply supports files up to 30 MB; Apply label actions are capped at 100 per app per tenant per day and resume after 12:00 UTC.
  • When Defender for Cloud Apps labels a document, visual markings such as headers, footers, or watermarks are not applied.
  • Microsoft documents that MDCA file policies retire on January 6, 2027, with migration toward Microsoft Purview DLP or auto-labeling policies.
Last updated: August 2026

6.4 Apply Sensitivity Labels with Microsoft Defender for Cloud Apps

Quick Answer: Microsoft Defender for Cloud Apps (MDCA) applies Microsoft Purview sensitivity labels as a file policy governance action on matching files in connected cloud apps. Labels must already be published. MDCA does not apply headers, footers, or watermarks when it labels. Keep the published file-type, app, size, and daily-action limits in view, and know that Microsoft documents file policy retirement on January 6, 2027.

Why MDCA labeling is on the SC-401 blueprint

Purview auto-labeling policies cover SharePoint, OneDrive, and Exchange inside Microsoft 365. Organizations also store Office files in Box or Google Workspace, and they need a cloud-access security broker that can find overshared files and apply the same Purview label (including encryption, when the label is configured for it) as a governance action. That is the MDCA integration: one checkbox to sync labels, then either apply a label to a single file from the Files inventory or let a file policy apply it automatically.

Microsoft’s current integration article (updated 2026-06-23) states that file policies retire on January 6, 2027, and tells customers to migrate file-based data protection to Microsoft Purview DLP or auto-labeling policies. SC-401 still measures applying sensitivity labels by using Defender for Cloud Apps, so you must know how the governance action works today and that Microsoft is moving this workload toward Purview. Do not invent a replacement wizard that is not in the docs; cite the published retirement date and the named destinations.

Prerequisites

You need both a Defender for Cloud Apps license and a Microsoft Purview license. As soon as both are in place, MDCA syncs the organization’s labels from Purview. You must also enable the Microsoft 365 app connector. Labels must be published as part of a sensitivity label policy in Purview—unpublished labels never appear as governance actions.

For MDCA to recognize a sensitivity label, the label scope in Purview must include at least Files and Emails. A Groups & sites-only container label is the wrong object for this feature.

In the label’s encryption configuration, permissions must be assigned to any authenticated user or all users in your organization so MDCA can read label information. If those rights are missing, automatic apply fails in ways that look like “the policy never matched.”

Supported files and apps

MDCA currently supports applying Purview sensitivity labels for these file types:

  • Word: docm, docx, dotm, dotx
  • Excel: xlam, xlsm, xlsx, xltx
  • PowerPoint: potm, potx, ppsx, ppsm, pptm, pptx
  • PDF, and for PDF you must use unified labels

Applying labels is currently available for files stored in Box, Google Workspace, SharePoint Online, and OneDrive. Microsoft states that more cloud apps will be supported in future versions; do not list Dropbox, Slack, or Azure Blob as supported apply targets unless a later official page says so.

Direct apply from the Files page works for files up to 30 MB.

How the integration works

After you enable Microsoft Purview in MDCA:

  1. MDCA retrieves the list of sensitivity labels used in the tenant and refreshes that list every hour.
  2. It scans files for those labels. If you enabled automatic scan, new or modified files join the scan queue and existing files and repositories are scanned. If a file policy searches for sensitivity labels, those files join the queue as well.
  3. Scans include labels discovered in the tenant. External labels (classification applied by someone outside your tenant) are added to the classification list unless you select Only scan files for Microsoft Information Protection sensitivity labels and content inspection warnings from this tenant.
  4. After enablement, new files added to connected cloud apps are scanned for sensitivity labels.
  5. You can create MDCA policies that apply your sensitivity labels automatically as a governance action.

Enable the integration in the Microsoft Defender portal: Settings > Cloud Apps > Information Protection > Microsoft Information Protection. Select Automatically scan new files for sensitivity labels from Microsoft Information Protection and content inspection warnings.

Automatic scan does not scan existing files until they are modified again. To inspect the existing corpus, you need at least one file policy that includes content inspection. If you have none, Microsoft’s documented workaround is to create a file policy, clear preset filters, set inspection to Built-in DLP, include files that match a preset expression, pick any predefined value, and save—content inspection then detects Purview labels.

Once connected, the Files page can filter by Purview sensitivity label. The file drawer shows whether a given file is labeled. Disabled labels appear as disabled; deleted labels are not displayed.

Apply a label directly or with a file policy

Direct apply. In the Defender portal under Cloud Apps > Files, open the row menu on a file and choose Apply sensitivity label. Pick an organization label and Apply. MDCA writes the label onto the original file. Remove sensitivity label is available from the same menu, subject to the limits below.

Automatic apply. Create a file policy (Policies > Policy management > Create policy > File policy). Filter on the files you care about (parent folder, collaborators, access level, owner OU, sensitive information types via Data Classification Service, and so on). Under governance actions for the app, select Apply sensitivity label and choose the label. You can combine that action with alerts, user notification, or other governance actions such as removing collaborators or removing sharing.

A typical exam scenario: files in a OneDrive folder that contain credit card numbers (Data Classification Service sensitive information type) get Confidential applied automatically, optionally with extra actions that strip external sharing. Another documented pattern is confidential data externally shared on Box, or recently modified restricted files outside a known SharePoint folder.

TopicPublished behavior
How the label is appliedFile policy governance action, or direct apply from Files
Cloud appsBox, Google Workspace, SharePoint Online, OneDrive
File typesListed Word/Excel/PowerPoint extensions; PDF with unified labels
Direct-apply sizeUp to 30 MB
Daily safety cap100 Apply label actions per app, per tenant; pauses until after 12:00 UTC
Visual markingsNot applied when MDCA labels the file
Label refreshLabel list retrieved hourly
File policy retirementJanuary 6, 2027, toward Purview DLP or auto-labeling

The daily cap is a safety precaution so a mis-scoped policy cannot stamp a label onto a huge corpus in one day. After 100 Apply label actions per app per tenant, the action pauses and continues the next day after 12:00 UTC. Disabling a policy suspends pending labeling tasks for that policy.

Integration limits you should memorize

Microsoft documents these limits; they are frequent distractors:

  • Labels applied outside MDCA: Unprotected labels applied outside MDCA can be overridden by MDCA but cannot be removed. MDCA cannot remove labels with protection from files that were labeled outside MDCA. To scan files that already have protection applied outside MDCA, grant permissions to inspect content for protected files.
  • Labels applied by MDCA: MDCA does not override labels on files it has already labeled.
  • Password-protected files: MDCA cannot read labels on password-protected files.
  • Empty files: Empty files are not labeled.
  • Checkout required: MDCA cannot label files in SharePoint libraries configured to require checkout.
  • Visual markings: When a document is labeled by MDCA, visual markings such as headers, footers, or watermarks are not applied. Item labels still carry encryption if the label is configured for it; markings are the missing piece. Users who later open the file in an Office client that applies markings from the label configuration may see markings at open time—that is the client, not MDCA’s apply action.

A related SharePoint limitation matters when MDCA changes a label on an encrypted Office file: if an app using a service principal downloads a labeled encrypted file and uploads it again with different encryption settings (for example Confidential to Highly Confidential, or Confidential to General), the upload can fail unless the service first runs Unlock-SPOSensitivityLabelEncryptedFile, or the original file is deleted or renamed before upload. That is why “MDCA changed the label and now Office for the web cannot open the file” is a troubleshooting pattern, not a random portal bug.

How this differs from Purview auto-labeling

Do not treat MDCA apply as a third auto-labeling policy type in the Purview portal. Purview auto-labeling policies live under Information Protection, require simulation, and target SharePoint, OneDrive, and Exchange with the 100,000 files/day and 100-policy caps. MDCA labeling lives under Defender file policies, uses governance actions, understands Box and Google Workspace, has a 100 apply-per-app-per-day safety cap, a 30 MB direct-apply ceiling, and skips visual markings.

Use them together on purpose. Example: Purview auto-labeling stamps Highly Confidential on SharePoint files that match a U.S. Social Security number classifier; an MDCA file policy finds Highly Confidential files that are shared externally in Box or OneDrive and either applies a stricter label, removes collaborators, or alerts. Investigation stays in the Defender Files inventory filtered by label, while Activity explorer and Purview auto-labeling reports cover the Microsoft 365 side.

For the exam, if a question says “apply a sensitivity label as a governance action when a file in Box contains credit card numbers,” the answer is an MDCA file policy, not a Purview auto-labeling policy and not a publishing policy default label.

Loading diagram...
Defender for Cloud Apps applying a Purview sensitivity label
Test Your Knowledge

When Microsoft Defender for Cloud Apps applies a Microsoft Purview sensitivity label to a file, which statement is true about visual markings?

A
B
C
D
Test Your Knowledge

Defender for Cloud Apps limits automatic Apply sensitivity label governance actions with which published daily safety cap?

A
B
C
D
Test Your Knowledge

Defender for Cloud Apps currently supports applying Microsoft Purview sensitivity labels to files stored in which cloud apps?

A
B
C
D