16.3 Sensitivity Labels & Policies
Key Takeaways
- Sensitivity labels mark and protect content based on its sensitivity (e.g., Public, Internal, Confidential, Highly Confidential) and can apply encryption, content markings, and site/group protection
- A sensitivity label can apply encryption (who can open and with what rights), content markings (watermarks, headers, footers), and Microsoft 365 Group/Team/SharePoint site protection
- Labels are created in Information protection > Labels and published via a sensitivity label policy that controls which users/groups see them, the default label, mandatory labeling, and justification for removal or change
- Service-side auto-labeling runs in the background for Exchange, SharePoint, and OneDrive based on SITs or trainable classifiers; client-side auto-labeling recommends labels in Word, Excel, PowerPoint, and Outlook
- Sensitivity labels govern protection and classification; retention labels govern keep/delete lifecycle — the two are independent and can coexist on the same item
Quick Answer: A sensitivity label in Microsoft Purview classifies content by its sensitivity (Public, Internal, Confidential, Highly Confidential) and can apply protection: encryption that controls who can open the content and what they can do with it, content markings such as watermarks and headers, and site/group protection for Microsoft 365 Groups, Teams, and SharePoint sites. Labels are created in the Purview compliance portal and published to users via a sensitivity label policy.
What a Sensitivity Label Can Do
A sensitivity label can apply several protections, each of which you configure when you create the label in Information protection > Labels:
- Encryption — controls who can open the content and what rights they have (view, edit, print, copy, forward). You can let the user assign permissions, or you can pre-define permissions (admin-defined). Encryption applies to files and emails.
- Content markings — apply a watermark, header, or footer to documents and emails. Markings are visible reminders of the content's classification and travel with the content.
- Site and group protection — when applied to a Microsoft 365 Group, Microsoft Team, or SharePoint site, the label controls external sharing, external user access, and device access policies. This is configured on the Site and group settings page of the label.
- Label-downgrading justifications — when a user replaces a higher-sensitivity label with a lower-sensitivity one, Purview can require a justification reason, which is logged.
Not every label applies every protection. A typical tiered taxonomy is Public (no protection), Internal (no encryption, maybe a footer), Confidential (encryption to internal users, watermark), Highly Confidential (encryption to a named group, restricted rights, watermark). The label order in the policy defines the sensitivity rank from least to most sensitive.
Creating and Publishing Labels
Labels are created in the Purview compliance portal under Information protection > Labels > + Create a label. After you create the label, it has no effect until you publish it through a sensitivity label policy. The policy controls:
- Which users and groups see the labels — publish to all users, or to specific users or mail-enabled security groups.
- Default label — the label applied automatically to new documents and emails when the user does not choose one.
- Mandatory labeling — whether users must apply a label before saving or sending. When mandatory, a user cannot save a document or send an email without a label.
- Justification for removal or downgrade — whether users must provide a reason to remove or lower a label.
- Provide users with a link to a custom help page — directs users to internal labeling guidance.
A single label policy can publish multiple labels, and a label can be published by only one policy at a time. Plan the label taxonomy first, then plan the policies that publish those labels to the right audiences.
Auto-Labeling
Purview offers two distinct auto-labeling mechanisms:
Service-Side Auto-Labeling
Service-side auto-labeling runs in the Purview service in the background, without relying on the Office client. You configure it under Information protection > Auto-labeling policies. The policy applies labels to content stored in Exchange, SharePoint, and OneDrive based on conditions:
- Sensitive info types — content that matches a SIT (e.g., a credit card SIT triggers a Highly Confidential label)
- Trainable classifiers — content that matches a trainable classifier such as Source Code or Legal documents
Service-side auto-labeling applies to content at rest and in transit through the service, including content uploaded to SharePoint by users who are not the original author. It is the recommended approach for large-scale labeling because it does not depend on endpoint configuration.
Client-Side Auto-Labeling
Client-side auto-labeling runs inside the Office apps (Word, Excel, PowerPoint, Outlook). When a user authors content that matches a SIT or trainable classifier configured in the label, Office recommends or automatically applies the label. You configure this in the label itself (the Auto-labeling for Office apps settings), not as a separate policy.
Client-side auto-labeling depends on the user's Office client supporting the feature and having the label policy deployed. It is best for in-the-moment authoring guidance; service-side is best for at-rest coverage. Most enterprises use both together.
Sensitivity vs Retention Labels
The distinction from retention labels (covered in 16.2) is a common exam trap:
| Sensitivity label | Retention label | |
|---|---|---|
| Purpose | Protection and classification | Lifecycle (keep/delete) |
| Settings | Encryption, content markings, site/group protection | Retain-then-delete, delete-only, retain-only |
| Publishing | Sensitivity label policy | Retention label policy or auto-apply retention label policy |
| Coexistence | Can coexist with a retention label on the same item | Can coexist with a sensitivity label on the same item |
An item can have both a sensitivity label (e.g., Highly Confidential with encryption) and a retention label (e.g., Retain 7 years then delete). The two operate independently.
Exam Tip
The MS-102 exam frequently tests the auto-labeling split: service-side runs in the background on Exchange/SharePoint/OneDrive based on SITs or trainable classifiers, while client-side runs in Word/Excel/PowerPoint/Outlook and recommends labels. Also know the three protections a label can apply (encryption, content markings, site/group protection) and the policy settings (default label, mandatory labeling, justification). A scenario where a user must give a reason to downgrade from Confidential to Internal maps to the justification-for-removal-or-change policy setting.
You need to ensure that when users replace a Confidential label with an Internal label on a document, they must provide a reason that is logged. Which setting should you configure?
Which statement correctly describes service-side auto-labeling in Microsoft Purview?