12.3 Sensitivity Labels and Data Loss Prevention
Key Takeaways
- Sensitivity labels from Microsoft Purview Information Protection classify content and can optionally encrypt it, add watermarks or headers, and restrict who can do what — examples include Confidential and Highly Confidential
- A sensitivity label is customizable, stored in clear-text metadata, and persistent: the classification travels with the file or email
- Data loss prevention (DLP) policies detect sensitive information types such as credit cards, health records, or Social Security numbers and help prevent oversharing
- DLP can monitor Exchange email, SharePoint, OneDrive, Teams chat and channels, and endpoints conceptually, then tip, block, or block-with-override
- Sensitivity labels classify and protect an item; DLP watches for risky sharing of sensitive info; retention labels decide how long to keep or delete content — they are not the same feature
Quick Answer: Sensitivity labels classify a document or email (for example Confidential or Highly Confidential) and can encrypt, watermark, or restrict it. Data loss prevention (DLP) watches for sensitive information types — credit cards, health data, government IDs — and blocks or warns when someone tries to overshare. Retention labels are a different tool: they keep or delete content for a period of time. Do not treat the three names as synonyms.
The April 30, 2025 MS-900 outline asks you to describe Microsoft Purview Information Protection features such as sensitivity labels and data loss prevention. This is another recommend-the-capability skill. You will not be asked to set label priority numbers, author a sensitive-info-type regex, or click every DLP location checkbox. You will be asked which feature stamps Confidential on a contract and encrypts it, which feature stops a credit-card list from leaving in email or Teams, and which feature is not a keep-for-seven-years rule.
Sensitivity labels: classify, then optionally protect
Sensitivity labels come from Microsoft Purview Information Protection. Official Learn: they let you classify and protect the organization’s data without blocking everyday collaboration. Content no longer stays behind a firewall — it roams across devices, apps, and services — so the protection has to travel with the item.
Think of a label as a stamp on the content. Official properties:
- Customizable. You invent categories that match the business. Microsoft’s own examples include Personal, Public, General, Confidential, and Highly Confidential. Those names are examples, not a required global taxonomy.
- Clear text. The label sits in file and email metadata, so other apps can read it.
- Persistent. The stamp stays with the content no matter where you save or store it. That persistence is why a Highly Confidential Word file can still be protected after someone downloads it from SharePoint.
Each item supports one sensitivity label from your organization. The same document or email can also have a retention label. Users must be signed in with a Microsoft 365 work or school account to apply your labels. Guests do not see your label names the way internal users do.
Do not confuse Purview sensitivity labels with Outlook’s old built-in sensitivity levels (Normal, Personal, Private, Confidential). Those Outlook flags are a sender hint. They cannot encrypt or enforce data security. If the exam says “sensitivity label,” it means Purview Information Protection.
What a label can do
After the label is applied, it can enforce protection settings you configured:
| Setting | What the user notices | Exam signal |
|---|---|---|
| Classification only | A name such as General on the sensitivity bar | Visual mapping and reporting; you can add protection later |
| Encryption / restricted permissions | Only authorized people can open or edit; some may only view | “Stop people outside Legal from reading this contract” |
| Content markings | Header, footer, and/or watermark (watermarks apply to documents, not email) | “Stamp Confidential on every page” |
| Container settings | Privacy, external sharing, and unmanaged-device access on a Team or SharePoint site | The label protects the site or team, not each file automatically |
| Auto-label or recommend | The app applies the label or prompts the user when it sees sensitive info | “If the file contains credit cards, recommend Highly Confidential” |
Encryption can limit who can do what and for how long. Markings can include the label name. Labels also work in Word, Excel, PowerPoint, and Outlook on desktop and the web (Windows, macOS, iOS, Android), and they can extend to meetings, Power BI, and — with extra work — third-party apps. MS-900 wants the core Office and files-and-email story.
Label policies publish labels to users or groups, not to “all Exchange mailboxes.” That is a classic contrast with retention labels, which you publish to locations. A policy can set a default label, require a label (mandatory labeling), and require a justification if someone lowers the classification. You do not need the 24-hour replication note for a scenario question, but you should know labels are published before users see them.
Parent/group labels such as Confidential \ All Employees are a two-tier display. The exam will not grade sublabel inheritance. It will grade “Confidential / Highly Confidential classify and can protect.”
Data loss prevention: stop oversharing
Data loss prevention (DLP) is the practice of stopping people from sharing sensitive data with people who should not have it. In Microsoft Purview you implement DLP by defining DLP policies.
Official examples of what organizations protect: financial data, proprietary data, credit card numbers, health records, and Social Security numbers. DLP is not a simple Ctrl+F for the word “confidential.” Official Learn: it uses deep content analysis — keywords, regular expressions, function validation, nearby secondary matches, and machine learning — to find sensitive information types (SITs).
When a user tries a prohibited action, a policy can:
- show a policy tip that warns them,
- block the sharing but allow an override with a written justification,
- block with no override,
- lock or quarantine an item at rest,
- hide sensitive content in a Teams chat so it is not displayed.
Monitored activities go to the unified audit log and Activity explorer. DLP alerts are a compliance incident, not a Defender malware family — though you can also investigate some DLP incidents from the Defender portal. Do not say “DLP is Defender.”
Where DLP works (conceptual locations)
MS-900 expects the Microsoft 365 locations, not every preview channel.
| Location | Typical oversharing story |
|---|---|
| Exchange Online email | Credit-card spreadsheet attached to an external message |
| SharePoint sites | Health records in a site shared with “anyone with the link” |
| OneDrive accounts | A user shares a folder of contracts outside the tenant |
| Teams chat and channel messages | Pasting a Social Security number into a chat |
| Endpoints (Windows 10/11 and recent macOS) | Copying a sensitive file to a USB drive |
Policies can also reach Office desktop apps, on-premises file shares (with extra scanning), cloud apps, Fabric / Power BI, and — in preview — some Copilot and unmanaged-AI web traffic. For this exam, if the stem says email, SharePoint, OneDrive, Teams, or a managed PC, DLP is in play.
A policy needs the same four decisions every time: what to monitor (template or custom SITs / labels), where to monitor, which conditions count as a match (for example 95 Social Security numbers mailed outside the org, or an item that already has a Highly Confidential label), and what action to take. Organizations usually start in simulation mode so they can see matches without blocking business mail. That is operational hygiene, not an MS-900 click path.
Exam trap triangle: sensitivity label vs DLP vs retention label
These three live in the Purview portal and all talk about “sensitive content.” They are not interchangeable.
| Tool | Job | Travels with the file? | Typical stem |
|---|---|---|---|
| Sensitivity label | Classify; optionally encrypt, mark, and restrict | Yes — metadata (and protection) persist | “Mark this Highly Confidential and only Legal can open it” |
| DLP policy | Detect SITs or labeled content and stop a sharing action | Policy lives in the service / endpoint, not as a stamp on the file | “Block credit cards from being emailed outside the company” |
| Retention label | Keep or delete content for a set time (records / lifecycle) | Official Learn: retention labels do not persist if the content leaves Microsoft 365 | “Keep contracts seven years, then delete” |
They can work together. Auto-labeling can apply a sensitivity label when a SIT is found. A DLP rule can use “item has this sensitivity label” or “item has this retention label” as a condition. A file can be Highly Confidential and on a seven-year retention label and blocked from external sharing by DLP. That cooperation does not merge the three products into one.
Two more contrasts that show up in fundamentals questions:
- Sensitivity labels are published to people. Retention labels are published to locations (for example all Exchange mailboxes).
- DLP is about oversharing now. eDiscovery (previous section) is about finding and holding content for a matter. Audit tells you who did what. Insider Risk scores risky people. Keep those lanes.
Zero Trust’s data pillar is this section in one sentence: classification and protection travel with the data, and oversharing is blocked even when the user is already “inside.”
Realistic exam-style scenarios
Stamp and encrypt. Legal wants every merger document marked Highly Confidential, watermarked, and readable only by the deal team. That is a sensitivity label with encryption and markings — not a DLP tip, and not a retention period.
Stop the credit-card blast. Finance accidentally emails a column of card numbers to a vendor. A DLP policy on Exchange (and Teams, if they paste the same list) detects the SIT and blocks or warns. Applying a Confidential label after the fact does not retroactively stop that send.
Keep for regulators, then delete. Records must keep invoices seven years. That is a retention label (or retention policy). Encryption is optional and separate. “Retain” is not “Confidential.”
USB copy on a laptop. An employee copies a file with health record numbers to a thumb drive. Endpoint DLP is the Purview control that can audit or restrict that copy. Autopilot does not. Insider Risk might later alert on a pattern of theft; the block is DLP.
Teams chat. Someone pastes a national ID into a channel. DLP can prevent the sensitive text from being displayed. That is not eDiscovery and not a watermark.
Wrong Outlook feature. A user sets Outlook’s built-in “Confidential” flag. That is not a Purview sensitivity label and does not encrypt the message.
Exam traps
- Label ≠ DLP ≠ retention. Classify/protect, stop oversharing, keep-or-delete.
- Sensitivity labels can classify without encrypting. Encryption is optional.
- One Purview sensitivity label per item; a retention label can sit beside it.
- Outlook’s built-in sensitivity levels are not Purview labels.
- DLP locations on this exam: Exchange, SharePoint, OneDrive, Teams, and endpoints. Do not say “DLP only works in Azure VMs.”
- DLP is not Defender and not eDiscovery. Tips and blocks versus threat hunting versus legal hold.
- Do not invent unpublished SIT counts or license SKUs. Describe the feature.
- Chapter 13 covers data residency and Microsoft Priva. Those are related trust topics, not substitutes for labels or DLP.
Official sources
- Learn about sensitivity labels — classify and protect; persistent metadata; encryption and markings; contrast with retention labels
- Learn about data loss prevention — SITs, policy tips and blocks, Exchange / SharePoint / OneDrive / Teams / endpoints
- Learn about sensitive information types — credit cards, health, government IDs used by DLP, labels, and insider risk
- Learn about retention policies and labels — keep or delete; do not persist outside Microsoft 365 the way sensitivity labels do
- Study guide for Exam MS-900 — sensitivity labels and data loss prevention
A law firm wants merger documents classified as Highly Confidential, watermarked, and readable only by the deal team even after someone downloads the file from SharePoint. Which Purview Information Protection feature matches that requirement?
Finance wants Microsoft 365 to detect credit-card numbers and health record identifiers and to warn or block users who try to email them outside the company or paste them into Teams. Which capability is designed for that?
Which statement correctly separates sensitivity labels, DLP, and retention labels?
Where can Microsoft Purview DLP policies monitor for oversharing at the Microsoft 365 fundamentals level?