Security & identity

Deploy Purview sensitivity labels: encryption, defaults and auto-labeling

Plan, create and publish Microsoft Purview sensitivity labels, add encryption safely, set default and mandatory labeling, and roll out auto-labeling with simulation.

13 min read
On this page

To deploy Microsoft Purview sensitivity labels, create a small set of labels (for example Public, General, Confidential and Highly Confidential) in the Microsoft Purview portal under Information Protection > Sensitivity labels, add encryption only to the labels that need it, and publish them with a label policy that sets a non-encrypting default label and requires justification for downgrades. Enable sensitivity labels for Office files in SharePoint and OneDrive before you publish encrypting labels, pilot with a few users, and only then add auto-labeling policies, which must run in simulation before they can label anything. Allow up to 24 hours for each change to reach all apps.

Who this is for and what you will have

This guide is for Microsoft 365 and compliance administrators starting a sensitivity label rollout, or cleaning up one that stalled. It covers documents and email; container labels for Teams, groups and sites are mentioned only where they affect the design.

At the end you will have:

  • A label taxonomy users can understand, in the right priority order.
  • Labels with content markings and, where needed, encryption configured with deliberate permission choices.
  • A label policy with a default label, justification for downgrades and a help link.
  • SharePoint and OneDrive able to process encrypted files, with co-authoring considered.
  • An auto-labeling policy for one high-value sensitive information type, validated in simulation.

How sensitivity labels work

A sensitivity label is stored in clear text in the metadata of a file or email, so it travels with the content and other apps can read it. Each item can have one sensitivity label (plus one retention label). A label can:

  • Apply encryption through the Azure Rights Management service and restrict who can open the content and what they can do.
  • Add content markings: headers and footers (up to 1,024 characters, with a 255-character total in Excel) and watermarks (up to 255 characters, documents only).
  • Be applied automatically or recommended to users when sensitive information is detected.
  • Protect containers, if you enable labels for groups and sites.

Labels do nothing until a label policy publishes them to users or groups. The policy also carries settings such as the default label and mandatory labeling.

Priority matters twice

Label order sets sensitivity. The least sensitive label sits at the top of the list and the most sensitive at the bottom. Justification prompts and auto-labeling both use this order to decide what counts as a downgrade or a higher-priority label.

Label policy order resolves conflicts. A user can be in several label policies and gets all their labels, but when settings conflict, the policy with the highest order number (lowest in the list) wins for each setting. Keep the organization-wide policy at the top and more specific policies below it.

Sublabels and label groups

Two-tier labels such as Confidential \ All Employees were originally built with parent labels and sublabels. Microsoft is replacing parent labels with label groups in the modern label scheme, which applies to tenants without labels or created from October 1, 2025, or tenants that migrated. Label groups have only a name, descriptions, color and priority and can't be published themselves. If you still use parent labels, never choose a parent label as a default or for auto-labeling, because a parent label can't be applied to content.

Prerequisites

  • Permissions: membership in the Information Protection or Information Protection Admins role group, a custom role group with Sensitivity Label Administrator, or the Compliance Administrator, Compliance Data Administrator or Security Administrator role group.
  • Licensing: users and admins need licences that include sensitivity labeling; check the Microsoft Purview service description for your plan. Auto-labeling, both client-side and service-side, is included with Microsoft 365 E5, Microsoft 365 E5 Compliance, Microsoft 365 E5 Information Protection and Governance and Azure Information Protection Premium P2; Microsoft notes it isn't included in E3 or Business Premium without an add-on.
  • Azure Rights Management activated for encryption. It is on by default in newer tenants, but the portal doesn't check this when you configure encryption.
  • Exchange Online configured for Rights Management if you want encrypted email in Outlook on the web and mobile, search indexing of encrypted email and DLP for protected messages.
  • Microsoft Entra configuration reviewed: cross-tenant access settings and Conditional Access policies can block access to encrypted content for external users.
  • Microsoft 365 auditing turned on, which auto-labeling simulation requires.
  • Office apps that use built-in labeling, such as Microsoft 365 Apps for enterprise.

Step 1: Design the taxonomy

Start with names your users already use. Microsoft suggests Personal, Public, General, Confidential and Highly Confidential as a starting point, and notes that effectiveness drops when users see more than five main labels or more than five sublabels under one. Write a tooltip for each label with concrete examples; long tooltips get truncated.

A practical first design:

Label (top to bottom)MarkingsEncryptionTypical use
PublicNoneNoneMarketing material, published documents
GeneralFooter "General"NoneDay-to-day internal work; good default
Confidential \ All EmployeesHeader and footerAssign permissions now: an all-employees group, EditorInternal plans, HR policies
Confidential \ Anyone (unrestricted)Header and footerNoneConfidential content that must go to partners
Highly Confidential \ Specified peopleHeader, footer, watermarkLet users assign permissionsBoard papers, M&A, legal

Start some labels without encryption and add it later if needed. When you later add encryption to a label, files in SharePoint and OneDrive pick up the new encryption when they're next accessed, but other already-labeled items keep their old state until the label is removed and reapplied.

Step 2: Create the labels

  1. Sign in to the Microsoft Purview portal and go to Solutions > Information Protection > Sensitivity labels.
  2. Select + Create > Label (or + Create a label in the classic scheme). In the modern scheme, create a Label group first for two-tier labels and create labels inside it with Create label in group.
  3. Enter the label name and a description for users that explains when to use it.
  4. On Define the scope for this label, select Files & other data assets and Emails. Meetings needs both of those selected. Groups & sites appears only after you enable labels for containers.
  5. On Choose protection settings for the types of items you selected, select the settings you need, including Control access if the label encrypts, and follow the prompts for each.
  6. Repeat for each label, then use ... > Move up or Move down so the most sensitive label is last.

The same can be scripted in Security & Compliance PowerShell:

Connect-IPPSSession -UserPrincipalName admin@contoso.com
New-Label -Name "General" -DisplayName "General" -Tooltip "Internal business data that isn't intended for public release." -ContentType "File, Email"
Get-Label | Format-Table -Property DisplayName, Name, Guid, ContentType

Microsoft recommends referring to labels by GUID in scripts, because display names aren't unique.

Step 3: Configure encryption deliberately

When you select Control access, choose Configure access control settings, then one of two models.

Assign permissions now

You decide who gets which rights. Add users or groups, or use Add any authenticated users where you only need encryption without restricting who opens the content. Then pick a predefined permission level, such as Editor or Restricted Editor, or custom usage rights. One label can grant different rights to different users and groups.

Two settings need care:

SettingMicrosoft's recommendationSide effects
User access to content expiresNever unless the content is time-boundAny value other than Never stops SharePoint and OneDrive processing the file and blocks co-authoring
Allow offline accessOnly for a number of days = 7 for sensitive business data; Never for the most sensitive dataLower values force more frequent reauthentication

The person who applies the label becomes the Rights Management issuer and always keeps Full Control, even after expiry.

Let users assign permissions

Users choose recipients or permissions when they apply the label. In Outlook you can enforce Do Not Forward (no forwarding, printing or copying) or Encrypt-Only (all rights except Save As, Export and Full Control, so recipients can't remove protection). In Word, Excel and PowerPoint users are prompted to specify people and permissions. Unencrypted Office attachments on an encrypted email automatically inherit the email's encryption.

If you plan a future tenant-to-tenant migration, note that labels must be recreated in the target and sites with user-defined permission labels can't be moved, as described in the cross-tenant migration architecture.

Step 4: Enable labels in SharePoint and OneDrive

Until you enable this, SharePoint and OneDrive can't process encrypted Office files, so search, eDiscovery, DLP, co-authoring and Office for the web don't work for them.

  1. In the Purview portal, go to Information Protection > Sensitivity labels. If you see a message to turn on processing for Office online files, select Turn on now. This requires a Global Administrator.
  2. Or use SharePoint Online Management Shell 16.0.19418.12000 or later. For Multi-Geo, run it in each geo:
Connect-SPOService -Url https://contoso-admin.sharepoint.com
Set-SPOTenant -EnableAIPIntegration $true
Set-SPOTenant -EnableSensitivityLabelforPDF $true

The PDF setting needs version 16.0.24211.12000 or later. Tenant-level SharePoint changes take about 15 minutes. Files labeled and encrypted before you enable this aren't processed until they are edited, or downloaded and uploaded again.

Co-authoring for encrypted files

Without it, Office desktop apps open encrypted files in exclusive mode and AutoSave is off. To enable it, go to Settings > Solution settings > Information Protection > Co-authoring for files with sensitivity labels and wait 24 hours. Read the warning first: it changes where label metadata is stored, every app and tool that reads labels must support the new format, and it can only be turned off with Set-PolicyConfig -EnableLabelCoauth:$false, which loses label information for unencrypted files.

Step 5: Publish with a label policy

  1. Go to Information Protection > Publishing policies and select Publish label.
  2. Choose the labels. In the classic scheme, include the parent of every sublabel.
  3. Keep Full directory unless you use administrative units.
  4. Choose users and groups. Mail-enabled security groups, distribution groups and Microsoft 365 groups (including dynamic membership) are supported.
  5. Configure the policy settings:
    • Require a justification when users remove a label or replace it with a lower-priority one: on. Justifications appear in activity explorer.
    • Mandatory labeling for documents and email: only together with a default label, or users get frequent prompts.
    • Provide users with a link to a custom help page: your internal labeling guide.
    • Default label for documents: General. For email, General as well. Microsoft advises against an encrypting default for documents because external recipients often can't open them.
  6. Name the policy and submit. It publishes automatically.

Pilot first: Microsoft recommends publishing new labels to a few test users, waiting at least an hour to check SharePoint and OneDrive behavior, and waiting a day before widening the policy so the labels have replicated to the services.

New-LabelPolicy -Name "Labels - Pilot" -Labels "Public","General","Confidential" -ExchangeLocation "pilot1@contoso.com","pilot2@contoso.com"

Step 6: Add auto-labeling

There are two complementary methods:

Auto-labeling in the labelAuto-labeling policy
RunsIn Office apps as users workIn the service for SharePoint, OneDrive and Exchange
Can recommend instead of applyYesNo
Simulation modeNoYes, required before turning on
Labels files at rest and incoming emailNoYes
Replaces a manually applied lower-priority labelNoConfigurable

Neither method replaces a manually applied label by default, and neither replaces a label with a higher priority.

To create a service-side policy:

  1. Go to Information Protection > Policies > Auto-labeling policies and select + Create auto-labeling policy, then choose to apply a label (policies can also remove a label).
  2. Pick a template, such as a financial or privacy regulation, or Custom.
  3. Choose the label, the locations (SharePoint sites, OneDrive users or groups, Exchange) and the rules, for example a sensitive information type with a minimum instance count.
  4. On the last page, select Run policy in simulation mode.

Simulation can take 12 hours. Policy management actions can be unavailable for about 24 hours after creation, and simulation can still trigger alert policies. Review the matched items, refine the rules, and rerun. Turning the policy on requires Compliance Administrator or Compliance Data Administrator.

Verify the deployment

  • In an Office app, the Sensitivity button shows your labels, the default label is applied to a new document and the help link appears.
  • Lowering a label prompts for justification.
  • An encrypted file uploaded to SharePoint opens in Office for the web and shows the label in the Sensitivity column.
  • Get-Label in Security & Compliance PowerShell returns the expected labels, GUIDs and content types.
  • SharePoint search finds labeled files with InformationProtectionLabelId:<label GUID>.
  • The audit log records Applied sensitivity label to file events.

Troubleshooting

Labels don't appear for users. Wait 24 hours, check the user is in a group in the policy, and check that the label scope includes files or email. Labels with no scope selected aren't shown.

"You don't have permission to make this change to the sensitivity label. Please contact the content owner." The user lacks the Export or Full Control right, or the issuer, owner or super user role needed to replace existing encryption, so the original encryption stays.

An encrypted file won't open in Office for the web or isn't found by search. Check that SharePoint integration is enabled, the label doesn't use access expiry or Double Key Encryption, and the file wasn't labeled before integration (download and upload it again). Files over 12 MB that are copied or moved to another site can't be processed.

A parent label never gets applied by default or auto-labeling. Parent labels can't be applied to content; select a sublabel.

External recipients can't open labeled documents. Review guest accounts, cross-tenant access settings and Conditional Access, or use a label that doesn't encrypt for external sharing.

Checklist

  • Rights Management activated and Exchange configured for it.
  • Five or fewer main labels, ordered least to most sensitive, with clear tooltips.
  • Encryption only on labels that need it; access expiry left at Never; offline access set deliberately.
  • SharePoint and OneDrive label integration enabled (and PDF if needed); co-authoring decision documented.
  • Label policy with General as default, downgrade justification and a help link; piloted before wide release.
  • Auto-labeling policies run in simulation and reviewed before turning on.
  • Verification done in Office desktop, Office for the web, search and the audit log.

References

Questions people ask

Should the default sensitivity label apply encryption?

Usually not for documents. Microsoft notes that a default label that encrypts documents often causes problems when files are shared with external users whose apps or accounts can't open encrypted content. Use a non-encrypting label such as General as the default and reserve encryption for Confidential and Highly Confidential labels.

How long do new sensitivity labels take to appear in Office apps?

Allow up to 24 hours for new labels and label policy changes to reach all apps and services. Changes that depend on new groups or group membership can take 24 to 48 hours, while Office for the web can pick up new labels within the hour.

What is the difference between auto-labeling in a label and an auto-labeling policy?

Auto-labeling in the label runs client-side in Office apps while users work, and can recommend a label instead of applying it. Auto-labeling policies run in the service for SharePoint, OneDrive and Exchange, label files at rest and email in transit, and must run in simulation first. Both need E5-level licensing such as Microsoft 365 E5 or E5 Compliance.

Why can't users open encrypted files in Office for the web?

Sensitivity labels for Office files in SharePoint and OneDrive must be enabled, with Turn on now in the Purview portal or Set-SPOTenant -EnableAIPIntegration $true. Labels with an access expiry other than Never or with Double Key Encryption still can't be processed by SharePoint and OneDrive.

Microsoft PurviewSensitivity labelsMicrosoft Information ProtectionSharePoint Online
  1. Microsoft 365 audit log search: who deleted, shared or forwarded what

    Use Microsoft Purview Audit and Search-UnifiedAuditLog to find who deleted a file, shared a link, purged email or created a forwarding rule, then export and read the AuditData.

  2. Purview retention policies and labels: meet retention, avoid data loss

    How Microsoft Purview retention policies and retention labels work across Exchange, SharePoint, OneDrive and Teams, which settings win, and how to roll them out without deleting content by accident.

  3. Stop Microsoft 365 Copilot using labelled files with Purview DLP

    Use the Purview DLP location for Microsoft 365 Copilot, sensitivity labels without the EXTRACT right and Restricted Content Discovery to keep confidential files and prompts out of Copilot responses.