To deploy Microsoft Purview sensitivity labels, create a small set of labels (for example Public, General, Confidential and Highly Confidential) in the Microsoft Purview portal under Information Protection > Sensitivity labels, add encryption only to the labels that need it, and publish them with a label policy that sets a non-encrypting default label and requires justification for downgrades. Enable sensitivity labels for Office files in SharePoint and OneDrive before you publish encrypting labels, pilot with a few users, and only then add auto-labeling policies, which must run in simulation before they can label anything. Allow up to 24 hours for each change to reach all apps.
Who this is for and what you will have
This guide is for Microsoft 365 and compliance administrators starting a sensitivity label rollout, or cleaning up one that stalled. It covers documents and email; container labels for Teams, groups and sites are mentioned only where they affect the design.
At the end you will have:
- A label taxonomy users can understand, in the right priority order.
- Labels with content markings and, where needed, encryption configured with deliberate permission choices.
- A label policy with a default label, justification for downgrades and a help link.
- SharePoint and OneDrive able to process encrypted files, with co-authoring considered.
- An auto-labeling policy for one high-value sensitive information type, validated in simulation.
How sensitivity labels work
A sensitivity label is stored in clear text in the metadata of a file or email, so it travels with the content and other apps can read it. Each item can have one sensitivity label (plus one retention label). A label can:
- Apply encryption through the Azure Rights Management service and restrict who can open the content and what they can do.
- Add content markings: headers and footers (up to 1,024 characters, with a 255-character total in Excel) and watermarks (up to 255 characters, documents only).
- Be applied automatically or recommended to users when sensitive information is detected.
- Protect containers, if you enable labels for groups and sites.
Labels do nothing until a label policy publishes them to users or groups. The policy also carries settings such as the default label and mandatory labeling.
Priority matters twice
Label order sets sensitivity. The least sensitive label sits at the top of the list and the most sensitive at the bottom. Justification prompts and auto-labeling both use this order to decide what counts as a downgrade or a higher-priority label.
Label policy order resolves conflicts. A user can be in several label policies and gets all their labels, but when settings conflict, the policy with the highest order number (lowest in the list) wins for each setting. Keep the organization-wide policy at the top and more specific policies below it.
Sublabels and label groups
Two-tier labels such as Confidential \ All Employees were originally built with parent labels and sublabels. Microsoft is replacing parent labels with label groups in the modern label scheme, which applies to tenants without labels or created from October 1, 2025, or tenants that migrated. Label groups have only a name, descriptions, color and priority and can't be published themselves. If you still use parent labels, never choose a parent label as a default or for auto-labeling, because a parent label can't be applied to content.
Prerequisites
- Permissions: membership in the Information Protection or Information Protection Admins role group, a custom role group with Sensitivity Label Administrator, or the Compliance Administrator, Compliance Data Administrator or Security Administrator role group.
- Licensing: users and admins need licences that include sensitivity labeling; check the Microsoft Purview service description for your plan. Auto-labeling, both client-side and service-side, is included with Microsoft 365 E5, Microsoft 365 E5 Compliance, Microsoft 365 E5 Information Protection and Governance and Azure Information Protection Premium P2; Microsoft notes it isn't included in E3 or Business Premium without an add-on.
- Azure Rights Management activated for encryption. It is on by default in newer tenants, but the portal doesn't check this when you configure encryption.
- Exchange Online configured for Rights Management if you want encrypted email in Outlook on the web and mobile, search indexing of encrypted email and DLP for protected messages.
- Microsoft Entra configuration reviewed: cross-tenant access settings and Conditional Access policies can block access to encrypted content for external users.
- Microsoft 365 auditing turned on, which auto-labeling simulation requires.
- Office apps that use built-in labeling, such as Microsoft 365 Apps for enterprise.
Step 1: Design the taxonomy
Start with names your users already use. Microsoft suggests Personal, Public, General, Confidential and Highly Confidential as a starting point, and notes that effectiveness drops when users see more than five main labels or more than five sublabels under one. Write a tooltip for each label with concrete examples; long tooltips get truncated.
A practical first design:
| Label (top to bottom) | Markings | Encryption | Typical use |
|---|---|---|---|
| Public | None | None | Marketing material, published documents |
| General | Footer "General" | None | Day-to-day internal work; good default |
| Confidential \ All Employees | Header and footer | Assign permissions now: an all-employees group, Editor | Internal plans, HR policies |
| Confidential \ Anyone (unrestricted) | Header and footer | None | Confidential content that must go to partners |
| Highly Confidential \ Specified people | Header, footer, watermark | Let users assign permissions | Board papers, M&A, legal |
Start some labels without encryption and add it later if needed. When you later add encryption to a label, files in SharePoint and OneDrive pick up the new encryption when they're next accessed, but other already-labeled items keep their old state until the label is removed and reapplied.
Step 2: Create the labels
- Sign in to the Microsoft Purview portal and go to Solutions > Information Protection > Sensitivity labels.
- Select + Create > Label (or + Create a label in the classic scheme). In the modern scheme, create a Label group first for two-tier labels and create labels inside it with Create label in group.
- Enter the label name and a description for users that explains when to use it.
- On Define the scope for this label, select Files & other data assets and Emails. Meetings needs both of those selected. Groups & sites appears only after you enable labels for containers.
- On Choose protection settings for the types of items you selected, select the settings you need, including Control access if the label encrypts, and follow the prompts for each.
- Repeat for each label, then use ... > Move up or Move down so the most sensitive label is last.
The same can be scripted in Security & Compliance PowerShell:
Connect-IPPSSession -UserPrincipalName admin@contoso.com
New-Label -Name "General" -DisplayName "General" -Tooltip "Internal business data that isn't intended for public release." -ContentType "File, Email"
Get-Label | Format-Table -Property DisplayName, Name, Guid, ContentTypeMicrosoft recommends referring to labels by GUID in scripts, because display names aren't unique.
Step 3: Configure encryption deliberately
When you select Control access, choose Configure access control settings, then one of two models.
Assign permissions now
You decide who gets which rights. Add users or groups, or use Add any authenticated users where you only need encryption without restricting who opens the content. Then pick a predefined permission level, such as Editor or Restricted Editor, or custom usage rights. One label can grant different rights to different users and groups.
Two settings need care:
| Setting | Microsoft's recommendation | Side effects |
|---|---|---|
| User access to content expires | Never unless the content is time-bound | Any value other than Never stops SharePoint and OneDrive processing the file and blocks co-authoring |
| Allow offline access | Only for a number of days = 7 for sensitive business data; Never for the most sensitive data | Lower values force more frequent reauthentication |
The person who applies the label becomes the Rights Management issuer and always keeps Full Control, even after expiry.
Let users assign permissions
Users choose recipients or permissions when they apply the label. In Outlook you can enforce Do Not Forward (no forwarding, printing or copying) or Encrypt-Only (all rights except Save As, Export and Full Control, so recipients can't remove protection). In Word, Excel and PowerPoint users are prompted to specify people and permissions. Unencrypted Office attachments on an encrypted email automatically inherit the email's encryption.
If you plan a future tenant-to-tenant migration, note that labels must be recreated in the target and sites with user-defined permission labels can't be moved, as described in the cross-tenant migration architecture.
Step 4: Enable labels in SharePoint and OneDrive
Until you enable this, SharePoint and OneDrive can't process encrypted Office files, so search, eDiscovery, DLP, co-authoring and Office for the web don't work for them.
- In the Purview portal, go to Information Protection > Sensitivity labels. If you see a message to turn on processing for Office online files, select Turn on now. This requires a Global Administrator.
- Or use SharePoint Online Management Shell 16.0.19418.12000 or later. For Multi-Geo, run it in each geo:
Connect-SPOService -Url https://contoso-admin.sharepoint.com
Set-SPOTenant -EnableAIPIntegration $true
Set-SPOTenant -EnableSensitivityLabelforPDF $trueThe PDF setting needs version 16.0.24211.12000 or later. Tenant-level SharePoint changes take about 15 minutes. Files labeled and encrypted before you enable this aren't processed until they are edited, or downloaded and uploaded again.
Co-authoring for encrypted files
Without it, Office desktop apps open encrypted files in exclusive mode and AutoSave is off. To enable it, go to Settings > Solution settings > Information Protection > Co-authoring for files with sensitivity labels and wait 24 hours. Read the warning first: it changes where label metadata is stored, every app and tool that reads labels must support the new format, and it can only be turned off with Set-PolicyConfig -EnableLabelCoauth:$false, which loses label information for unencrypted files.
Step 5: Publish with a label policy
- Go to Information Protection > Publishing policies and select Publish label.
- Choose the labels. In the classic scheme, include the parent of every sublabel.
- Keep Full directory unless you use administrative units.
- Choose users and groups. Mail-enabled security groups, distribution groups and Microsoft 365 groups (including dynamic membership) are supported.
- Configure the policy settings:
- Require a justification when users remove a label or replace it with a lower-priority one: on. Justifications appear in activity explorer.
- Mandatory labeling for documents and email: only together with a default label, or users get frequent prompts.
- Provide users with a link to a custom help page: your internal labeling guide.
- Default label for documents: General. For email, General as well. Microsoft advises against an encrypting default for documents because external recipients often can't open them.
- Name the policy and submit. It publishes automatically.
Pilot first: Microsoft recommends publishing new labels to a few test users, waiting at least an hour to check SharePoint and OneDrive behavior, and waiting a day before widening the policy so the labels have replicated to the services.
New-LabelPolicy -Name "Labels - Pilot" -Labels "Public","General","Confidential" -ExchangeLocation "pilot1@contoso.com","pilot2@contoso.com"Step 6: Add auto-labeling
There are two complementary methods:
| Auto-labeling in the label | Auto-labeling policy | |
|---|---|---|
| Runs | In Office apps as users work | In the service for SharePoint, OneDrive and Exchange |
| Can recommend instead of apply | Yes | No |
| Simulation mode | No | Yes, required before turning on |
| Labels files at rest and incoming email | No | Yes |
| Replaces a manually applied lower-priority label | No | Configurable |
Neither method replaces a manually applied label by default, and neither replaces a label with a higher priority.
To create a service-side policy:
- Go to Information Protection > Policies > Auto-labeling policies and select + Create auto-labeling policy, then choose to apply a label (policies can also remove a label).
- Pick a template, such as a financial or privacy regulation, or Custom.
- Choose the label, the locations (SharePoint sites, OneDrive users or groups, Exchange) and the rules, for example a sensitive information type with a minimum instance count.
- On the last page, select Run policy in simulation mode.
Simulation can take 12 hours. Policy management actions can be unavailable for about 24 hours after creation, and simulation can still trigger alert policies. Review the matched items, refine the rules, and rerun. Turning the policy on requires Compliance Administrator or Compliance Data Administrator.
Verify the deployment
- In an Office app, the Sensitivity button shows your labels, the default label is applied to a new document and the help link appears.
- Lowering a label prompts for justification.
- An encrypted file uploaded to SharePoint opens in Office for the web and shows the label in the Sensitivity column.
Get-Labelin Security & Compliance PowerShell returns the expected labels, GUIDs and content types.- SharePoint search finds labeled files with
InformationProtectionLabelId:<label GUID>. - The audit log records Applied sensitivity label to file events.
Troubleshooting
Labels don't appear for users. Wait 24 hours, check the user is in a group in the policy, and check that the label scope includes files or email. Labels with no scope selected aren't shown.
"You don't have permission to make this change to the sensitivity label. Please contact the content owner." The user lacks the Export or Full Control right, or the issuer, owner or super user role needed to replace existing encryption, so the original encryption stays.
An encrypted file won't open in Office for the web or isn't found by search. Check that SharePoint integration is enabled, the label doesn't use access expiry or Double Key Encryption, and the file wasn't labeled before integration (download and upload it again). Files over 12 MB that are copied or moved to another site can't be processed.
A parent label never gets applied by default or auto-labeling. Parent labels can't be applied to content; select a sublabel.
External recipients can't open labeled documents. Review guest accounts, cross-tenant access settings and Conditional Access, or use a label that doesn't encrypt for external sharing.
Checklist
- Rights Management activated and Exchange configured for it.
- Five or fewer main labels, ordered least to most sensitive, with clear tooltips.
- Encryption only on labels that need it; access expiry left at Never; offline access set deliberately.
- SharePoint and OneDrive label integration enabled (and PDF if needed); co-authoring decision documented.
- Label policy with General as default, downgrade justification and a help link; piloted before wide release.
- Auto-labeling policies run in simulation and reviewed before turning on.
- Verification done in Office desktop, Office for the web, search and the audit log.
References
- Learn about sensitivity labels
- Get started with sensitivity labels
- Create and publish sensitivity labels
- Apply encryption using sensitivity labels
- Enable sensitivity labels for files in SharePoint and OneDrive
- Enable co-authoring for encrypted documents
- Automatically apply a sensitivity label to Microsoft 365 data
- New-Label
- New-LabelPolicy