Sensitivity labels are how Microsoft 365 marks content with a classification and the protections that go with it. A document labelled Confidential can carry encryption, watermarks, sharing restrictions, and retention behaviour wherever it goes.
The label hierarchy
Most organisations land on a 3 or 4 tier hierarchy:
- Public: content intended for external sharing
- Internal: content for staff and trusted contractors
- Confidential: content with restricted access (commercial, HR, board)
- Highly Confidential: content requiring encryption and tight access (legal, regulatory, M&A)
Keep the hierarchy short. 5 or more tiers and users stop reading the names.
What a label can do
A single label can apply any combination of:
- Visual markings (header, footer, watermark)
- Encryption (locks the file to specific users or groups)
- Sharing restrictions (block external, require sign-in, link expiry)
- Content marking for downstream policies (DLP, retention, auto-classification)
Where labels apply
Sensitivity labels work across:
- Office apps (Word, Excel, PowerPoint, Outlook)
- SharePoint and OneDrive (file-level)
- Microsoft 365 Groups, Teams, and SharePoint sites (container-level)
- Power BI datasets
- Schematised data assets in Microsoft Purview
Manual versus automatic labelling
Three ways to apply a label:
- Manually: users pick a label themselves
- Default: applied automatically to all new content in a location
- Auto-apply: applied based on content keywords, sensitive info types, or trainable classifiers
Start manual, then layer in default and auto-apply as your users get comfortable with the labelling habit.
Get the rollout right
The technical setup is the easy part. The hard part is the change management. Plan for:
- A short training video or in-app prompt explaining what labels mean
- A clear escalation path when users do not know which label to apply
- A pilot group before tenant-wide rollout
For help designing your label taxonomy, submit a support ticket.
Comments
0 comments
Please sign in to leave a comment.