Compliance
Sensitivity labels
Microsoft Purview sensitivity labels
Microsoft Purview sensitivity labels are the mechanism for classifying and protecting content, documents, emails, Teams meetings, and, in the current unified taxonomy, containers such as SharePoint sites, Teams, and Microsoft 365 Groups, based on its business sensitivity.
Why Sensitivity labels matters in a Microsoft estate
Sensitivity labels matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How Sensitivity labels shows up in practice
They apply protections that travel with the content itself, rather than depending solely on where it happens to be stored. A label such as Confidential or Highly Confidential can carry encryption that restricts who can open, edit, forward, or print a document, visual markings like headers, footers, or watermarks that make the classification visible to users, and content-specific restrictions. Because the protection is embedded in the file through Microsoft's rights management service, it persists even if the file is later downloaded, emailed, or moved outside the tenant, unlike protections that rely purely on the storage location's own permissions.
Labels can be applied manually by end users choosing from a defined taxonomy, recommended to users based on content detected as matching a sensitive information type, or applied automatically for content matching defined patterns. Container-level labels can independently drive settings like whether a Team or SharePoint site permits external sharing or unmanaged device access, meaning a single label choice made when a site is created can carry meaningful and sometimes overlooked security consequences. Sensitivity labels are commonly confused with retention labels despite sharing the same Purview infrastructure and admin experience. Sensitivity labels control who can access and what they can do with content, while retention labels control how long content is kept and whether it is disposed of.
Both can, since Microsoft's taxonomy unification, be managed from a similar interface, but they answer entirely different governance questions, and a given piece of content will often carry one of each rather than only one or the other. Getting real value from sensitivity labels depends heavily on classification accuracy. A taxonomy with too many overlapping labels leads to inconsistent application and user confusion about which one to choose, while automatic classification tuned too broadly generates false positives that erode user trust in the labelling prompts and encourage them to be dismissed rather than acted on.
A commonly recommended approach is starting with a small number of clearly differentiated labels and expanding only where a genuine business need for finer granularity is demonstrated. For organisations pursuing ISO/IEC 27001 or SOC 2, sensitivity labels are frequently the practical implementation of the standard's required information classification scheme and the access control and data handling controls that follow from it. DLP policies commonly reference sensitivity labels directly as a condition, meaning a document's label can be the trigger that blocks it from being shared externally or attached to an outbound email in the first place.