A Purview policy that makes sensitivity labels available to selected users and groups. It also controls settings like which label applies by default, whether people have to label content, and whether they must give a reason before removing a label or choosing a less restrictive one.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Label policy in context, with comparison tables and the common traps.
Terms in this definition
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Sensitivity labels
Purview's way of classifying, and if needed encrypting, content in Office apps and services. They take over from the classic labels of AIP.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- Route table label
Name for a set of route tables in Virtual WAN hubs, used when choosing where routes propagate; Default, for instance, covers the defaultRouteTable of every hub.
Related terms
- Default label
Lets a label policy put a set sensitivity label on content that has none, from emails and files to new sites, groups and Power BI items. People can swap it for another, and it leaves existing labels untouched, which isn't true of a library's default.
- Default label policy
A Purview sensitivity label policy option (Apply this default label to Power BI content) that automatically labels any Fabric or Power BI item saved without one, whether new or edited. Files and email have their own, separate default label.
- Mandatory label policy
When this sensitivity label policy setting is on, people can't save supported Power BI or Fabric content until they pick a label. It has no effect on service principals, API calls or B2B guest users, and certain items, including Dataflow Gen2, are excluded.
- Mandatory labelling
A label policy option in Microsoft Purview: until a sensitivity label is picked, people can't save or send files and emails, or create new groups and sites.
- PFileSupportedExtensions
An advanced setting in an information protection client label policy that controls which file types get encrypted. The scanner protects only PDFs and Office files unless this setting widens the list.
- setLabels
Bulk labelling through an admin REST API: it applies one sensitivity label to many items, named by their IDs, while removeLabels undoes this. Callers need to be Fabric administrators whose label policy contains that label, and there's a ceiling of 25 calls an hour, each covering up to 2,000 items.