Purview's way of classifying, and if needed encrypting, content in Office apps and services. They take over from the classic labels of AIP.
Also called Microsoft Purview sensitivity labels.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500SC-900AB-900DP-600DP-700PL-300SC-401
Each book explains Sensitivity labels in context, with comparison tables and the common traps.
Terms in this definition
- Take over
Only an owner can set up scheduled refresh, data source credentials and automatic aggregations for a semantic model. This action, in the model's settings in the service, transfers ownership to whoever selects it.
- Azure Information Protection
Service that classifies and protects documents in Office apps, applying a single label to each (if several match, the last one in the policy wins). Its classic client has been retired, with Microsoft Purview sensitivity labels taking over.
Related terms
- Azure Rights Management
The service that does the actual encrypting behind sensitivity labels, message encryption and DKE in Purview Information Protection, attaching usage rights to protected content. Newer tenants get it switched on automatically; older ones turn it on with PowerShell.
- EnableMIPLabels
Set this Entra group setting to True with Microsoft Graph PowerShell to allow sensitivity labels on Teams, SharePoint sites and Microsoft 365 groups; afterwards run Execute-AzureAdLabelSync to bring the labels across.
- Execute-AzureAdLabelSync
Run from Security & Compliance PowerShell to copy sensitivity labels into Microsoft Entra ID, after which Teams, SharePoint sites and groups can use them. Allow up to a day for them to appear.
- Information Protection Admins
A role group in Microsoft Purview whose members create, change and remove DLP policies, sensitivity labels, label policies and every kind of classifier. They also look after endpoint DLP settings.
- Information Protection Analysts
People in this Microsoft Purview role group work with activity explorer and DLP alerts. They can look at, but not change, classifiers, sensitivity labels and DLP policies.
- Information Protection Readers
A role group in Microsoft Purview that can only view reports about sensitivity labels and DLP policies.
- IRM
Protection that stops recipients doing things like printing, copying or forwarding documents and messages. Microsoft 365 delivers it through Azure Rights Management, and today it is applied with sensitivity labels.
- Label group
Sensitivity labels in the modern scheme sit inside these containers, which carry nothing but a name, description, colour and priority. You can't publish one by itself, and they take over the job parent labels used to do.