Create Sensitivity Label
Create Sensitivity Label
Configure sensitivity labels in Microsoft Purview for DKE
Microsoft Purview Configuration
The workflow presented below is an example of how to set up Microsoft Purview Information Protection Sensitivity Labels. The configurations listed here are example configurations and must be set up on a company-specific basis.
You can skip this chapter if you are already familiar with creating Sensitivity labels or your organization has created Label policies.
New Sensitivity Label
Basic Details
Begin by providing the basic details of your label:
| Field | Description |
|---|---|
| Name | Internal name for your label, visible only in Purview |
| Display Name | The name users will see when applying the label |
| Description for users | Description users see when choosing the label |
Define Scope of Label
Define the scope of the Sensitivity label. Admins can choose between 4 groups:
- Files and other data assets
- Emails
- Meetings
- Groups & Sites
For DKE use case, select Files and Emails.
Protection Settings
The protection settings will be enforced when the label is applied.
Choose only Control Access from the list and select Next.
Access Control
Define who has control over the Sensitivity label:
| Setting | Value |
|---|---|
| Configure access control settings | Configure now |
| Assign permissions | Assign permissions now |
| User access to content expires | Never |
| Allow offline access | Never (recommended) |
| Use Double Key Encryption | Use DKE |
| DKE Endpoint URL | Your DKE Access URL |
Offline Access Recommendations:
- Never: Use for highly sensitive content (employee/customer data, passwords, source code, financial reports). This ensures maximum security—revoked users can't reopen the document.
- Always: Use for less sensitive content where users can retain access for up to 30 days after access is removed.
How Offline Access Works: When a user opens encrypted content, they receive a use license from Azure Rights Management. This includes their usage rights, the document's encryption key, and an expiration date (default 30 days). During this time, users can access content offline without reauthentication.
Finalize Label
We recommend not enabling Auto-labeling for files and emails and to leave all Group & Sites Protection Settings unchecked. All default values of the options.
- Review the summary of the Sensitivity label
- Verify all details are correct
- Select Create Label
Purview will ask if you would like to publish it now or at a later point. Selecting Publish label will begin publishing it.
Publishing Label
If you choose to publish the label later:
- Go to the Sensitivity Labels page
- Select your newly created label
- Click Publish to create a new policy
You can publish multiple labels at the same time.
Admin Units
Do not specify admin units. This way the policy will apply to all users and groups. Select Next.
Users and Groups
The labels will be available for the users, distribution groups, mail-enabled security groups, and Microsoft 365 Groups you choose. By default, this is all Users and Groups.
Policy Settings
We recommend enabling Users must provide a justification to remove a label or lower its classification.
Publishing the policy can take a few minutes, depending on the size of your company.
Begin Using Sensitivity Labels
The user must log out and restart all Microsoft related applications (Word, Outlook, Excel, etc.) to see the Sensitivity label in the list. In some cases a full workstation restart is required.
You are now ready to begin using your Sensitivity labels.