Skip to main content

Create Sensitivity Label

Applies to:
Microsoft PurviewSensitivity LabelsInformation Protection

Microsoft Purview Configuration​

The workflow presented below is an example of how to set up Microsoft Purview Information Protection Sensitivity Labels. The configurations listed here are example configurations and must be set up on a company-specific basis.

Note

You can skip this chapter if you are already familiar with creating Sensitivity labels or your organization has created Label policies.

New Sensitivity Label​

1

Basic Details

Begin by providing the basic details of your label:

FieldDescription
NameInternal name for your label, visible only in Purview
Display NameThe name users will see when applying the label
Description for usersDescription users see when choosing the label
2

Define Scope of Label

Define the scope of the Sensitivity label. Admins can choose between 4 groups:

  • Files and other data assets
  • Emails
  • Meetings
  • Groups & Sites

For DKE use case, select Files and Emails.

3

Protection Settings

The protection settings will be enforced when the label is applied.

Choose only Control Access from the list and select Next.

4

Access Control

Define who has control over the Sensitivity label:

SettingValue
Configure access control settingsConfigure now
Assign permissionsAssign permissions now
User access to content expiresNever
Allow offline accessNever (recommended)
Use Double Key EncryptionUse DKE
DKE Endpoint URLYour DKE Access URL
Tip

Offline Access Recommendations:

  • Never: Use for highly sensitive content (employee/customer data, passwords, source code, financial reports). This ensures maximum security—revoked users can't reopen the document.
  • Always: Use for less sensitive content where users can retain access for up to 30 days after access is removed.
Important

How Offline Access Works: When a user opens encrypted content, they receive a use license from Azure Rights Management. This includes their usage rights, the document's encryption key, and an expiration date (default 30 days). During this time, users can access content offline without reauthentication.

Finalize Label​

Note

We recommend not enabling Auto-labeling for files and emails and to leave all Group & Sites Protection Settings unchecked. All default values of the options.

  1. Review the summary of the Sensitivity label
  2. Verify all details are correct
  3. Select Create Label

Purview will ask if you would like to publish it now or at a later point. Selecting Publish label will begin publishing it.

Publishing Label​

If you choose to publish the label later:

  1. Go to the Sensitivity Labels page
  2. Select your newly created label
  3. Click Publish to create a new policy

You can publish multiple labels at the same time.

Admin Units​

Do not specify admin units. This way the policy will apply to all users and groups. Select Next.

Users and Groups​

The labels will be available for the users, distribution groups, mail-enabled security groups, and Microsoft 365 Groups you choose. By default, this is all Users and Groups.

Policy Settings​

Tip

We recommend enabling Users must provide a justification to remove a label or lower its classification.

Note

Publishing the policy can take a few minutes, depending on the size of your company.

Begin Using Sensitivity Labels​

Important

The user must log out and restart all Microsoft related applications (Word, Outlook, Excel, etc.) to see the Sensitivity label in the list. In some cases a full workstation restart is required.

You are now ready to begin using your Sensitivity labels.

What's Next​