Skip to main content

What Are Microsoft 365 Sensitivity Labels in 2026 — and How Can They Protect Your Business?

Media Three colleagues collaborating at a laptop, with a plant in the foreground.

 

Businesses store enormous amounts of sensitive information inside Microsoft 365.

Customer records.

Contracts.

Financial information.

HR documents.

Board papers.

Legal correspondence.

Commercial proposals.

Project information.

And increasingly, information that can also be discovered and used through Microsoft 365 Copilot.

The challenge is that not every document should be treated in the same way.

A company brochure can be freely shared.

A staff procedure might be internal only.

A customer contract could be confidential.

An acquisition document might need to be restricted to just a handful of directors.

That is where Microsoft Purview sensitivity labels come in.

Sensitivity labels allow organisations to classify information according to its sensitivity and then apply appropriate protection to that information. Depending on the configuration, labels can enforce encryption, add visual markings, restrict access and help control collaboration across Microsoft 365.

Instead of relying entirely on employees remembering which information is sensitive every time they send an email or share a document, sensitivity labels can turn your data-classification policy into practical Microsoft 365 controls.

What Is a Sensitivity Label?

Think of a sensitivity label as a digital classification attached to information.

A simple business structure might contain labels such as:

Public

Internal

Confidential

Highly Confidential

A law firm, financial organisation or other business with specialist requirements might introduce additional categories, but simpler is usually better.

Once applied, the label can remain associated with the information.

This is one of the biggest differences between sensitivity labels and ordinary file permissions.

Permissions often depend heavily on where the information currently lives.

Sensitivity-label protection can travel with supported content.

For example, an encrypted confidential Word document can retain its protection when somebody downloads it from SharePoint or sends it elsewhere. Microsoft describes sensitivity labels as persistent metadata that can remain with information as it moves between supported applications, services and devices.

What Can Microsoft Purview Sensitivity Labels Protect?

Sensitivity labels now extend considerably beyond Word documents.

Depending on the label scope, configuration, licensing and workload, Microsoft supports sensitivity-labelling scenarios across areas including:

Office documents

Email

Microsoft Teams

SharePoint sites

Microsoft 365 Groups

Loop workspaces and components

Meetings and calendar items

and other Microsoft data-protection scenarios.

That makes them increasingly important as Microsoft 365 becomes the information platform underpinning the business rather than simply an email system.

1. Classify Information Clearly

The first job of a sensitivity label is classification.

A user looking at a file can immediately understand how the organisation expects that information to be handled.

For example:

Public

Information approved for external distribution.

Marketing brochures, public price lists and published website material might fall here.

Internal

Routine business information intended for employees but not necessarily for public distribution.

Confidential

Sensitive customer information, financial information, contracts or commercial documentation.

Highly Confidential

HR records, board papers, acquisition information, legal material or other information requiring restricted access.

The exact names are up to the organisation.

The important thing is that employees understand them.

Creating twelve different shades of confidential information may look sophisticated in a policy document, but if employees cannot distinguish between them, the system becomes counterproductive.

A good classification scheme should make the correct decision reasonably obvious.

2. Encrypt Sensitive Documents and Emails

Sensitivity labels can do more than display a classification.

They can also apply encryption and usage restrictions.

For example, a Highly Confidential document might be configured so that only specified users or groups can open it.

Depending on how protection is configured, organisations can control actions such as reading, editing, printing, copying or forwarding protected content.

Imagine an executive report is accidentally emailed outside the organisation.

Without persistent protection, the recipient may simply open it.

If appropriate label-based encryption has been applied, possession of the file does not necessarily mean permission to read it.

That is an important distinction.

Security should not always disappear the moment a document leaves its original SharePoint library.

3. Add Headers, Footers and Watermarks

Labels can also provide visible protection.

For example:

CONFIDENTIAL

could appear in the document header.

Or:

INTERNAL USE ONLY

could be displayed as a footer or watermark.

These markings do not replace technical security controls, but they provide an immediate reminder to employees.

Someone preparing to screen-share or send a document externally may notice:

HIGHLY CONFIDENTIAL

across the document and reconsider what they are about to do.

Sometimes that small behavioural prompt is valuable.

4. Protect Teams, SharePoint and Microsoft 365 Groups

Sensitivity labels are not limited to individual documents.

Microsoft also supports applying labels to containers such as Teams, SharePoint sites and Microsoft 365 Groups.

This is an important concept.

Suppose your organisation has:

General Company Team

Marketing Team

Board Team

Acquisition Project Team

They clearly should not all have identical collaboration policies.

A sensitivity label applied to a Team or SharePoint site can influence settings such as privacy and external collaboration depending on how the organisation configures the labels.

For example:

Internal

might permit normal internal collaboration.

Confidential

might restrict external sharing.

Highly Confidential

might require stricter privacy or access conditions.

This helps security follow the purpose of the workspace rather than relying on administrators remembering to configure every new Team perfectly.

Container Labels and Document Labels Aren't Exactly the Same Thing

This is an important nuance that the previous article did not explain.

A sensitivity label applied to a SharePoint site or Team protects the container and its collaboration settings.

That does not automatically mean every document inside it receives that same document-level encryption.

Microsoft distinguishes between sensitivity labels used for content and those used to protect collaboration containers.

For example:

A SharePoint site could be classified as Confidential and restricted from external sharing.

Documents inside the site could also have their own individual sensitivity labels.

Understanding this distinction prevents organisations from assuming:

“The Team is labelled Confidential, therefore every file inside it is automatically encrypted as Confidential.”

Your labelling strategy needs to consider both levels.

5. Use Sensitivity Labels With SharePoint and OneDrive

Sensitivity labelling can integrate directly with SharePoint and OneDrive.

Microsoft now supports users viewing and applying supported sensitivity labels from the details pane without necessarily needing to open the file first. The same experience can also be available through the Files area in Teams.

This makes classification much more practical.

Rather than expecting users to open every Word or Excel file before classifying it, labels become part of the information-management environment itself.

However, administrators need to configure the relevant Microsoft Purview and SharePoint/OneDrive capabilities properly. Microsoft still documents enabling sensitivity-label support for files in SharePoint and OneDrive as an important configuration step.

6. Automatically Apply Labels Where Appropriate

Manual labelling is useful.

But people forget things.

Microsoft Purview can also support automatic labelling where appropriate licensing and configuration are available.

Policies can evaluate information against defined conditions and apply or recommend sensitivity labels when sensitive content is detected.

For example, the organisation might identify documents containing specific types of financial or personal information.

Instead of hoping every employee remembers:

“This particular spreadsheet should be Confidential.”

Microsoft Purview can help automate the process.

This becomes particularly useful in larger organisations where thousands or millions of files make purely manual classification unrealistic.

However, automatic labelling should be tested carefully.

An over-aggressive policy that labels practically everything Highly Confidential can create enormous frustration.

Security controls work best when they are accurate enough that employees trust them.

7. Sensitivity Labels Matter Even More With Microsoft 365 Copilot

This is one of the biggest reasons I would update the previous article.

AI changes the importance of information governance.

Microsoft 365 Copilot can help employees find, summarise and work with information they are already authorised to access.

That makes getting permissions and information classification right before broad AI adoption extremely important.

Microsoft documents that Microsoft 365 Copilot works with existing Microsoft Purview sensitivity labels and encryption controls. Sensitivity labels can also be displayed in Copilot experiences so users retain information about the classification of referenced content.

This does not mean sensitivity labels magically solve every Copilot security problem.

You still need to review:

SharePoint permissions.

OneDrive sharing.

Teams membership.

Old data.

External access.

Overshared information.

But labels provide another important information-protection layer.

Think of it this way

Before Copilot, an employee might need to know that a sensitive document existed and manually find it.

AI can make information much easier to discover.

That is brilliant for productivity.

But it also makes poor information governance much more visible.

The correct reaction is not:

“Don't deploy AI.”

It is:

“Fix the permissions, classification and governance first.”

8. Sensitivity Labels Can Work With DLP

Sensitivity labels and Data Loss Prevention — DLP — are related, but they are not the same feature.

Sensitivity labels answer questions such as:

How sensitive is this information?

and:

What protection should stay attached to it?

DLP policies can look at information and activity and decide whether particular actions should be allowed, warned about or blocked.

Microsoft Purview supports combining information protection and DLP so organisations can build more sophisticated data-security policies.

For example, an organisation might decide:

Highly Confidential information should not normally be shared externally.

The label provides classification.

DLP can become another enforcement layer.

Microsoft also provides DLP capabilities relating specifically to Microsoft 365 Copilot and Copilot Chat scenarios.

9. Sensitivity Labels Now Extend Into Microsoft Loop

Microsoft Loop has become increasingly important for collaborative work.

Microsoft's current documentation supports using sensitivity labels with Loop so organisations can extend information protection into Loop-created information and workspaces.

This matters because business information increasingly does not live exclusively inside traditional Word documents.

Modern collaboration creates information across:

Teams.

Loop.

SharePoint.

OneDrive.

Email.

Meetings.

AI interactions.

A modern classification strategy therefore needs to follow the way people actually work.

10. Labels Should Reflect Business Risk, Not IT Terminology

One of the biggest mistakes businesses make is allowing IT to design sensitivity labels in isolation.

Sensitivity labels are not primarily an IT problem.

They are an information-governance problem implemented through technology.

Someone needs to decide:

Which data genuinely matters?

What would cause damage if disclosed?

Which information can leave the organisation?

Who should access confidential material?

Which customers have contractual confidentiality requirements?

What needs encryption?

Which departments need external collaboration?

Those decisions may require input from:

Management.

IT.

Cyber security.

HR.

Finance.

Legal or compliance.

Department heads.

Only then should the technology be configured.

Keep the Label Structure Simple

A common mistake is creating too many labels.

You might start with:

Public.

Internal.

Confidential.

Highly Confidential.

Then somebody suggests:

Internal Confidential.

Customer Confidential.

Customer Highly Confidential.

Finance Confidential.

Restricted Confidential.

Executive Highly Restricted.

Suddenly employees need a flowchart every time they save a spreadsheet.

That's not good information protection.

Microsoft's labelling system is powerful, but the design should remain understandable.

For many SMEs, a smaller number of clear labels is likely to work better than a huge classification hierarchy.

Microsoft is also rolling out a newer modern label scheme that can migrate previous parent-label structures into label groups, another reason organisations with established Purview configurations should periodically review how their label taxonomy is designed.

Don't Encrypt Everything

Another mistake is assuming:

More encryption = more security.

Technically, perhaps.

Operationally, not necessarily.

Encrypting ordinary internal documentation unnecessarily can create:

Access problems.

External collaboration problems.

Application compatibility issues.

Administrative overhead.

User frustration.

A sensible sensitivity-label project asks:

What genuinely requires persistent encryption?

rather than encrypting every document because the feature exists.

Good security should protect the organisation while allowing employees to work.

Test Before Rolling Labels Out Across the Company

Start with a pilot.

Choose representative users.

Perhaps:

Finance.

Management.

HR.

An ordinary office user.

Someone who collaborates externally.

Then test realistic scenarios.

Can employees understand the labels?

Do external recipients behave as expected?

Can mobile users open protected content?

Does encryption affect existing workflows?

How does the labelling behave in Outlook?

What happens in SharePoint?

What happens in Teams?

Does Copilot behave as expected?

Testing ten employees is significantly easier than discovering a policy mistake after deployment to 300.

Train Employees

Even an excellent technical configuration can fail if nobody understands it.

Employees should know:

What each label means.

When to apply it.

What happens when they apply it.

Whether labels can be changed.

When external sharing is permitted.

What to do when unsure.

Do not give employees a 60-page information-classification manual and expect success.

Use realistic examples.

Marketing brochure → Public

Staff procedure → Internal

Customer contract → Confidential

Board acquisition discussion → Highly Confidential

That is much easier to understand.

Are Sensitivity Labels Enough to Protect Microsoft 365?

No.

They are one layer.

A properly secured Microsoft 365 environment may also need:

Strong MFA or passkeys

Microsoft Entra Conditional Access

Microsoft Defender

Endpoint security and EDR

Appropriate SharePoint permissions

External-sharing controls

Data Loss Prevention

Retention policies

Audit logging

Privileged-access controls

Backup and recovery

Security awareness training

Sensitivity labels are excellent at helping answer:

“How should this information be handled?”

But they should sit inside a wider Microsoft 365 security strategy.

Microsoft 365 Sensitivity Labels in 2026: The Key Message

Sensitivity labels are no longer simply colourful tags saying:

Confidential

They are part of Microsoft Purview Information Protection and can provide persistent classification and protection across Microsoft 365.

They can help businesses:

Classify information.

Encrypt sensitive files and emails.

Add visual markings.

Control collaboration environments.

Support automatic classification.

Improve information governance.

Extend protection into modern services such as Loop.

And increasingly, support safer adoption of Microsoft 365 Copilot.

The technology is powerful.

But the most important work happens before anyone creates the first label.

You need to understand which information matters, who should access it and how employees genuinely need to collaborate.

Then configure Purview around the business.

Not the other way around.

Microsoft Purview and Sensitivity Labels With Hamilton Group

Hamilton Group can help businesses review and improve how sensitive information is protected across Microsoft 365.

We can help with Microsoft Purview sensitivity labels, SharePoint and OneDrive permissions, Teams security, external sharing, Microsoft 365 Copilot readiness, Microsoft Entra ID, Conditional Access, Microsoft Defender, DLP and wider Microsoft 365 security.

We can also help design a practical label structure that employees can actually understand rather than deploying a complicated classification system simply because Microsoft makes it technically possible.

The objective is to make information easier to classify, harder to expose accidentally and appropriately protected wherever the business needs to use it.

And when your employees need IT support, our aim is to make first contact on support requests within 15 minutes.

Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our Microsoft 365 and cyber-security experts.