What Are Microsoft 365 Sensitivity Labels in 2026 — and How Can They Protect Your Business?
Businesses store enormous amounts of sensitive information inside Microsoft 365.
Customer records.
Contracts.
Financial information.
HR documents.
Board papers.
Legal correspondence.
Commercial proposals.
Project information.
And increasingly, information that can also be discovered and used through Microsoft 365 Copilot.
The challenge is that not every document should be treated in the same way.
A company brochure can be freely shared.
A staff procedure might be internal only.
A customer contract could be confidential.
An acquisition document might need to be restricted to just a handful of directors.
That is where Microsoft Purview sensitivity labels come in.
Sensitivity labels allow organisations to classify information according to its sensitivity and then apply appropriate protection to that information. Depending on the configuration, labels can enforce encryption, add visual markings, restrict access and help control collaboration across Microsoft 365.
Instead of relying entirely on employees remembering which information is sensitive every time they send an email or share a document, sensitivity labels can turn your data-classification policy into practical Microsoft 365 controls.
What Is a Sensitivity Label?
Think of a sensitivity label as a digital classification attached to information.
A simple business structure might contain labels such as:
Public
Internal
Confidential
Highly Confidential
A law firm, financial organisation or other business with specialist requirements might introduce additional categories, but simpler is usually better.
Once applied, the label can remain associated with the information.
This is one of the biggest differences between sensitivity labels and ordinary file permissions.
Permissions often depend heavily on where the information currently lives.
Sensitivity-label protection can travel with supported content.
For example, an encrypted confidential Word document can retain its protection when somebody downloads it from SharePoint or sends it elsewhere. Microsoft describes sensitivity labels as persistent metadata that can remain with information as it moves between supported applications, services and devices.
What Can Microsoft Purview Sensitivity Labels Protect?
Sensitivity labels now extend considerably beyond Word documents.
Depending on the label scope, configuration, licensing and workload, Microsoft supports sensitivity-labelling scenarios across areas including:
Office documents
Microsoft Teams
SharePoint sites
Microsoft 365 Groups
Loop workspaces and components
Meetings and calendar items
and other Microsoft data-protection scenarios.
That makes them increasingly important as Microsoft 365 becomes the information platform underpinning the business rather than simply an email system.
1. Classify Information Clearly
The first job of a sensitivity label is classification.
A user looking at a file can immediately understand how the organisation expects that information to be handled.
For example:
Public
Information approved for external distribution.
Marketing brochures, public price lists and published website material might fall here.
Internal
Routine business information intended for employees but not necessarily for public distribution.
Confidential
Sensitive customer information, financial information, contracts or commercial documentation.
Highly Confidential
HR records, board papers, acquisition information, legal material or other information requiring restricted access.
The exact names are up to the organisation.
The important thing is that employees understand them.
Creating twelve different shades of confidential information may look sophisticated in a policy document, but if employees cannot distinguish between them, the system becomes counterproductive.
A good classification scheme should make the correct decision reasonably obvious.
2. Encrypt Sensitive Documents and Emails
Sensitivity labels can do more than display a classification.
They can also apply encryption and usage restrictions.
For example, a Highly Confidential document might be configured so that only specified users or groups can open it.
Depending on how protection is configured, organisations can control actions such as reading, editing, printing, copying or forwarding protected content.
Imagine an executive report is accidentally emailed outside the organisation.
Without persistent protection, the recipient may simply open it.
If appropriate label-based encryption has been applied, possession of the file does not necessarily mean permission to read it.
That is an important distinction.
Security should not always disappear the moment a document leaves its original SharePoint library.
3. Add Headers, Footers and Watermarks
Labels can also provide visible protection.
For example:
CONFIDENTIAL
could appear in the document header.
Or:
INTERNAL USE ONLY
could be displayed as a footer or watermark.
These markings do not replace technical security controls, but they provide an immediate reminder to employees.
Someone preparing to screen-share or send a document externally may notice:
HIGHLY CONFIDENTIAL
across the document and reconsider what they are about to do.
Sometimes that small behavioural prompt is valuable.
4. Protect Teams, SharePoint and Microsoft 365 Groups
Sensitivity labels are not limited to individual documents.
Microsoft also supports applying labels to containers such as Teams, SharePoint sites and Microsoft 365 Groups.
This is an important concept.
Suppose your organisation has:
General Company Team
Marketing Team
Board Team
Acquisition Project Team
They clearly should not all have identical collaboration policies.
A sensitivity label applied to a Team or SharePoint site can influence settings such as privacy and external collaboration depending on how the organisation configures the labels.
For example:
Internal
might permit normal internal collaboration.
Confidential
might restrict external sharing.
Highly Confidential
might require stricter privacy or access conditions.
This helps security follow the purpose of the workspace rather than relying on administrators remembering to configure every new Team perfectly.
Container Labels and Document Labels Aren't Exactly the Same Thing
This is an important nuance that the previous article did not explain.
A sensitivity label applied to a SharePoint site or Team protects the container and its collaboration settings.
That does not automatically mean every document inside it receives that same document-level encryption.
Microsoft distinguishes between sensitivity labels used for content and those used to protect collaboration containers.
For example:
A SharePoint site could be classified as Confidential and restricted from external sharing.
Documents inside the site could also have their own individual sensitivity labels.
Understanding this distinction prevents organisations from assuming:
“The Team is labelled Confidential, therefore every file inside it is automatically encrypted as Confidential.”
Your labelling strategy needs to consider both levels.
5. Use Sensitivity Labels With SharePoint and OneDrive
Sensitivity labelling can integrate directly with SharePoint and OneDrive.
Microsoft now supports users viewing and applying supported sensitivity labels from the details pane without necessarily needing to open the file first. The same experience can also be available through the Files area in Teams.
This makes classification much more practical.
Rather than expecting users to open every Word or Excel file before classifying it, labels become part of the information-management environment itself.
However, administrators need to configure the relevant Microsoft Purview and SharePoint/OneDrive capabilities properly. Microsoft still documents enabling sensitivity-label support for files in SharePoint and OneDrive as an important configuration step.
6. Automatically Apply Labels Where Appropriate
Manual labelling is useful.
But people forget things.
Microsoft Purview can also support automatic labelling where appropriate licensing and configuration are available.
Policies can evaluate information against defined conditions and apply or recommend sensitivity labels when sensitive content is detected.
For example, the organisation might identify documents containing specific types of financial or personal information.
Instead of hoping every employee remembers:
“This particular spreadsheet should be Confidential.”
Microsoft Purview can help automate the process.
This becomes particularly useful in larger organisations where thousands or millions of files make purely manual classification unrealistic.
However, automatic labelling should be tested carefully.
An over-aggressive policy that labels practically everything Highly Confidential can create enormous frustration.
Security controls work best when they are accurate enough that employees trust them.
7. Sensitivity Labels Matter Even More With Microsoft 365 Copilot
This is one of the biggest reasons I would update the previous article.
AI changes the importance of information governance.
Microsoft 365 Copilot can help employees find, summarise and work with information they are already authorised to access.
That makes getting permissions and information classification right before broad AI adoption extremely important.
Microsoft documents that Microsoft 365 Copilot works with existing Microsoft Purview sensitivity labels and encryption controls. Sensitivity labels can also be displayed in Copilot experiences so users retain information about the classification of referenced content.
This does not mean sensitivity labels magically solve every Copilot security problem.
You still need to review:
SharePoint permissions.
OneDrive sharing.
Teams membership.
Old data.
External access.
Overshared information.
But labels provide another important information-protection layer.
Think of it this way
Before Copilot, an employee might need to know that a sensitive document existed and manually find it.
AI can make information much easier to discover.
That is brilliant for productivity.
But it also makes poor information governance much more visible.
The correct reaction is not:
“Don't deploy AI.”
It is:
“Fix the permissions, classification and governance first.”
8. Sensitivity Labels Can Work With DLP
Sensitivity labels and Data Loss Prevention — DLP — are related, but they are not the same feature.
Sensitivity labels answer questions such as:
How sensitive is this information?
and:
What protection should stay attached to it?
DLP policies can look at information and activity and decide whether particular actions should be allowed, warned about or blocked.
Microsoft Purview supports combining information protection and DLP so organisations can build more sophisticated data-security policies.
For example, an organisation might decide:
Highly Confidential information should not normally be shared externally.
The label provides classification.
DLP can become another enforcement layer.
Microsoft also provides DLP capabilities relating specifically to Microsoft 365 Copilot and Copilot Chat scenarios.
9. Sensitivity Labels Now Extend Into Microsoft Loop
Microsoft Loop has become increasingly important for collaborative work.
Microsoft's current documentation supports using sensitivity labels with Loop so organisations can extend information protection into Loop-created information and workspaces.
This matters because business information increasingly does not live exclusively inside traditional Word documents.
Modern collaboration creates information across:
Teams.
Loop.
SharePoint.
OneDrive.
Email.
Meetings.
AI interactions.
A modern classification strategy therefore needs to follow the way people actually work.
10. Labels Should Reflect Business Risk, Not IT Terminology
One of the biggest mistakes businesses make is allowing IT to design sensitivity labels in isolation.
Sensitivity labels are not primarily an IT problem.
They are an information-governance problem implemented through technology.
Someone needs to decide:
Which data genuinely matters?
What would cause damage if disclosed?
Which information can leave the organisation?
Who should access confidential material?
Which customers have contractual confidentiality requirements?
What needs encryption?
Which departments need external collaboration?
Those decisions may require input from:
Management.
IT.
Cyber security.
HR.
Finance.
Legal or compliance.
Department heads.
Only then should the technology be configured.
Keep the Label Structure Simple
A common mistake is creating too many labels.
You might start with:
Public.
Internal.
Confidential.
Highly Confidential.
Then somebody suggests:
Internal Confidential.
Customer Confidential.
Customer Highly Confidential.
Finance Confidential.
Restricted Confidential.
Executive Highly Restricted.
Suddenly employees need a flowchart every time they save a spreadsheet.
That's not good information protection.
Microsoft's labelling system is powerful, but the design should remain understandable.
For many SMEs, a smaller number of clear labels is likely to work better than a huge classification hierarchy.
Microsoft is also rolling out a newer modern label scheme that can migrate previous parent-label structures into label groups, another reason organisations with established Purview configurations should periodically review how their label taxonomy is designed.
Don't Encrypt Everything
Another mistake is assuming:
More encryption = more security.
Technically, perhaps.
Operationally, not necessarily.
Encrypting ordinary internal documentation unnecessarily can create:
Access problems.
External collaboration problems.
Application compatibility issues.
Administrative overhead.
User frustration.
A sensible sensitivity-label project asks:
What genuinely requires persistent encryption?
rather than encrypting every document because the feature exists.
Good security should protect the organisation while allowing employees to work.
Test Before Rolling Labels Out Across the Company
Start with a pilot.
Choose representative users.
Perhaps:
Finance.
Management.
HR.
An ordinary office user.
Someone who collaborates externally.
Then test realistic scenarios.
Can employees understand the labels?
Do external recipients behave as expected?
Can mobile users open protected content?
Does encryption affect existing workflows?
How does the labelling behave in Outlook?
What happens in SharePoint?
What happens in Teams?
Does Copilot behave as expected?
Testing ten employees is significantly easier than discovering a policy mistake after deployment to 300.
Train Employees
Even an excellent technical configuration can fail if nobody understands it.
Employees should know:
What each label means.
When to apply it.
What happens when they apply it.
Whether labels can be changed.
When external sharing is permitted.
What to do when unsure.
Do not give employees a 60-page information-classification manual and expect success.
Use realistic examples.
Marketing brochure → Public
Staff procedure → Internal
Customer contract → Confidential
Board acquisition discussion → Highly Confidential
That is much easier to understand.
Are Sensitivity Labels Enough to Protect Microsoft 365?
No.
They are one layer.
A properly secured Microsoft 365 environment may also need:
Strong MFA or passkeys
Microsoft Entra Conditional Access
Microsoft Defender
Endpoint security and EDR
Appropriate SharePoint permissions
External-sharing controls
Data Loss Prevention
Retention policies
Audit logging
Privileged-access controls
Backup and recovery
Security awareness training
Sensitivity labels are excellent at helping answer:
“How should this information be handled?”
But they should sit inside a wider Microsoft 365 security strategy.
Microsoft 365 Sensitivity Labels in 2026: The Key Message
Sensitivity labels are no longer simply colourful tags saying:
Confidential
They are part of Microsoft Purview Information Protection and can provide persistent classification and protection across Microsoft 365.
They can help businesses:
Classify information.
Encrypt sensitive files and emails.
Add visual markings.
Control collaboration environments.
Support automatic classification.
Improve information governance.
Extend protection into modern services such as Loop.
And increasingly, support safer adoption of Microsoft 365 Copilot.
The technology is powerful.
But the most important work happens before anyone creates the first label.
You need to understand which information matters, who should access it and how employees genuinely need to collaborate.
Then configure Purview around the business.
Not the other way around.
Microsoft Purview and Sensitivity Labels With Hamilton Group
Hamilton Group can help businesses review and improve how sensitive information is protected across Microsoft 365.
We can help with Microsoft Purview sensitivity labels, SharePoint and OneDrive permissions, Teams security, external sharing, Microsoft 365 Copilot readiness, Microsoft Entra ID, Conditional Access, Microsoft Defender, DLP and wider Microsoft 365 security.
We can also help design a practical label structure that employees can actually understand rather than deploying a complicated classification system simply because Microsoft makes it technically possible.
The objective is to make information easier to classify, harder to expose accidentally and appropriately protected wherever the business needs to use it.
And when your employees need IT support, our aim is to make first contact on support requests within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our Microsoft 365 and cyber-security experts.