Blog Post

Microsoft Security Community Blog
1 MIN READ

Using Sensitivity labels with Microsoft Teams, O365 Groups and SharePoint Online sites

AdamBell's avatar
AdamBell
Icon for Microsoft rankMicrosoft
Mar 11, 2020

With the ability to label a SharePoint Online site, Teams site or O365 Group we're introduced to the first capabilities of applying sensitivity labels to "containers". Check out the webinar to understand how this works and how to use this in your organization.

 

This webinar was presented on Thu Mar 5th 2020, and the recording can be found here.

 

Attached to this post are:

  1. The FAQ document that summarizes the questions and answers that came up over the course of both Webinars; and
  2. A PDF copy of the presentation.

Thanks to those of you who participated during the two sessions and if you haven’t already, don’t forget to check out our resources available on the Tech Community.

 

Thanks!

@Adam Bell  on behalf of the MIP and Compliance CXE team

Updated May 11, 2021
Version 4.0

19 Comments

  • lightupdifire's avatar
    lightupdifire
    Brass Contributor

    Hello,

    About Site and Group Settings, if plan to use it to allow or limit access from unmanaged devices, would be good to:

    1. Allow to disable "Incompatible sensitivity label detected" messages;

    2. Remove the "None" option, so only existing Sensitivity label can be applied or allow to set Default sensitivity label in SharePoint Online Template for new sites, so users cannot create a site without Sensitivity label;

    3. Work with OneDrive team & integration, right now, to enable Sensitivity label per site, the general SharePoint Admin Access Control policy must be changed to "Allow full download"; If in the past, company strategy was to Limit access from unmanaged devices, this new solution force to disable this setting and set it back to "Allow full download", nothing documented about it + if we disable this setting and set back "Allow full download", this disable existing Conditional Access policies created before by this setting;

    4. Explain configuration in more details, have a feeling that Conditional Access policy explanation missing in all documents about SharePoint sites with Sensitivity labeling;

    5. SharePoint Sensitivity labeling solution must follow the logic of the data classification if the organization deployed as example 10+ Sensitivity labels and build internal Data Classification documentation in the past, and now we try to integrate something regarding SharePoint site labeling... makes it a little bit confusing for end-users.

  • Andre_Silva's avatar
    Andre_Silva
    Copper Contributor

    Maybe I don't understand exactly the goal of this feature, but I would like to understand what is the goal to take available sensitivity labels in sharepoint sites, but if I put/create a file in a library this file isn't automatically classified with label of site? 

     

    Thank you!

  • Gurdev Singh's avatar
    Gurdev Singh
    Iron Contributor

    AdamBellDoes SharePoint crawl the sensitivity label property applied to documents? Older AIP classic labels were being crawled and were available under crawled properties. However, the newer sensitivity labels aren't showing in crawled properties for us.

  • Anonymous's avatar
    Anonymous

    Hi there is an error in the survey linked from the presentations  it is asking for the email address to be a number.

  • Is there a plan to consider teams meetings as a container and apply a sensitivity label to meetings initiated?

    My customer would like to clearly indicate that a meeting is unclassified and be sure end-users are aware before they share content.

    It would also be good to prevent sharing of content that is labeled higher than that of the meeting.  

    Also, is there a way to make the sensitivity label stronger visually present like we do with Banner/waterwark in documents ....today label is somewhat hidden in small print in a corner.

  • Wes MacDonald's avatar
    Wes MacDonald
    Copper Contributor

    While the FAQ says this is Office E3 feature, I have found that not to be true.  There must be at least one (1) Azure AD Premium P1 license in your Azure AD organization (https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/groups-assign-sensitivity-labels). 

     

    Wes