Forum Widgets
Latest Discussions
Issues with AutoSave and Sensitivity Labels – Need Advice on Best Practices
Hello everyone, I'm currently facing an issue with implementing Sensitivity Labels in Microsoft 365, and I was hoping to get some insights from others who might have encountered similar challenges. The Setup: We’ve implemented Sensitivity Labels with encryption in our organization to ensure external users are always authenticated when accessing our files. Our files are primarily stored on our on-premises servers. We’ve configured the labels to restrict access to authenticated users, with different permissions based on user roles (e.g., Co-Owners for internal users and restricted permissions for external users). The Problem: While the labeling process is working as expected, one significant issue we've run into is that AutoSave no longer functions correctly after applying the labels, particularly for documents that are encrypted when using the client app. The documents are not saving automatically, which can lead to information loss and angry employees. 🥺 I can live with the limitation that the label can only be applied in the client application (i.e., not through the web interface). However, the AutoSave problem is a significant hurdle. Questions for the Community: Has anyone else encountered issues with AutoSave after applying Sensitivity Labels with encryption? How did you work around this? Are there any best practices or configuration adjustments I should consider to resolve this issue? How have other organizations handled the authentication requirement for external users while still ensuring a smooth workflow? Looking forward to hearing your thoughts and experiences! Thanks in advance!SolvedSophie_BruehlOct 23, 2025Iron Contributor984Views0likes3CommentsSafeguard data on third-party collaboration platforms
I am exploring options to safeguard sensitive data in third-party collaboration platforms like GitHub and Confluence. Does Microsoft Purview provide any native integration for these platforms? Do I need to rely on third-party connectors/integrations to extend Purview’s capabilities into these environments?SaqibSyedOct 08, 2025Copper Contributor100Views0likes2CommentsSecuring Data with Microsoft Purview IRM + Defender: A Hands-On Lab
Hi everyone I recently explored how Microsoft Purview Insider Risk Management (IRM) integrates with Microsoft Defender to secure sensitive data. This lab demonstrates how these tools work together to identify, investigate, and mitigate insider risks. What I covered in this lab: Set up Insider Risk Management policies in Microsoft Purview Connected Microsoft Defender to monitor risky activities Walkthrough of alerts triggered → triaged → escalated into cases Key governance and compliance insights Key learnings from the lab: Purview IRM policies detect both accidental risks (like data spillage) and malicious ones (IP theft, fraud, insider trading) IRM principles include transparency (balancing privacy vs. protection), configurable policies, integrations across Microsoft 365 apps, and actionable alerts IRM workflow follows: Define policies → Trigger alerts → Triage by severity → Investigate cases (dashboards, Content Explorer, Activity Explorer) → Take action (training, legal escalation, or SIEM integration) Defender + Purview together provide unified coverage: Defender detects and responds to threats, while Purview governs compliance and insider risk This was part of my ongoing series of security labs. Curious to hear from others — how are you approaching Insider Risk Management in your organizations or labs?Perparim_Abdullahu-PerparimLabsOct 06, 2025Copper Contributor202Views0likes4CommentsAADSTS50020: protected PDF issue for external users
I have been recently (don't know when it was started) observed getting error from protected PDF (sensitivity label with user defined permission) file while trying to open that pdf via AIP viewer mobile app (Android/iOS) AS external user (who has permission to open/view). No issue with Office file types protected. external (not internal, not guest) user (currently testing with gmail.com account, other O365 tenant user) getting error as attached from AIP view mobile app. We do have AIP excluded at conditional access policy which helped so far to avoid this problem for external users. Is there been any recent change in behavior around user defined protected PDF? Since user having problem is external, have no clue where to look for log and start investigation. Error code: AADSTS50020mevaibhav831345Oct 04, 2025Copper Contributor215Views0likes3CommentsAlert on DLP Policy Change
Is it possible to configure an alert from Purview when a DLP policy is created, amended or removed? I am trying to build a process to satisfy NIST CM-6(2): Respond to Unauthorized Changes that identifies when a policy chnage happens and to cross reference to an authorised change record. I can find the events Updated, Created or Changed a DLP Poloicy in audit search but can Purview be configured to generate an alert when these events happen?GrahamP67Aug 01, 2025Copper Contributor79Views0likes1CommentDLP Alerts Naming Metadata
Im currently facing an issue that every time my DLP policy matches, it creates an Alert on Defender where the name of the file appears on it, for example: DLP policy match for document 'file.pdf' on a device DLP policy matched for email with subject (SUBJECT) I do not want that file.pdf nor SUBJECT appear on the title on Defender, where i can configure to avoid this ?HleoJul 31, 2025Copper Contributor63Views0likes1CommentSuppress Alerting to Endpoint DLP Printing on "Print to PDF".
Is there a way to configure an Endpoint DLP policy for Printing to NOT alert on "Print to File" events primarily Print to PDf's. For example print events where the target name are "Microsoft Print to PDF" or "Adobe PDF"? I understand you can create Printer groups, but there is no way to use as a condition when creating DLP rule.Dalesh07Jul 17, 2025Copper Contributor335Views0likes5CommentsCan DLP Purview scan inbound emails for Sensitive data?
I have a unique use case where we are trying to understand if DLP Purview can scan inbound email external email for sensitive information. If so, is there a specific white page that gives instructions on what settings need to be enabled to scan inbound. I tried using conditions in the existing DLP policies but the external emails were not flagged.SolvedJamie34Jun 19, 2025Copper Contributor234Views0likes2CommentsDLP Policy Rule "U.S. Physical Address" exclusion
We have the built in Sensitive Info Type "U.S. Physical Address" in our Default HR & Privacy Info Protection Policy in simulation. This is set to the location of just Exchange Email only. Everyone in the company has our physical address in their email signature. This combination keeps triggering alerts even if I set the instance count to something like 3. I've asked Co-Pilot for instructions to create an exclusion where I can enter our physical address to be ignored but the instructions always mention options that don't exist in the rule edit screen. I see online people asking for signatures to be ignored but the response is they can't be. Am I doomed to ask all staff to remove their signature, remove this SIT altogether, or just let the Action of "encrypt email messages" proceed and have our organization look the fool for encrypting every email sent outside the organization? Anyone know how to tell Purview to ignore your own physical address?ENMRSHJun 19, 2025Copper Contributor344Views0likes8CommentsMS Purview InformationProtectionPolicy - Extract Sensitivity Labels - Permissions Granted
Hello community, I'm currently facing an issue trying to extract sensitivity labels from our Microsoft 365 tenant and could use some assistance. I have already ensured that the necessary permissions and application are in place. I initially attempted to retrieve the labels via the Microsoft Graph Explorer (graph-explorer) using the endpoint: https://graph.microsoft.com/beta/security/informationProtection/sensitivityLabels. As you can see in the attached image, I encountered a "Forbidden - 403" error, suggesting a problem with permissions or consent, even though InformationProtectionPolicy.Read is listed under the "Modify permissions" tab as "Unconsent". The only way that I found to solve it was using "https://graph.microsoft.com/beta/me/security/informationProtection/sensitivityLabels" but I need to use it in Python Code, without a user validation of credential. Next, I tried to achieve the same using Python and the Microsoft Graph API directly. I obtained an access token using a Client ID and Secret, authenticating against https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token. The application associated with this Client ID and Secret has been granted the InformationProtectionPolicy.Read permission. However, when making a GET request to https://graph.microsoft.com/beta/security/informationProtection/sensitivityLabels in Python, I receive the following error: I have already granted what I believe are the relevant permissions, including InformationProtectionPolicy.Read.All, InformationProtectionPolicy.Read, Application.Read.All, and User.Read. Has anyone successfully retrieved sensitivity labels using the Microsoft Graph API? If so, could you please share any insights or potential solutions? I'm wondering if there are other specific permissions required or if there's a particular nuance I might be missing. Any help would be greatly appreciated! Thank you in advance. Leonardo CanalLeonardoCanalJun 04, 2025Copper Contributor168Views0likes2Comments
Resources
Tags
- sensitivit label4 Topics
- sensitivity label2 Topics
- dlp2 Topics
- purview2 Topics
- PowerApps Connector1 Topic
- Defender XDR1 Topic
- dlp block1 Topic
- Information Protection1 Topic
- protection policy1 Topic
- encryption1 Topic