Forum Discussion

princzsaharan's avatar
princzsaharan
Copper Contributor
Oct 02, 2026

Two labels does not appear in outlook

We are at the very beginning of deploying the four sensitivity labels: Public, Internal, Restricted, and Confidential.

The labels are visible in Word, Excel, PowerPoint, and other Microsoft 365 apps, but they do not appear in Outlook Desktop or Outlook on the Web (OWA) for me or the pilot users. Restricted and Confidential are configured with encryption and settings for both of them are same , i know strange but that's what mgmt want refer to the attached screenshot.

 

4 Replies

  • NoahHelp's avatar
    NoahHelp
    Brass Contributor

    Since IRM passes, I would compare the label definitions and publishing policy rather than the encryption configuration. Outlook only offers labels whose scope includes email and that are published to the signed-in user.

    In Microsoft Purview, open each missing label and verify that its scope includes Emails, not only Files and other data assets. Then open the publishing policy and confirm the pilot users are included directly or through the expected group. Check that the labels are not disabled, hidden under an unexpected parent label, or assigned only through a policy with a different priority.

    After saving, allow policy replication time, then sign out of Outlook on the web and test a new message in a private window. Compare that with a label that already appears. If the missing labels still do not load, export the label and policy details with Security & Compliance PowerShell and open a Purview support request with the label GUIDs, policy GUID, affected UPN, and UTC test time. That will distinguish label publication from a working IRM backend.

  • Have you checked your tenant settings and validated that Azure Rights Management and Office Message Encryption (OME) are correctly configured in Exchange Online?

    Get-IRMConfiguration | fl *. and check that  AzureRMSLicensingEnabled and InternalLicensingEnabled are TRUE.

    You can also test the IRM for a user 

    Test-IRMConfiguration -Sender user@domain.com

    Get-IRMConfiguration | fl *.

    and verify that  AzureRMSLicensingEnabled and InternalLicensingEnabled are TRUE.

     

    You can also validate IRM functionality for a user with

    Test-IRMConfiguration 

     

    See Set up Microsoft Purview Message Encryption | Microsoft Learn for more info

    • princzsaharan's avatar
      princzsaharan
      Copper Contributor

      Yes, I checked the tenant settings. Both AzureRMSLicensingEnabled and InternalLicensingEnabled are set to True in Get-IRMConfiguration. I also ran Test-IRMConfiguration for a test user, and it came back with an overall result of PASS. RMS templates were acquired, encryption and decryption were verified successfully, and IRM is confirmed enabled

      • Creativejodielawrance's avatar
        Creativejodielawrance
        Copper Contributor

        Great catch ruling out the tenant IRM layer with Nikki's check. Since ⁠Test-IRMConfiguration⁠ came back clean, the next most likely culprit is policy scope. Have you double-checked that the Exchange workload is explicitly enabled in the label publishing policy itself, and how long ago were these labels created?

        I would try making a test label without encryption just for outlook and see if it appears.