Forum Discussion

manojviduranga's avatar
Jul 11, 2022

Microsoft Purview Sensitivity labels: restricting users from selecting lower level of sensitivity

Howdy Folks!

 

Do we have an option to restrict users from selecting a label that is lower than previously used (on a reply/forward email scenario) ? I'm aware of the "users must provide justification to remove/downgrade a classification" option but, is there a way we could completely restrict downgrading? Has anyone worked around this ?
 

 

This is a crucial option on our approach of aligning to Australian government standards. 
 
any thoughts are greatly appreciated!
Thank you!

4 Replies

  • JakubUrban's avatar
    JakubUrban
    Copper Contributor

    If you will do some test with 2 different users, you will find out that to be able to change classification, you need to have permissions to do it. It means no one, who do not have specific permissions to do it, cannot lower or anyhow change classification level.

    Since the person who label the document initialy becomes the owner of the file, this person can do anything with the document, even changing the classification. Because the OWNER role has all permissions.

    But once you are other person who has only rights up to the Co-Owner, you cannot change a label. It means when you are NOT OWNER of the document, you MUST HAVE Co-Owner permissions to be able to CHANGE CLASSIFICATION.

    Any other role (Co-Author, Reviewer, Viewer) DO NOT HAVE permissions to change a label, since they do not have EDITRIGHTSDATA atomic permission.

    Check it here: https://learn.microsoft.com/en-us/azure/information-protection/configure-usage-rights

     

    pkaup , augrasp , rhycsm , manojviduranga 

  • augrasp's avatar
    augrasp
    Copper Contributor

    Hello manojviduranga ,

    I noticed the following things on my test tenant:

    • document owner will always have the right to change label
    • you can have a custom set of rights applied to the document through the original document label that removes the "edit rights (EDITRIGHTSDATA)". But that will also prevent users from upgrading the label

    I haven't found a real good solution to this problem. If anyone has, let us know :).

     

    P.

  • rhycsm's avatar
    rhycsm
    Copper Contributor
    Hi Manoj - Have you got the solution for this? Just deployed the Purview, its seems the option to restrict the users is yet to be added?

    Cheers,
    Rhey

Resources