Setting a default sensitivity label on a SharePoint Site or Document Library

%3CLINGO-SUB%20id%3D%22lingo-sub-755786%22%20slang%3D%22en-US%22%3ESetting%20a%20default%20sensitivity%20label%20on%20a%20SharePoint%20Site%20or%20Document%20Library%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-755786%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20trying%20to%20use%20MCAS%20to%20solve%20for%20a%20customer's%20requirement%20with%20default%20sensitivity%20labels%20in%20Office%20365%20(primarily%20in%20SharePoint%20and%20OneDrive).%26nbsp%3BI%20pulled%20the%20following%20diagram%20together%20to%20highlight%20the%20specific%20requirements%3A%3C%2FP%3E%3COL%3E%3CLI%3EWe%20need%20the%20ability%20to%20apply%20a%20general%20default%20label%20of%20%E2%80%98Internal%20Use%E2%80%99%20to%20the%20customer's%20SharePoint%20and%20OneDrive%20environment.%3C%2FLI%3E%3CLI%3EWe%20need%20the%20ability%20to%20apply%20a%20different%20default%20label%20to%20certain%20sites.%20In%20the%20case%20of%20HR%2C%20the%20default%20label%20would%20be%20%E2%80%98Confidential%E2%80%99.%3C%2FLI%3E%3CLI%3EWe%20need%20the%20ability%20to%20apply%20a%20different%20default%20label%20to%20certain%20document%20libraries.%20In%20the%20case%20of%20HR%2C%20the%20default%20label%20for%20one%20of%20the%20document%20libraries%20would%20be%20%E2%80%98Restricted%E2%80%99%3C%2FLI%3E%3CLI%3E%3CDIV%3EWe%20need%20the%20ability%20to%20auto-apply%20these%20labels%20to%20the%20documents%20at%20rest.%26nbsp%3B%20We%20have%20400K%2B%20documents%20and%20coming%20up%20with%20a%20solution%20that%20requires%20the%20document%20to%20be%20opened%20and%20saved%20to%20apply%20the%20label%20will%20not%20work.%3C%2FDIV%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F123326i6F36AFFDB23462D9%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222019-07-15_15-51-25.png%22%20title%3D%222019-07-15_15-51-25.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20something%20that%20MCAS%20can%20support%3F%20Thus%20far%20we%20see%20the%20ability%20to%20apply%20default%20labels%20at%20the%20folder%20level%20-%20but%20nothing%20higher%20in%20terms%20of%20Document%20Libraries%20or%20Sites.%20The%20customer%20has%20hundreds%20of%20folders%2C%20so%20configuring%20and%20managing%20things%20at%20the%20folder%20level%20doesn't%20seem%20sustainable.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20guidance%20you%20can%20provide%20is%20appreciated!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-755786%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-772669%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20a%20default%20sensitivity%20label%20on%20a%20SharePoint%20Site%20or%20Document%20Library%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-772669%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226697%22%20target%3D%22_blank%22%3E%40Seth%20Weddon%3C%2FA%3E%2C%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20order%20to%20retrieve%20Labels%20from%20Office%20365%20into%20MCAS%2C%20you%20need%20to%20configure%20Unified%20Labeling%20in%20Azure%20Information%20Protection.%20Once%20enabled%2C%20you%20would%20be%20able%20to%20satisfy%20use%20cases%201%20and%204.%20For%20use%20case%204%2C%20I%20recommend%20to%20first%20setup%20a%20file%20policy%20in%20monitoring%20mode%20to%20understand%20how%20many%20SharePoint%20and%20OneDrive%20files%20will%20need%20the%20Internal%20Use%20Label%20before%20setting%20the%20governance%20action.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EFor%20use%20cases%202%20and%203%20you%20can%20use%20the%20native%20Office365%20DLP%20where%20you%20are%20able%20to%20create%20and%20publish%20Office365%20sensitivity%20labels%20to%20SharePoint%20sites%20%2F%20document%20libraries.%20By%20creating%20a%20label%20in%20the%20console%20you%20can%20then%20automatically%20apply%20a%20label%20by%20again%20enabling%20Unified%20Labeling%20with%20AIP.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F124391i4DA390E6ED3C1D86%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22SCC.PNG%22%20title%3D%22SCC.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-868257%22%20slang%3D%22en-US%22%3ERe%3A%20Setting%20a%20default%20sensitivity%20label%20on%20a%20SharePoint%20Site%20or%20Document%20Library%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-868257%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F222323%22%20target%3D%22_blank%22%3E%40Anisha%20Gupta%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20not%20getting%20it.%20My%20understanding%20is%20that%20the%20Sensitivity%20labels%20and%20Sensitivity%20Label%20policies%20allows%20you%20to%20define%20a%20default%20label%20based%20on%20the%20users%20to%20which%20you%20apply%20the%20policy.%20Not%20based%20on%20the%20location%20of%20the%20files.%20So%20I%20don't%20understand%20how%20this%20would%20work%20for%20case%20%232%20and%20case%20%233.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20believe%20that%20you%20could%20use%20MCAS%20to%20apply%20the%20specific%20labels%20to%20all%20files%20and%20folders%20that%20are%20in%20a%20a%20selected%20library%20using%20the%20governance%20options.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECharles%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

We're trying to use MCAS to solve for a customer's requirement with default sensitivity labels in Office 365 (primarily in SharePoint and OneDrive). I pulled the following diagram together to highlight the specific requirements:

  1. We need the ability to apply a general default label of ‘Internal Use’ to the customer's SharePoint and OneDrive environment.
  2. We need the ability to apply a different default label to certain sites. In the case of HR, the default label would be ‘Confidential’.
  3. We need the ability to apply a different default label to certain document libraries. In the case of HR, the default label for one of the document libraries would be ‘Restricted’
  4. We need the ability to auto-apply these labels to the documents at rest.  We have 400K+ documents and coming up with a solution that requires the document to be opened and saved to apply the label will not work.

2019-07-15_15-51-25.png

 

Is this something that MCAS can support? Thus far we see the ability to apply default labels at the folder level - but nothing higher in terms of Document Libraries or Sites. The customer has hundreds of folders, so configuring and managing things at the folder level doesn't seem sustainable.

 

Any guidance you can provide is appreciated!

2 Replies
Highlighted

Hi @Seth Weddon

In order to retrieve Labels from Office 365 into MCAS, you need to configure Unified Labeling in Azure Information Protection. Once enabled, you would be able to satisfy use cases 1 and 4. For use case 4, I recommend to first setup a file policy in monitoring mode to understand how many SharePoint and OneDrive files will need the Internal Use Label before setting the governance action. 

For use cases 2 and 3 you can use the native Office365 DLP where you are able to create and publish Office365 sensitivity labels to SharePoint sites / document libraries. By creating a label in the console you can then automatically apply a label by again enabling Unified Labeling with AIP.

 

SCC.PNG

 

Highlighted

Hi @Anisha Gupta 

 

I'm not getting it. My understanding is that the Sensitivity labels and Sensitivity Label policies allows you to define a default label based on the users to which you apply the policy. Not based on the location of the files. So I don't understand how this would work for case #2 and case #3.

 

I believe that you could use MCAS to apply the specific labels to all files and folders that are in a a selected library using the governance options.

 

Charles