Sensitivity Labels - External Sharing in SharePoint

%3CLINGO-SUB%20id%3D%22lingo-sub-1399530%22%20slang%3D%22en-US%22%3ESensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1399530%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20created%20a%20Sensitivity%20Label%20that%20prevents%20External%20Sharing.%20I%20have%20applied%20this%20Sensitivity%20Label%20to%20a%20new%20Team%20that%20I%20have%20created%20and%20it%20has%20successfully%20applied%20to%20the%20Group%20and%20the%20SharePoint%20Site%20associated%20with%20the%20Team.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20does%20what%20is%20expected%20and%20prevents%20guests%20from%20being%20invited%20to%20the%20Team%2FGroup%2FSite%20but%20it%20does%20not%20prevent%20files%2Ffolders%20within%20the%20Site%20being%20shared%20with%20External%20parties.%20External%20Sharing%20on%20the%20SharePoint%20Site%20is%20enabled%20by%20default%20for%20new%2Fexisting%20guests%20but%20I%20would%20have%20expected%20the%20Sensitivity%20Label%20to%20change%2Foverrule%20this%20and%20prevent%20files%2Ffolders%20from%20being%20shared%20as%20well%20as%20preventing%20guests%20from%20being%20invited.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20expected%20behaviour%20and%20if%20so%20is%20this%20a%20feature%20expected%20to%20be%20released%20once%20it%20goes%20into%20GA%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1402670%22%20slang%3D%22en-US%22%3ERe%3A%20Sensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1402670%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F671464%22%20target%3D%22_blank%22%3E%40CraigWatson%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20now%2C%20this%20is%20expected%20behaviour.%26nbsp%3B%20The%20label%20settings%20don't%20apply%20to%20any%20content%20%3CEM%3Ein%26nbsp%3B%3C%2FEM%3Ethe%20container%2C%20only%26nbsp%3B%3CEM%3Ethe%20container%3C%2FEM%3E.%26nbsp%3B%20In%20the%20example%20of%20external%20sharing%2C%20you%20are%20prohibiting%20adding%20guests%20to%20the%20group%20or%20site%2C%20but%20not%20its%20files.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELast%20I%20checked%2C%20there%20is%20currently%20a%20private%20preview%20of%20applying%20sensitivity%20labels%20automatically%20to%20files%20in%20SPO.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1402804%22%20slang%3D%22en-US%22%3ERe%3A%20Sensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1402804%22%20slang%3D%22en-US%22%3E%3CP%3EThank%26nbsp%3Byou%20for%20the%20response%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F74084%22%20target%3D%22_blank%22%3E%40Ruairidh%20Campbell%3C%2FA%3E%2C%20much%20appreciated%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20hoping%20this%20function%20in%20private%20preview%20prevents%20the%20file%2Ffolder%20that%20has%20the%20sensitivity%20label%20applied%20prevents%20it%20from%20being%20shared%2C%20regardless%20of%20the%20External%20Sharing%20setting%20on%20Sharepoint%2C%20as%20currently%20you%20CAN%20apply%20a%20sensitivity%20label%20to%20a%20file%2C%20but%20it%20does%20not%20prevent%20it%20from%20being%20shared%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20would%20negate%20the%20need%20for%20a%20powershell%20script%20that%20identifies%20all%20Sharepoint%20Sites%20with%20an%20%22Internal%22%20sensitivity%20label%20and%20setting%20the%20SPOSharingCapability%20to%20%22Disabled%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELets%20see%20what%20the%20future%20brings%20-%20Thanks%20again!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1408414%22%20slang%3D%22en-US%22%3ERe%3A%20Sensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1408414%22%20slang%3D%22en-US%22%3EHey%2C%20no%20problem.%20There%20are%20better%20DLP%20experts%20than%20me%20who%20might%20have%20other%20ideas%20to%20help%20in%20the%20meantime%2C%20but%20you%20could%20try%20enabling%20'sensitive%20by%20default'%20although%20it's%20tenant%20wide.%20For%20any%20file%20uploaded%20it%20won't%20let%20it%20be%20shared%20until%20DLP%20processes.%20Then%20it's%20just%20a%20case%20of%20making%20sure%20you%20have%20DLP%20in%20place%20to%20stop%20sharing%20on%20sites%20you%20don't%20want%20when%20it%20does%20process.%20Not%20sure%20how%20this%20works%20for%20folders%20though.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1413683%22%20slang%3D%22en-US%22%3ERe%3A%20Sensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1413683%22%20slang%3D%22en-US%22%3EFYI%3A%20you%20can%20tag%20documents%20with%20labels%20automatically%20utilizing%20MCAS.%20Really%20nice%20to%20do%20it%20this%20way%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Fuse-case-information-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcloud-app-security%2Fuse-case-information-protection%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1417462%22%20slang%3D%22en-US%22%3ERe%3A%20Sensitivity%20Labels%20-%20External%20Sharing%20in%20SharePoint%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1417462%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20for%20the%20responses%20guys%2C%20I%20am%20investigating%20the%20Auto-Labeling%20functions%20and%20they%20seem..%20detailed!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20dont%20know%20if%20I%20need%20to%20set%20up%20a%20separate%20post%20for%20this%20but%20I%20need%20some%20assistance%20with%20a%20Sharepoint%20Online%20Powershell%20Script%2C%20essentially%20I%20want%20it%20to%20run%20across%20all%20SPO%20Sites%20in%20our%20environment%20on%20a%20schedule%20and%20do%20the%20below%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-SPO%20Site%20where%20%22SensitivityLabel%22%20-eq%20blank%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor-each%20SPOSite%20%7C%20Set-SPOSite%20-SensitivityLabel%20%22GUID%20of%20Internal%20Sensitivity%20Label%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet-SPOSite%20where%20Sensitivity%20Label%20-eq%20%22GUID%20of%20Internal%20Sensitivity%20Label%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20each%20SPO%20Site%20%7C%20Set-SPOSite%20-SharingCapability%20Disabled%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20struggling%20to%20find%20a%20way%20in%20the%20script%20of%20identifying%20all%20SPO%20sites%20with%20no%20Sensitivity%20Label%20applied%20to%20the%20put%20into%20a%20variable%20and%20then%20apply%20a%20sensitivity%20label.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20anyone%20help%20with%20a%20script%20to%20execute%20the%20logic%20above%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECraig%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I have created a Sensitivity Label that prevents External Sharing. I have applied this Sensitivity Label to a new Team that I have created and it has successfully applied to the Group and the SharePoint Site associated with the Team. 

 

It does what is expected and prevents guests from being invited to the Team/Group/Site but it does not prevent files/folders within the Site being shared with External parties. External Sharing on the SharePoint Site is enabled by default for new/existing guests but I would have expected the Sensitivity Label to change/overrule this and prevent files/folders from being shared as well as preventing guests from being invited.

 

Is this expected behaviour and if so is this a feature expected to be released once it goes into GA?

5 Replies
Highlighted

Hey @CraigWatson,

 

For now, this is expected behaviour.  The label settings don't apply to any content in the container, only the container.  In the example of external sharing, you are prohibiting adding guests to the group or site, but not its files.

 

Last I checked, there is currently a private preview of applying sensitivity labels automatically to files in SPO.

Highlighted

Thank you for the response @Ruairidh Campbell, much appreciated :)

 

I am hoping this function in private preview prevents the file/folder that has the sensitivity label applied prevents it from being shared, regardless of the External Sharing setting on Sharepoint, as currently you CAN apply a sensitivity label to a file, but it does not prevent it from being shared

 

This would negate the need for a powershell script that identifies all Sharepoint Sites with an "Internal" sensitivity label and setting the SPOSharingCapability to "Disabled"

 

Lets see what the future brings - Thanks again!

Highlighted
Hey, no problem. There are better DLP experts than me who might have other ideas to help in the meantime, but you could try enabling 'sensitive by default' although it's tenant wide. For any file uploaded it won't let it be shared until DLP processes. Then it's just a case of making sure you have DLP in place to stop sharing on sites you don't want when it does process. Not sure how this works for folders though.
Highlighted
FYI: you can tag documents with labels automatically utilizing MCAS. Really nice to do it this way: https://docs.microsoft.com/en-us/cloud-app-security/use-case-information-protection
Highlighted

Thank you for the responses guys, I am investigating the Auto-Labeling functions and they seem.. detailed!

 

I dont know if I need to set up a separate post for this but I need some assistance with a Sharepoint Online Powershell Script, essentially I want it to run across all SPO Sites in our environment on a schedule and do the below

 

Get-SPO Site where "SensitivityLabel" -eq blank

 

For-each SPOSite | Set-SPOSite -SensitivityLabel "GUID of Internal Sensitivity Label"

 

Get-SPOSite where Sensitivity Label -eq "GUID of Internal Sensitivity Label"

 

For each SPO Site | Set-SPOSite -SharingCapability Disabled

 

I am struggling to find a way in the script of identifying all SPO sites with no Sensitivity Label applied to the put into a variable and then apply a sensitivity label.

 

Can anyone help with a script to execute the logic above?

 

Craig