SOLVED

Apply AIP labels to existing data at scale?

%3CLINGO-SUB%20id%3D%22lingo-sub-2249255%22%20slang%3D%22en-US%22%3EApply%20AIP%20labels%20to%20exiting%20data%20at%20scale%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2249255%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20folks%2C%3C%2FP%3E%3CP%3EDoes%20MS365%20have%20the%20capability%20to%20apply%20a%20label%20to%20existing%20data%20in%20SPO%20and%20OD%20based%20on%20a%20Sensitive%20data%20scan%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20example%3C%2FP%3E%3CP%3ESensitive%20Data%3A%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BLabel%3A%3C%2FP%3E%3CP%3ESSN%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20Confidential%3C%2FP%3E%3CP%3EPCI%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BConfidential%3C%2FP%3E%3CP%3EPatents%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3BTop%20Secret%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3Eromatlo%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2257357%22%20slang%3D%22en-US%22%3ERe%3A%20Apply%20AIP%20labels%20to%20existing%20data%20at%20scale%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2257357%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F417694%22%20target%3D%22_blank%22%3E%40romatlo32%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20do%20have%20the%20ability%20to%20create%20an%20auto-labeling%20policy%20and%20target%20locations%20such%20as%20SPO%20and%20OD%20but%20right%20now%20it%20is%20limited%20in%20terms%20of%20scale%20as%20you%20can%20only%20add%2010%20sites%20to%20each%20auto-labeling%20policy%20and%20you%20are%20allowed%20to%20create%20no%20more%20than%2010%20of%20these%20policies%20per%20tenant.%20I%20hear%20that%20the%20limit%20will%20be%20increased%20in%20the%20future%2C%20but%20this%20is%20currently%20what%20it%20is.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFor%20each%20auto-labeling%20policy%20you%20can%20choose%20a%20label%20(ex%3A%20Confidential)%20to%20auto%20apply%20based%20on%20rules%20(conditions)%20that%20are%20met.%20So%20in%20your%20case%20you%20can%20create%20a%20rule%20with%20a%20condition%20equal%20to%20'Content%20that%20contains%20any%20of%20these%20sensitive%20info%20types%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3CSTRONG%3ESSN%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%3CSTRONG%3E%26nbsp%3BPCI%3C%2FSTRONG%3E%20(You%20may%20have%20to%20individually%20select%20the%20sensitive%20information%20types%20that%20are%20predefined%20(over%20200%20to%20choose%20from)%20or%20create%20your%20own%20if%20necessary)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESelect%20SPO%20and%20OD%20locations%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou'd%20then%20have%20to%20create%20another%20auto-labeling%20policy%20--%26gt%3B%20Choose%20a%20label(ex%3A%20Top%20Secret)%20to%20auto%20apply%20--%26gt%3B%20create%20a%20rule%20with%20a%20condition%20equal%20to%20'Content%20that%20contains%20any%20of%20these%20sensitive%20info%20type(s)'%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EPatent%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESelect%20SPO%20and%20OD%20locations%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20will%20apply%20to%20content%20that%20is%20already%20saved%20(and%20future%20content)%20in%20SPO%20and%20OD%20if%20it%20matches%20the%20conditions%20of%20the%20rules%20you%20define.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20included%20a%20link%20below%20to%20Microsoft%20documentation%20that%20discusses%20this%20in%20greater%20detail.%20Hope%20this%20Helps!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-%20Julian%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fapply-sensitivity-label-automatically%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fapply-sensitivity-label-automatically%3Fview%3Do365-worldwide%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2260130%22%20slang%3D%22en-US%22%3ERe%3A%20Apply%20AIP%20labels%20to%20existing%20data%20at%20scale%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2260130%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1018611%22%20target%3D%22_blank%22%3E%40Julian_Nwosu%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%26nbsp%3B%20Sounds%20like%20you%20are%20confirming%20for%20auto%20labeling%20for%20new%20documents%2C%20correct%3F%3C%2FP%3E%3CP%3EI%20am%20also%20referring%20to%20existing%20data%20(before%20a%20labeling%20policy)%20that%20has%20no%20label%20at%20all.%26nbsp%3B%20Could%20we%20also%20label%20that%20existing%20data%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi folks,

Does MS365 have the capability to apply a label to existing data in SPO and OD based on a Sensitive data scan?

 

For example

Sensitive Data:     Label:

SSN                      Confidential

PCI                       Confidential

Patents                 Top Secret

 

Thanks,

romatlo

3 Replies

Hi @romatlo32,

 

You do have the ability to create an auto-labeling policy and target locations such as SPO and OD but right now it is limited in terms of scale as you can only add 10 sites to each auto-labeling policy and you are allowed to create no more than 10 of these policies per tenant. I hear that the limit will be increased in the future, but this is currently what it is.

 

For each auto-labeling policy you can choose a label (ex: Confidential) to auto apply based on rules (conditions) that are met. So in your case you can create a rule with a condition equal to 'Content that contains any of these sensitive info types"

 SSN

 PCI (You may have to individually select the sensitive information types that are predefined (over 200 to choose from) or create your own if necessary)

 

Select SPO and OD locations

 

You'd then have to create another auto-labeling policy --> Choose a label(ex: Top Secret) to auto apply --> create a rule with a condition equal to 'Content that contains any of these sensitive info type(s)':

 

Patent

 

Select SPO and OD locations

 

This will apply to content that is already saved (and future content) in SPO and OD if it matches the conditions of the rules you define.

 

I've included a link below to Microsoft documentation that discusses this in greater detail. Hope this Helps!

 

- Julian

 

 

https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-label-automatically?view...

 

@Julian_Nwosu 

 

Thank you!  Sounds like you are confirming for auto labeling for new documents, correct?

I am also referring to existing data (before a labeling policy) that has no label at all.  Could we also label that existing data?

best response confirmed by romatlo32 (New Contributor)
Solution

@romatlo32 Correct. You can also label existing data at rest in SharePoint and OneDrive

 

Specific to auto-labeling for SharePoint and OneDrive:

  • Office files for Word, PowerPoint, and Excel are supported. Open XML format is supported (such as .docx and .xlsx) but not Microsoft Office 97-2003 format (such as .doc and .xls).
    • These files can be auto-labeled at rest before or after the auto-labeling policies are created. Note that files cannot be auto-labeled if they are part of an open session (the file is open).

https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-label-automatically?view...

 

- Julian