Home > Glossary > Microsoft 365 Administrator > Sensitivity Labels

📖 What is Sensitivity Labels?

Sensitivity Labels are Microsoft Purview tools used to classify and protect sensitive data within Microsoft 365. They allow administrators to apply visual markings, encryption, and access restrictions to documents and emails, ensuring that sensitive information remains protected regardless of where the file is stored or shared.

🥋 Sensei Says:

"Remember that labels can be applied manually by users or automatically based on predefined sensitive information types or trainable classifiers."

📚 Certification: Microsoft 365 Administrator (MS-102)

🔑 What are the Key Concepts of Sensitivity Labels?

  • Encryption and Access Control: Labels can encrypt content and restrict access to specific users or groups, ensuring data remains protected even when shared externally.
  • Visual Markings: Administrators can configure headers, footers, and watermarks to provide immediate visual cues to users regarding the document's classification and sensitivity level.
  • Auto-labeling Policies: Labels can be applied automatically using Sensitive Information Types (SITs) or trainable classifiers to detect patterns like credit card numbers or medical records.
  • Label Policies: These policies determine which sensitivity labels are published to specific users or groups, controlling who has the ability to apply certain classifications.
  • Container Labeling: Beyond individual files, labels can be applied to Microsoft Teams, groups, and SharePoint sites to enforce privacy settings and external sharing restrictions.

🎯 How does Sensitivity Labels appear on the MS-102 Exam?

You may be asked to design a solution where documents containing PII are automatically encrypted and restricted to the HR department using auto-labeling policies.

A scenario might describe a requirement to prevent external users from printing or forwarding a specific document, requiring you to configure encryption settings within a sensitivity label.

Expect questions where you must distinguish between applying a label to a specific file versus applying a label to a SharePoint site to control guest access.

❓ Frequently Asked Questions

What is the difference between sensitivity labels and retention labels?

Sensitivity labels focus on protection and classification (who can see the data), while retention labels focus on the data lifecycle (how long the data must be kept or when it should be deleted).


Can users change a label that was automatically applied?

Yes, if the policy allows it. Administrators can require users to provide a business justification when downgrading a label to a lower sensitivity level for auditing purposes.


How do sensitivity labels affect external sharing in Microsoft Teams?

When applied to a Team or site, sensitivity labels can automatically disable guest access, enforce private membership, or restrict the ability to create external sharing links.

Related Terms from Microsoft 365 Administrator

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Sensitivity Labels? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium