Your input shapes our product. Suggest a feature now →
  1. Home
  2. Tools
  3. Sensitivity Label Settings

SharePoint Sensitivity Labels: The Complete Admin Reference

Sensitivity labels in SharePoint Online split into two distinct scopes, each with separate settings and licensing requirements. This reference covers every setting that affects SharePoint behaviour.

Label scope Applies to Primary SharePoint effect Minimum plan
Files and emails Individual documents in SharePoint and OneDrive Encryption, content marking (watermark, header, footer) Microsoft 365 E3 or Business Premium
Groups and sites SharePoint site, Teams channel, Microsoft 365 Group container Privacy setting, external sharing controls, device access policy Microsoft 365 E3 or Business Premium
Schematized data assets Microsoft Purview data map assets None (applies to Purview data catalog only) Microsoft Purview Data Catalog licence

Container label settings (Groups and sites scope)

When a label with the Groups and sites scope is applied to a SharePoint site, the settings below take effect at the site level and override the corresponding tenant-level defaults for that site only.

Setting Available options Behaviour when not configured in the label
Privacy Public / Private / No override No override; site retains its current privacy setting
External user access to the group Allow existing external users / Block new and existing external users Allow (label must explicitly block)
External sharing from the site Anyone / Authenticated guests / Existing guests only / Only organisation members Inherits tenant-level or site-level sharing setting, whichever is more restrictive
Conditional access: unmanaged devices Full access / Limited web-only access / Block access Full access (inherits tenant conditional access policy)
Authentication context None / Require a specific Entra ID conditional access policy None

File label encryption settings (Files and emails scope)

Encryption is optional at the label level. A label without encryption still provides classification and content marking. Encrypted files use Azure Rights Management Service (RMS) and remain protected wherever the file travels, including outside SharePoint.

Encryption option What it does Typical use case
No encryption Label applies classification and content marking only; file access is governed by SharePoint permissions as usual General classification where SharePoint permissions provide adequate access control
Apply encryption with admin-defined permissions Azure RMS encryption is applied; admin pre-configures which users or groups can open, edit, or print the file Confidential documents that may leave SharePoint via email or download
Let users assign permissions (Do Not Forward / Encrypt-Only) User selects recipients and rights at the time they apply the label in an Office app Ad-hoc sensitive communications where the sender controls the recipient list
Double Key Encryption (DKE) Encryption uses two keys: one Microsoft-held, one held by the organisation in its own key store Highly regulated scenarios requiring data sovereignty over encryption keys

Content marking options

Content marking applies to files and emails regardless of whether encryption is enabled. Office apps insert the markings when a user opens and saves the file. They do not appear in the SharePoint browser viewer.

Marking type Supported Office apps Dynamic variable support
Header Word, Excel, PowerPoint (desktop and web) Yes: ${LabelName}, ${TenantName}, ${Item.Label}
Footer Word, Excel, PowerPoint (desktop and web) Yes
Watermark Word, PowerPoint (not Excel) Yes

Auto-labelling availability

Auto-labelling removes the dependency on users to choose labels. Two modes are available, with different licensing requirements and triggers.

Mode How it runs Required plan
Client-side (recommended label) Office app recommends or automatically applies the label when a user opens or saves a file, based on the content detected Microsoft 365 E3 or Business Premium
Service-side (auto-labelling policy) Microsoft 365 service crawls SharePoint and OneDrive in the background and applies labels to existing files without user action; supports simulation mode before going live Microsoft 365 E5, Microsoft 365 E5 Compliance, or Purview Information Protection P2 add-on

What sensitivity labels do not control in SharePoint

Sensitivity labels govern classification and protection at the content level. Permission management is a separate concern. Labels do not affect or report on:

  • Who holds site membership or direct permissions on document libraries and lists
  • Sharing links: who has received them, what permission they grant, and when they expire
  • Unique permission inheritance breaks across subsites or libraries
  • Guest user stale access or Entra ID guest account status

To audit and remediate sharing links and direct permissions across a Microsoft 365 tenant, see the guide on how to audit SharePoint permissions or the Shared Links and Permissions tool in ShareMaster.

Frequently Asked Questions

Does a sensitivity label applied to a SharePoint site automatically label the files inside?

No. A container label (Groups and sites scope) sets the site's privacy and external sharing settings but does not label the documents stored within it. File labeling requires a separate label configured with the Files and emails scope, applied either manually or through an auto-labelling policy.

Can external users access SharePoint files that have an encrypted sensitivity label?

It depends on the label. If the label does not apply encryption, external access is governed by the normal site and tenant sharing settings. If the label applies Azure RMS encryption, external users can only open the file if the label was configured to include external domain or guest user permissions within the encryption settings.

What is the difference between a site label and a file label in SharePoint?

A site label (Groups and sites scope) governs the container: privacy, external sharing, and device access. A file label (Files and emails scope) governs individual documents: encryption and content marking. A single label in Microsoft Purview can include both scopes simultaneously.

Can end users apply or change sensitivity labels on files in SharePoint?

Yes, if the label has been published to their label policy. Users select a label from the sensitivity column in a document library or from the sensitivity bar in Office apps. Admins can enforce mandatory labeling or require a written justification when users downgrade to a lower-sensitivity label.

Try ShareMaster free for 14 days