Appearance
Process - Sensitivity Labels
Process – Sensitivity Labels
Versioning
12 Aug 2025
Andrew Badge
Initial Version
Overview
This document outlines sensitivity labels; what they are, how they can be used and why they’re important.
What are Sensitivity Labels
Sensitivity Labels are system labels (in Microsoft 365 in this case) that enforce restrictions on documents, emails or meetings based on the content and its sensitivity (is the content confidential).
Each label can set one or more restrictions:
- Restrict access to certain people or groups
- Prevent sharing outside the organisation
- Prevent printing or screenshots
- Add a watermark or text to the email or document
How are sensitivity labels different from permissions?
Permissions restrict access to a system or document. But once a person has access they can copy, download or share the content; maybe to outside the organisation.
If this is confidential content or business Intellectual property we may want to prevent this.
Setting a sensitivity label can force the document to be encrypted and only users who login (and are part of a nominated group) can access the content.
How are labels applied?
Labels can be default overall (this applies to all apps) or have a default set for a certain SharePoint site or library.
Labels can then be overridden by the user for a folder, email or file.
Standard Labels
Below are the standard labels, the Description and the settings that are applied.
NB: this is the default and will likely be refined and additional descriptions added.
Label name
Label description for users
Settings
Personal
Non-business data, for personal use only.
Scope: Files & other data assets, Emails, Meetings*
Public
Business data that is specifically prepared and approved for public consumption.
Scope: Files & other data assets, Emails, Meetings*
General
Business data that is not intended for public consumption. However, this can be shared with external partners, as required. Examples include a company internal telephone directory, organizational charts, internal standards, and most internal communication.
Scope: Files & other data assets, Emails
General
\ Anyone (unrestricted)
Organization data that isn’t intended for public consumption but can be shared with external partners if appropriate. Examples include customer conversations that don’t include sensitive info or released marketing materials.
Scope: Files & other data assets, Emails, Meetings*
General
\ All Employees (unrestricted)
Organization data that isn’t intended for public consumption. If you need to share this content with external partners, confirm with other data owners that it's OK to share and then change the label to General \ Anyone (unrestricted) . Examples include a company internal telephone directory, organizational charts, internal standards, and most internal communication.
Scope: Files & other data assets, Emails, Meetings*
Confidential
Sensitive business data that could cause damage to the business if shared with unauthorized people. Examples include contracts, security reports, forecast summaries, and sales account data.
Scope: Files & other data assets, Emails
Confidential
\ Anyone (unrestricted)
Confidential data that doesn’t need to be encrypted. Use this option with care and appropriate business justification.
Scope: Files & other data assets, Emails, Meetings*
Content marking: Footer: Classified as Confidential
Confidential
\ All Employees
Confidential data that requires protection, which allows all employees full permissions. Data owners can track and revoke content.
Scope: Files & other data assets, Emails, Meetings*
Encryption: All users and groups in the org: Co-Author
Content marking: Footer: Classified as Confidential
Confidential
\ Trusted People
Confidential data that can be shared with trusted people inside and outside your organization. These people can also reshare the data as needed.
Scope: Files & other data assets, Emails, Meetings*
Encryption: Let users assign permissions:
- Encrypt-Only for Outlook
- Prompt users in Word, PowerPoint, and Excel
Footer: Classified as Confidential
Highly Confidential
Very sensitive business data that would cause damage to the business if it was shared with unauthorized people. Examples include employee and customer information, passwords, source code, and pre-announced financial reports.
Scope: Files & other data assets, Emails
Watermark: HIGHLY CONFIDENTIAL
Highly Confidential
\ All Employees
Highly confidential data that allows all employees view, edit, and reply permissions to this content. Data owners can track and revoke content.
Scope: Files & other data assets, Emails, Meetings*
Encryption: All users and groups in the org: Co-Author
Content marking: Footer: Classified as Highly Confidential
Highly Confidential
\ Specific People
Highly confidential data that requires protection and can be viewed only by people you specify and with the permission level you choose.
Scope: Files & other data assets, Emails, Meetings*
Encryption: Let users assign permissions:
- Do Not Forward for Outlook
- Prompt users in Word, PowerPoint, and Excel
Content marking: Footer: Classified as Highly Confidential

