Skip to content

Process - Sensitivity Labels

Process – Sensitivity Labels

Versioning

12 Aug 2025

Andrew Badge

Initial Version

Overview

This document outlines sensitivity labels; what they are, how they can be used and why they’re important.

What are Sensitivity Labels

Sensitivity Labels are system labels (in Microsoft 365 in this case) that enforce restrictions on documents, emails or meetings based on the content and its sensitivity (is the content confidential).

Each label can set one or more restrictions:

  • Restrict access to certain people or groups
  • Prevent sharing outside the organisation
  • Prevent printing or screenshots
  • Add a watermark or text to the email or document

How are sensitivity labels different from permissions?

Permissions restrict access to a system or document. But once a person has access they can copy, download or share the content; maybe to outside the organisation.

If this is confidential content or business Intellectual property we may want to prevent this.

Setting a sensitivity label can force the document to be encrypted and only users who login (and are part of a nominated group) can access the content.

How are labels applied?

Labels can be default overall (this applies to all apps) or have a default set for a certain SharePoint site or library.

Labels can then be overridden by the user for a folder, email or file.

Standard Labels

Below are the standard labels, the Description and the settings that are applied.

NB: this is the default and will likely be refined and additional descriptions added.

Label name

Label description for users

Settings

Personal

Non-business data, for personal use only.

Scope: Files & other data assets, Emails, Meetings*

Public

Business data that is specifically prepared and approved for public consumption.

Scope: Files & other data assets, Emails, Meetings*

General

Business data that is not intended for public consumption. However, this can be shared with external partners, as required. Examples include a company internal telephone directory, organizational charts, internal standards, and most internal communication.

Scope: Files & other data assets, Emails

General
\ Anyone (unrestricted)

Organization data that isn’t intended for public consumption but can be shared with external partners if appropriate. Examples include customer conversations that don’t include sensitive info or released marketing materials.

Scope: Files & other data assets, Emails, Meetings*

General
\ All Employees (unrestricted)

Organization data that isn’t intended for public consumption. If you need to share this content with external partners, confirm with other data owners that it's OK to share and then change the label to General \ Anyone (unrestricted) . Examples include a company internal telephone directory, organizational charts, internal standards, and most internal communication.

Scope: Files & other data assets, Emails, Meetings*

Confidential

Sensitive business data that could cause damage to the business if shared with unauthorized people. Examples include contracts, security reports, forecast summaries, and sales account data.

Scope: Files & other data assets, Emails

Confidential
\ Anyone (unrestricted)

Confidential data that doesn’t need to be encrypted. Use this option with care and appropriate business justification.

Scope: Files & other data assets, Emails, Meetings*

Content marking: Footer: Classified as Confidential

Confidential
\ All Employees

Confidential data that requires protection, which allows all employees full permissions. Data owners can track and revoke content.

Scope: Files & other data assets, Emails, Meetings*

Encryption: All users and groups in the org: Co-Author

Content marking: Footer: Classified as Confidential

Confidential
\ Trusted People

Confidential data that can be shared with trusted people inside and outside your organization. These people can also reshare the data as needed.

Scope: Files & other data assets, Emails, Meetings*

Encryption: Let users assign permissions:
- Encrypt-Only for Outlook
- Prompt users in Word, PowerPoint, and Excel

Footer: Classified as Confidential

Highly Confidential

Very sensitive business data that would cause damage to the business if it was shared with unauthorized people. Examples include employee and customer information, passwords, source code, and pre-announced financial reports.

Scope: Files & other data assets, Emails

Watermark: HIGHLY CONFIDENTIAL

Highly Confidential
\ All Employees

Highly confidential data that allows all employees view, edit, and reply permissions to this content. Data owners can track and revoke content.

Scope: Files & other data assets, Emails, Meetings*

Encryption: All users and groups in the org: Co-Author

Content marking: Footer: Classified as Highly Confidential

Highly Confidential
\ Specific People

Highly confidential data that requires protection and can be viewed only by people you specify and with the permission level you choose.

Scope: Files & other data assets, Emails, Meetings*

Encryption: Let users assign permissions:
- Do Not Forward for Outlook
- Prompt users in Word, PowerPoint, and Excel

Content marking: Footer: Classified as Highly Confidential