Microsoft Purview Information Protection

Enterprise implementation of Microsoft Purview Information Protection covering Sensitivity Labels, Label Policies, Manual Classification, Automatic Labeling, Encryption, and Information Protection across Microsoft 365 workloads.


View GitHub Repository

Enterprise Overview

This project demonstrates the implementation of Microsoft Purview Information Protection within a Microsoft 365 enterprise environment. The objective is to establish a standardized data classification framework using Sensitivity Labels, publish those labels to users, apply encryption and access control, and automate classification using Sensitive Information Types (SITs).


The implementation forms the foundation for Microsoft Purview Data Loss Prevention, Microsoft Purview Audit, Microsoft Defender for Cloud Apps, and Microsoft Purview Data Lifecycle Management.

Business Problem

Organizations create thousands of documents, emails and collaboration files every day. Without centralized information protection:


A standardized information classification model is required before implementing downstream security controls such as DLP.

Business Requirements

RequirementPurpose
Enterprise ClassificationStandardize data classification across Microsoft 365
Sensitivity LabelsProtect confidential information consistently
EncryptionRestrict document access to authorized users
Automatic ClassificationReduce human error through automation
Label PoliciesPublish labels to users and workloads
Microsoft 365 IntegrationProtect Exchange, SharePoint, OneDrive and Teams

Microsoft Solution

CapabilityDescription
Sensitivity LabelsClassify and protect Microsoft 365 content
Label PoliciesPublish labels across Microsoft 365 workloads
Manual LabelingUser-driven document classification
Automatic LabelingDetect Sensitive Information Types automatically
EncryptionAzure Rights Management protection
Content MarkingHeaders, footers and watermarks
Microsoft 365 IntegrationExchange, SharePoint, OneDrive, Teams and Office Apps

Enterprise Perspective

StageImplementation
Business ProblemUnclassified enterprise information increases the risk of accidental data exposure.
Business RequirementImplement enterprise-wide data classification with encryption and policy-based protection.
Microsoft SolutionMicrosoft Purview Information Protection using Sensitivity Labels and Auto Labeling.
ConfigurationCustom labels, label policies, manual labeling and automatic labeling configured.
ValidationLabels successfully published and available across Microsoft 365 applications.
OutcomeEnterprise information is consistently classified and protected before sharing.

Architecture Overview

Purview Information Protection Architecture

Enterprise Information Protection Architecture

Implementation Phase 1 – Microsoft Purview Overview

Microsoft Purview Information Protection provides a centralized platform for classifying, protecting and governing enterprise information across Microsoft 365 workloads. During this lab the Information Protection solution was accessed through the Microsoft Purview portal where Sensitivity Labels, Label Policies and Auto-labeling Policies were configured.

Microsoft Purview Compliance Portal

Information Protection Solution

Sensitivity Labels Navigation

Implementation Phase 2 – Creating Enterprise Sensitivity Labels

Sensitivity Labels provide the foundation for Microsoft Information Protection. Labels classify enterprise information while optionally applying encryption, permissions, content marking and access control. In this implementation multiple enterprise labels were created for different business classifications.

LabelPurpose
PublicUnrestricted Information
GeneralInternal Business Information
ConfidentialEncrypted Business Data
Highly ConfidentialRestricted Enterprise Data
Finance ConfidentialAutomatic Credit Card Protection

Sensitivity Labels List

Create Label

Label Description

Label Scope Configuration

Each Sensitivity Label was configured to protect Files and Emails, allowing Microsoft 365 applications such as Word, Excel, PowerPoint, Outlook, SharePoint Online and OneDrive to recognize the label. The Groups & Sites scope was not configured in this foundational lab.

Files & Emails Scope

Basic Label Information

Scope Selection

Protection Configuration

Microsoft Purview allows each Sensitivity Label to enforce encryption, assign permissions, restrict offline access and configure content markings such as headers, footers and watermarks. These settings ensure protection remains attached to the document regardless of where it is stored or shared.

Protection Settings

Access Control

Encryption Permissions

Implementation Phase 3 – Publishing Sensitivity Label Policies

After creating the enterprise sensitivity labels, a Label Policy was configured to publish them to Microsoft 365 users. Publishing makes the labels available within Outlook, Word, Excel, PowerPoint, SharePoint, OneDrive and Teams. The policy synchronizes automatically across Microsoft 365 once published.

Create Label Policy

Select Labels

Assign Users

Policy Settings

Policy Synchronization

Implementation Phase 4 – Manual Sensitivity Labels

Manual labeling enables users to classify documents themselves directly from Microsoft Office applications. This approach provides flexibility while still enforcing encryption, permissions and organizational classification standards.

Purview Administration

Sensitivity Labels Overview

Manual Label Applied in Microsoft Word

Implementation Phase 5 – Automatic Sensitivity Labels

Automatic labeling removes the dependency on users manually selecting a classification. Microsoft Purview scans content for Sensitive Information Types (SITs) such as Credit Card Numbers and automatically applies the configured Sensitivity Label. This greatly reduces human error and improves compliance.

DetectionConfigured Action
Credit Card NumberApply Finance Confidential Label
EncryptionEnabled
Label PublishingCompleted
Automatic ClassificationEnabled

Create Auto Label Policy

Scope Configuration

Enable Auto Labeling

Detection Conditions

Sensitive Information Type

Credit Card Detection Configuration

Auto-Label Policy Validation

The automatic labeling policy was configured to detect Credit Card Numbers using Microsoft's built-in Sensitive Information Types (SITs). When the configured detection threshold is met, Microsoft Purview automatically applies the Finance Confidential Sensitivity Label. This minimizes user dependency while ensuring sensitive financial information is consistently protected.

Review Auto-label Configuration

Publish Auto-label Policy

Auto-label Policy Wizard

Policy Scope

Final Policy Review

Validation Results

Validation ItemStatus
Purview Portal AccessibleVerified
Enterprise Sensitivity Labels CreatedCompleted
Label Policies PublishedCompleted
Manual Labeling TestedVerified
Automatic Labeling Policy ConfiguredVerified
Credit Card Detection ConfiguredVerified
Encryption Settings ConfiguredVerified
Microsoft 365 IntegrationVerified

Skills Demonstrated

Microsoft Purview Information Protection Sensitivity Labels Label Policies Manual Classification Automatic Labeling Encryption Microsoft 365 Exchange Online SharePoint Online OneDrive Microsoft Teams

MS-102 Exam Objectives Covered

Zero Trust Alignment

Zero Trust PrincipleImplementation
Verify ExplicitlyEvery document is classified before protection.
Least PrivilegeEncryption limits access to authorized users.
Assume BreachProtection remains attached to the file wherever it travels.

PowerShell Automation

ScriptPurpose
New-SensitivityLabels.ps1Create enterprise sensitivity labels.
New-AutoLabelingPolicy.ps1Create Auto-labeling Policy.
Get-SensitivityLabelReport.ps1Generate Information Protection reports.

Related Projects

Lessons Learned

Conclusion

This project demonstrates a complete Microsoft Purview Information Protection implementation using Sensitivity Labels, Label Policies, Manual Classification and Automatic Labeling. The environment establishes an enterprise-ready data classification framework supporting Microsoft 365 security, compliance and Zero Trust initiatives while providing a strong practical reference for MS-102 Microsoft 365 Administrator exam preparation.

View GitHub Repository →