Labels and DLP in practice: one company day in six situations
Sensitivity labels and DLP sound like theory for IT. Here's the translation into everyday life — six situations from an ordinary company day you'll probably recognise from your own office, and what happens in each of them.
In the previous two instalments we took apart two things: sensitivity labels, which tell a document what it is, and DLP, which makes sure it isn’t mishandled. The theory is clear: a label classifies, DLP enforces. But “classifies” and “enforces” are still abstract words — and until you picture a specific Tuesday morning when Jana from HR is sending an e-mail, it all stays a bit on paper.
So let’s walk through that Tuesday. Six situations from an ordinary company day, each with a different person and a different problem — and in each you’ll see how a label and DLP work together. No new theory, just last time’s in action.
8:40 — Jana from HR and the payroll spreadsheet
Jana is preparing materials for a leadership meeting and accidentally drags the whole department’s payroll spreadsheet into a library shared with the entire company. The classic two-seconds-of-inattention mistake.
- Without the system: the spreadsheet sits there. Anyone who knows about that library opens it. Nobody notices for years — until it blows up.
- With labels and DLP: the payroll spreadsheet carries a Highly Confidential label (it got it automatically, because someone from HR created it in the personnel library). A rule is tied to that label: “must not leave the narrow HR circle.” So DLP blocks the sharing outright and shows Jana why. The document never even reaches the company library.
This is the hardest end of the scale — a block. And it makes sense here, because payroll is exactly the content where one annoying prompt beats one leak.
10:15 — salesman Petr sends a quote to a client
Petr has finished a price quote and is e-mailing it to a client. The quote is labelled Confidential — it’s business material that normally doesn’t go out. But this particular e-mail is meant to go out; it’s legitimate work.
- Badly configured DLP: it blocks the e-mail because “Confidential must not go out.” Petr is furious, calls IT, and next time sends the quote from his private Gmail, where governance can’t reach.
- Well-configured DLP: instead of a block, a warning pops up (a policy tip): “This document is Confidential and you’re sending it outside the company. Do you really want to continue?” Petr knows what he’s doing, clicks confirm — and the e-mail goes out. Meanwhile the system has recorded that it left, who sent it and where.
This is the subtlety the whole previous instalment was about. DLP isn’t supposed to stop work. It’s supposed to ask at the right moment — and let the person decide.
11:30 — the contract that was forgotten
A colleague from operations sends a supplier a draft contract. It contains a paragraph with the directors’ national ID numbers. Nobody ever labelled that contract — it was created in a hurry, saved to the desktop, and now it’s flying out.
- Without the system: the ID numbers go out by e-mail to the supplier. Nobody considered that these are personal data.
- With labels and DLP: even though the document has no label, DLP can look inside and recognise the national ID number pattern. The second route kicks in — detection by content, not by label. The colleague gets a warning that the e-mail contains personal data and reconsiders whether to leave it there.
The key lesson: labels cover what people deliberately marked. Content detection catches what got forgotten — and things get forgotten all the time.
14:00 — Martin “backs up” his work to a USB stick
Martin is resigning and, the day before he leaves, wants to copy a few folders to a USB stick “just in case.” Among them are project documents labelled Confidential.
- Without the system: the stick goes in, the files copy, Martin leaves with them. Nobody finds out.
- With labels and DLP: this is where Endpoint DLP comes in — the part that watches even what happens outside Microsoft, right on the computer. Copying Confidential content to USB is recorded and Martin gets a warning (or the action is blocked outright, depending on the setup). IT has a record that someone tried.
This scenario shows the reach people underestimate with DLP: it doesn’t end at e-mail and SharePoint, it extends all the way to the endpoint device. (Note — Endpoint DLP is a higher-licence feature, typically E5.)
15:20 — Lucie asks Copilot about salaries
Manager Lucie opens Copilot and types: “Summarise the salary range in my team.” Technically she has access to some of those documents, so AI could assemble them into a neat table in a second.
- Without the system: Copilot dutifully goes through everything Lucie has rights to and pours the sensitive figures into an answer. Fast and convenient — and completely out of control.
- With labels and DLP: the payroll documents carry a Highly Confidential label (the most sensitive ones also No AI). A DLP for Copilot rule is tied to it — “this content must not be used as grounding for AI answers.” So Copilot won’t include it in the answer, even though Lucie has the right to it. The last safeguard that permissions alone can’t provide.
And because AI today isn’t powered by Copilot alone: every solution handles labels its own way. Our EP365 AI Chat defines what AI will see through permissions and a defined scope of sources — you keep sensitive content out of it by leaving it outside that scope or restricting access to it (directly honouring labels is a direction we’re developing the app in). What matters is knowing the answer to one question before you switch AI on: what keeps sensitive content out of its reach?
16:45 — the external consultant and the encrypted file
An external consultant has joined the project. A colleague accidentally forwards them a document labelled Highly Confidential that carries encryption. The consultant is outside the company and has none of your licences.
- The worry we often hear: “surely the protection only works for our people with a licence, right?”
- How it actually is: the protection travels with the file, not with the licence. Encryption and restrictions are baked right into the document — so a consultant without a licence simply can’t open it (or opens it read-only, with no way to forward it on), depending on what rights the label grants. The protection holds even where your licence doesn’t reach.
This is the most common misunderstanding around the whole topic. The licence is needed by whoever applies the label. The protection of an already-applied label is felt by everyone — a colleague, a supplier, a consultant.
What repeats across every situation
Six different people, six different problems — and yet the same four principles keep coming back:
- A label classifies, DLP enforces. In almost every situation the label decided first (“this is Highly Confidential”) and only then did DLP kick in (“and therefore it must not…”). One without the other wouldn’t work.
- The system distinguishes risk from ordinary work. It blocked Jana’s sharing; it merely reminded Petr. The difference between a block and a warning is what separates protection people accept from protection they bypass.
- Protection travels with the content — not with the location or the licence. It applies on USB, in outbound e-mail, and with an external consultant who has no licence.
- AI is a new scenario, not an exception. Copilot and any other AI read the same data — and labels with DLP are what govern them too.
What to take away
Three sentences to close:
- Labels and DLP aren’t two topics, they’re one system. The label says what, DLP says what to do about it — and only together do they make sense.
- The best protection is the one you barely meet during the day. It steps in only when it must, and otherwise lets people work. Exactly like in those six situations.
- Start with the most sensitive. Payroll, personal data, strategic documents — where a single leak would hurt most. The rest can be built up gradually.
At EP365 we help companies build this system so it works exactly like in the examples above — from label design through DLP policies to tuning them so they protect without slowing things down. We most often handle it as part of a governance design or security audit. If you’d like to walk through how those six situations would play out at your place, drop us a line.
In the next instalment we’ll leave protection behind and look at the content lifecycle: how to set up retention and archiving so that years of old clutter don’t pile up in SharePoint — and why it matters more than it seems, precisely because of AI.