Sensitivity labels: which five are enough to start
The most powerful data-protection tool in Microsoft 365 that almost nobody uses. What sensitivity labels actually are, what they're for, what you need for them — and which five are enough to get started this week.
In the article about three licences we wrote one sentence that deserves an instalment of its own: sensitivity labels are the bridge between permission and classification. It sounds like a sentence for the compliance department. In reality it’s the most practical data-protection tool you probably already pay for in your licence — and almost certainly don’t use.
Sensitivity labels are something of a mystery. Most organisations either don’t know about them, or know them only by name and consider them “something complicated to do with encryption”. This article wants to break that impression. We’ll go through it in order: what it is, what it’s for, what you need for it and how it works — and at the end you’ll get a concrete set of five labels you can start with, without having to plan for six months first.
The short version for the impatient
Before we get into detail, here’s the whole topic in five points:
- What it is: an invisible sticker you attach to a document, e-mail or site. It travels with it wherever the file goes — even outside the company.
- What it’s for: it tells your environment (and AI) how sensitive the content is — and can enforce protection accordingly: encrypt it, block forwarding outside, add a watermark.
- What you need: manual labelling is already in Microsoft 365 Business Premium and E3. For automatic labelling at scale you need E5 (Purview Information Protection Plan 2).
- How it’s done: you create the labels once in the Microsoft Purview portal, “publish” them to users, and they appear right inside Word, Outlook and SharePoint as a button.
- Why right now: the moment you switch on Copilot or any other AI, it reads content according to permissions — but without labels it sees a contract and a lunch invitation exactly the same. A label is the language you use to tell AI what not to touch.
If that’s enough for you, you have the big picture. For how it all fits together and where the traps are, read on.
What sensitivity labels really are
Picture the classic “CONFIDENTIAL” stamp on a paper folder. Anyone who picks it up immediately knows how to handle it. A sensitivity label is the same, only digital — and smarter. It’s a piece of metadata attached directly to a document, e-mail, site or group that stays with it even when someone downloads the file, forwards it or saves it to a USB stick.
Two things are important to grasp:
- The label travels with the content, not with the location. When you label a document “Confidential” and someone e-mails it out, the label goes with it. Protection isn’t lost at the SharePoint boundary.
- A label can merely describe, or also enforce. The simplest label is just a sticker — classification for overview and reporting. But you can “arm” that same label: to automatically encrypt the file, add a watermark, block printing or prevent forwarding outside the company. You decide how much protection belongs to which level.
Where do labels appear? Right where people work — as a button in the top bar of Word, Excel, PowerPoint and Outlook, as an option on a SharePoint site or Teams team. The user needs to know nothing about Purview or encryption. They just see a menu of “Public / Internal / Confidential” and pick one.
What exactly it’s for
Sensitivity labels solve two things that are related but not the same:
1. Classification — so the environment knows what’s what. Without labels, everything lies on one pile in the libraries. A contract, a salary statement, a marketing flyer and a meeting note all have the same permissions and look the same. A label is the first moment content gets a name: “this is confidential, that is public.” Only then can anything else be built on top.
2. Protection — so sensitive content can’t be mishandled. Once a label carries protection, a wish becomes an enforceable rule. “This document must not be sent out” is no longer a note in an e-mail but a technical barrier. Encryption, download restrictions, watermarks, print blocking — all of it can be tied to a label and applies wherever the file is.
And thirdly, a dimension that was marginal a year ago and is now crucial: labels are the language you speak to AI. Microsoft 365 Copilot and other AI tools respect permissions — but a permission alone doesn’t say a document is sensitive. A label does. Copilot honours encrypted content and won’t show it to someone without rights to it; and through DLP policies for Copilot, labelled content can be excluded from AI answers entirely. Without labels, AI sees everything the same way. With labels, you give it guardrails.
It’s worth distinguishing the two layers that meet here — permission and classification — because each solves something different. Our own application, EasyPortal 365 AI Chat (Private Secure AI), stands on the first: it reads SharePoint exclusively under the identity of the signed-in user, so the AI never sees more than the person asking — there is no service account with broader access inside it. Before it’s even switched on, it can also scan the environment and warn the administrator about content open to the whole organisation (the Environment Check feature). That’s the permission layer: it governs who can reach the content. Sensitivity labels are the second, complementary layer — they carry the information about what the content is, across every tool, and can hide it even from someone who technically has the right to it. Neither layer replaces the other; together they give the full picture.
What you need for it
The good news: you probably don’t need to buy anything to get started.
- Manual labelling (the user picks a label themselves) is part of Microsoft 365 Business Premium, E3 and higher. That covers the vast majority of companies and is enough for a complete start.
- Automatic labelling (the environment recognises sensitive content and labels it itself) requires a higher tier — typically Microsoft 365 E5 or the Purview Information Protection Plan 2 add-on. That’s useful once you want to label thousands of existing documents at once.
With a licence and without one. Distinguish two things — applying a label and feeling its protection. Only someone with a licence (Business Premium/E3 and up) can label manually. But the protection on an already-labelled document applies to everyone: encryption and restrictions are enforced at the file level, not the user level — so even a colleague or external recipient without a licence will run into the fact that they can’t open or forward an encrypted document. A label protects even where a licence doesn’t reach.
Where it’s set up: in the Microsoft Purview portal (formerly the Compliance centre). There you create the labels, set their protection and “publish” them to selected people through what’s called a label policy. It’s a job for the administrator, not the end user — who then just picks from a ready-made menu.
One thing worth knowing up front: labels have a priority order by sensitivity. “Public” is at the bottom, “Highly Confidential” at the top. That order decides which rule wins when two of them meet — so think it through now, not as you go.
Which five labels are enough to start
Here’s the core of the whole article. Microsoft and practice agree on one thing: less is more. The recommended ceiling is five top-level labels (each optionally with a few sub-labels). Companies that start with eight or ten almost always hit the wall — users get lost in them and adoption falls apart. The most common cause of failure isn’t the technology, it’s an over-complicated taxonomy right at the start.
The five you won’t go wrong with:
- Public — content meant to go out without restriction: flyers, press releases, public price lists. No protection, just a clear “this can go out” marking.
- Internal — the default state for ordinary company work: notes, presentations, operational documents. It’s not secret, but it doesn’t belong outside. This label will be on most of your content.
- Confidential — content only for employees and approved partners: contracts, business materials, internal finance. This is where protection starts — typically a ban on external sharing.
- Highly Confidential — the most sensitive: payroll, personal data, strategic and legal materials, mergers and acquisitions. Encryption, a narrow circle of people, often exclusion from AI.
- (optional) Regulated / No AI — a special label for content under a special regime: data under GDPR beyond the ordinary, documents that must not go into AI grounding. Create it only when you truly need it.
The golden rule of naming: be specific, not generic. “Confidential – employees only” tells the user more than “Confidential 1”. The clearer the name, the fewer mistakes at selection.
A “No AI” label is only as strong as the AI that respects it
The fifth label is worth an extra note, because it touches exactly what we’re talking about today. Marking a document “No AI” only makes sense if the tool powering the AI actually honours that label. Microsoft 365 Copilot handles it through DLP policies for Copilot — it excludes labelled content from answers. With custom and partner AI solutions it therefore pays to ask: how do you handle sensitivity labels?
Our EP365 AI Chat defines what the AI will see primarily through permissions and a defined scope of sources — content that shouldn’t reach AI is excluded today by keeping it outside that scope or restricting access to it. Directly honouring a “No AI” label — so that sensitively labelled documents don’t reach an answer even for an authorised user — is a logical next step that would sharpen this control further. Precisely this kind of feedback from practice is what tells us where to develop the application next.
How to roll it out without it collapsing
Deploying labels isn’t about doing everything at once. The proven approach goes in waves:
- Agree first, don’t click. Get the taxonomy (those five labels) signed off with the business — HR, legal, finance, leadership. Labels have to match how people actually think about data, not how IT sees it.
- Pilot with a small group. Turn labels on first for a handful of people who’ll give feedback. You’ll refine the names and protection before the whole company sees them.
- Start step by step. First e-mail labelling (the easiest habit), then optional document labelling, then automatic labelling, and finally DLP rules that build on the labels.
- Encryption only at the top. Turn protection on carefully and from the highest tiers down. An encrypted document behaves differently (it can’t always be opened externally, it complicates some tools) — test it on the pilot, not across the board.
The single most important sentence of this section: taxonomy is the hardest thing to fix retroactively. Once labels are on tens of thousands of documents, renaming hurts. Half a day spent on which five labels and how to name them saves months.
What to do with old content
There remains the question that deters companies most: we have hundreds of thousands of existing documents with no labels — what do we do with them?
Nobody’s going to label them by hand, forget that. There are two routes:
- Automatic labelling by content. The environment can recognise sensitive patterns itself — account numbers, national ID numbers, keywords — and assign a label without human intervention. It requires a higher licence (E5) but handles thousands of files at once.
- A default label on the library. You set a default label on a library and new content gets it automatically. Until recently that applied only to newly uploaded or edited files. Microsoft is now preparing automatic labelling of existing files “at rest” too — including those nobody has opened in years (public preview is planned for August 2026, general availability for October 2026). This closes a long-standing gap where old unlabelled content stayed outside protection. A user’s manual choice is still respected — if someone deliberately picked a different label, the system won’t overwrite it.
The practical takeaway: start with new content and a pilot, catch up on the old with automation. Don’t wait until everything is labelled — that’s the road to never starting.
What to take away
Three sentences to close:
- Sensitivity labels aren’t a compliance luxury, they’re basic hygiene. And manual labelling is probably already paid for in your Business Premium or E3.
- Success is decided by taxonomy, not technology. Five clearly named labels agreed with the business beat ten perfectly configured ones nobody understands.
- Without labels, AI sees everything the same way. If you’re planning Copilot or any AI over company data, labels aren’t an optional extra — they’re a prerequisite.
At EP365 we help companies build classification from scratch — from taxonomy design through a pilot to automatic labelling and DLP integration. We most often handle it as part of a governance design or security audit, because labels only make sense when they build on tidied-up permissions. If you’re not sure which five labels would make sense for you, drop us a line — we’ll go through it over your specific environment.
In the next instalment we’ll stay with practice: how to set up DLP policies that build on sensitivity labels — and how to protect content with them without blocking everyday work.