Use Microsoft Purview Sensitivity Labels in Word, Excel, Outlook, and Microsoft 365
Sensitivity labels are no longer a new Office add-in experience; they are a core Microsoft Purview Information Protection capability built into Microsoft 365. When deployed well, labels help users classify documents, emails, sites, Teams, and other collaboration spaces so sensitive data stays protected wherever it goes.
What sensitivity labels do in 2026
Microsoft Purview sensitivity labels help organizations classify and protect information based on business value and risk. Users can apply labels such as Public, Internal, Confidential, or Highly Confidential directly in Microsoft 365 Apps, including Word, Excel, PowerPoint, and Outlook across supported desktop, web, and mobile experiences. Depending on how your organization configures the label, it can apply encryption, restrict who can open or edit the content, add headers, footers, or watermarks, and help enforce compliance controls.
Manage labels in Microsoft Purview, not the old Security & Compliance Center
Sensitivity labels are now managed through Microsoft Purview, primarily in the Microsoft Purview portal and compliance portal experiences. Organizations that still have legacy Azure Information Protection configurations should plan around unified sensitivity labels in Microsoft Purview. In most modern Microsoft 365 environments, labels are created, published, monitored, and governed from Purview rather than the older Microsoft 365 Security & Compliance Center or classic Azure Information Protection portal.
Where labels can apply
Sensitivity labels can protect more than individual Word, Excel, PowerPoint, and PDF files. They can also apply to Outlook email, SharePoint and OneDrive content, Microsoft Teams, Microsoft 365 Groups, and SharePoint sites. Depending on licensing and configuration, labels can also help control external sharing, unmanaged device access, privacy settings for Teams and Groups, and other collaboration controls. This makes labels useful both for protecting individual files and for governing the places where sensitive work happens.
User experience in Microsoft 365 Apps
For users, the experience is designed to be simple: a Sensitivity control appears in the Microsoft 365 app ribbon or message window, showing the labels published to that user. When a label is selected, the file or email carries that classification with it. If protection is applied, the permissions can remain with the content even when it is copied, downloaded, emailed, or stored in another supported location. Current screenshots should reflect the modern Microsoft 365 Apps interface rather than the older 2019 Office ribbon.
Policy options that make labels effective
A strong sensitivity labeling policy usually includes more than a list of labels. Microsoft Purview can support mandatory labeling, default labels, user justification when a label is downgraded or removed, visual content markings, encryption, access restrictions, and label inheritance in supported scenarios. Labels can also work with Microsoft Purview Data Loss Prevention policies, retention and compliance workflows, and security monitoring so that classification becomes part of a broader data protection strategy.
Automatic and recommended labeling
Manual labeling is useful, but it depends on users making the right choice every time. Microsoft Purview can also recommend or automatically apply labels when content matches configured conditions, such as sensitive information types, trainable classifiers, or other policy rules. Advanced automatic labeling and some classifier-based capabilities typically require Microsoft 365 E5, Microsoft Purview add-ons, or equivalent licensing, so licensing should be reviewed before deployment.
Licensing considerations
Core sensitivity labeling capabilities are available in many Microsoft 365 business and enterprise plans, but the exact feature set depends on the subscription. Microsoft 365 Business Premium and Microsoft 365 E3 commonly support important baseline information protection scenarios, while Microsoft 365 E5 and Microsoft Purview Information Protection or compliance add-ons enable more advanced automation, analytics, and governance features. If you buy Microsoft licensing through CSP, New Commerce Experience terms such as monthly or annual commitments can affect cost planning, so it is best to map requirements to licensing before rollout.
Recommended deployment approach
Start with a clear information classification model rather than turning on every feature at once. Define a small number of labels that employees can understand, map each label to business rules, pilot the labels with a representative group, and publish policies gradually. Train users with practical examples, monitor adoption in Microsoft Purview, review false positives and user feedback, and then tune the policy. After the baseline is stable, add advanced capabilities such as automatic labeling, stricter DLP policies, and container labels for Teams and SharePoint.
Key takeaways
- Sensitivity labels are now part of Microsoft Purview Information Protection and should be managed in Microsoft Purview, not the retired Security & Compliance Center experience.
- Labels can classify and protect files, emails, SharePoint sites, OneDrive content, Microsoft Teams, and Microsoft 365 Groups, depending on configuration and licensing.
- Modern label policies can include encryption, visual markings, default labels, mandatory labels, downgrade justification, external sharing controls, and DLP integration.
- Automatic and recommended labeling can reduce user error, but advanced capabilities may require Microsoft 365 E5 or Microsoft Purview compliance add-ons.
- A successful rollout starts with a simple classification taxonomy, a pilot group, user training, monitoring, and gradual policy tuning.
Need help designing or modernizing sensitivity labels in Microsoft 365? IT Partner can assess your current Microsoft Purview configuration, align labels with your compliance requirements, and help deploy information protection policies with the right Microsoft 365 licensing.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.