Skip to main content

How Microsoft 365 can help protect sensitive business information

Microsoft Purview Information Protection can help a business classify sensitive email and documents and apply appropriate handling or access controls.

The service previously known as Azure Information Protection now forms part of Microsoft Purview Information Protection. It helps organisations identify sensitive information and apply labels that explain how it should be handled.

The name has changed, but the business question remains the same: how can employees recognise important information and share it with the right level of care?

What is a sensitivity label?

A sensitivity label is a classification applied to an email, document or other supported content. A business might use simple labels such as Public, Internal and Confidential, with clear guidance about what each one means.

Depending on the licence and configuration, a label can also apply controls. It may add a visual marking, restrict access or encrypt supported content so that only authorised people can open it.

Why labels need business input

Technology cannot decide the meaning of every piece of information by itself. The organisation needs to agree:

  • which information is sensitive;
  • which labels employees can understand;
  • what each label should do;
  • when a label should be applied automatically; and
  • who can change or remove a protection.

Keep the system usable

Too many labels create uncertainty. Controls that are too restrictive can interrupt legitimate collaboration and encourage workarounds. Begin with a small, understandable model and test it with the people who create and share the information.

Protection should follow the information

Where supported, the label remains associated with the content. That can help the intended protection continue when a document is downloaded or shared, rather than relying only on the place where it was originally stored.

Information protection is part of a wider plan

Labels do not replace correct Microsoft 365 access, managed devices, secure sharing, backup or employee awareness. They add another control where the sensitivity of the information justifies it.

baseMSP can consider information protection as part of a wider Microsoft 365 review and roadmap. The appropriate design depends on the information, licence and working practices of the business.

Further reading

Microsoft explains the current approach in its Microsoft Purview information-protection guidance.

Continue reading

Talk it through

Have a question about what this means for your business?

Tell us what you have in place or what you're trying to decide. We'll explain where we can help and make the next step clear.