Baseline

Information Protection

Sensitivity labels, publishing policies, auto-labeling, and DLP deployed via Security & Compliance PowerShell under the deployInformationProtection pipeline toggle. Exchange message encryption (IRM/OME) is backed up and deployed separately under deployExchange.

Sensitivity LabelsAIPDLPAuto-LabelingPublishing PoliciesOME/IRM

Baseline Label Taxonomy

CONFIG365 ships a hierarchical label scheme from Public through Highly Confidential. Public, General, and Any user (internal or external) are standalone top-level labels; parent labels under Confidential and Highly Confidential define classification tiers with encrypted sub-labels.

Public
Priority 0

Information approved for public release. No encryption or access restrictions.

General
Priority 1

Default internal classification. Content marking footer applied; suitable for everyday business use.

Any user (internal or external)
Priority 2

Standalone encrypted label for routine external collaboration. Authenticated users (internal and guest) may access; not classified as Confidential.

Confidential
Priority 3

Sensitive business information. Sub-labels control who can open protected content.

Label onlyAll EmployeesRecipients onlyCustom
Highly Confidential
Priority 8

High-sensitivity data. Encryption enforced; sub-labels define access scope.

Label onlyAll EmployeesRecipients onlyCustom

Container labels: Labels can be scoped to Microsoft 365 Groups, SharePoint sites, and Teams. Site-level sensitivity labels integrate with SharePoint tenant settings — see the SharePoint settings reference for DisableDocumentLibraryDefaultLabeling and related SpoTenant controls.

Default Label Publishing

The Default Label Publishing policy publishes every baseline parent and sub label — publishing parent groups alone is not enough for encrypted flyout options to appear in Office apps. CONFIG365 syncs the full label list on each baseline update.

Recipients only → Outlook / Exchange only

The Recipients only sub labels (Confidential and Highly Confidential) use ContentType=Email so they appear when labeling mail in Outlook — not in SharePoint, OneDrive, or Teams document libraries.

Any user (internal or external)

Standalone top-level label for routine external collaboration (Authenticated users template). It is not duplicated under Confidential or Highly Confidential flyouts.

No mandatory or restriction policies: CONFIG365 does not deploy mandatory labeling or user-facing restriction policies by default — those are left to MSP choice in Purview if needed.

Backup & Deploy Paths

Nightly backup exports live Purview configuration to the tenant repo under backups/information-protection/. Promote desired settings to baseline/baseline/information-protection/ via the policy viewer.

information-protection/sensitivity-labels/

One JSON per label — display name, priority, encryption, content marking, and sub-label hierarchy.

information-protection/label-policies/

Publishing policies that make labels available to users in Office apps and Outlook.

information-protection/label-policy-rules/

Rules within publishing policies — location scopes, mandatory labeling, and default label settings.

information-protection/auto-label-policies/

Auto-labeling policy definitions for Exchange, SharePoint, OneDrive, and Teams.

information-protection/auto-label-rules/

Conditions and actions for auto-labeling (sensitive info types, keyword dictionaries, etc.).

information-protection/dlp-policies/

Data loss prevention policy shells — workload scope and mode.

information-protection/dlp-rules/

DLP rule conditions, actions, and exceptions within each policy.

Deploy processing order

  1. 1 Sensitivity labels (parent labels before sub-labels)
  2. 2 Label publishing policies
  3. 3 Label policy rules
  4. 4 Auto-labeling policies
  5. 5 Auto-labeling rules

Exchange Message Encryption

IRM (Rights Management) and OME (Office Message Encryption) configuration is backed up under exchange/irm-configuration/ and exchange/ome-configuration/. These deploy with the deployExchange toggle, not deployInformationProtection.

IRM Configuration

Internal rights management templates and transport-level IRM settings for Exchange Online.

OME Configuration

Office Message Encryption branding, templates, and transport rules that trigger OME on outbound mail.

Requirements & Permissions

Deploy and backup use Security & Compliance PowerShell (IPPS) via the portal-connected delegated account. The account needs Compliance Administrator or Information Protection Administrator (or equivalent). Label changes trigger an Azure AD label sync; CONFIG365 reconnects the IPPS session automatically if Graph/EXO connections interrupt it mid-run.