Information Protection
Sensitivity labels, publishing policies, auto-labeling, and DLP deployed via Security & Compliance PowerShell
under the deployInformationProtection pipeline toggle.
Exchange message encryption (IRM/OME) is backed up and deployed separately under
deployExchange.
Baseline Label Taxonomy
CONFIG365 ships a hierarchical label scheme from Public through Highly Confidential. Public, General, and Any user (internal or external) are standalone top-level labels; parent labels under Confidential and Highly Confidential define classification tiers with encrypted sub-labels.
Priority 0 Information approved for public release. No encryption or access restrictions.
Priority 1 Default internal classification. Content marking footer applied; suitable for everyday business use.
Priority 2 Standalone encrypted label for routine external collaboration. Authenticated users (internal and guest) may access; not classified as Confidential.
Priority 3 Sensitive business information. Sub-labels control who can open protected content.
Priority 8 High-sensitivity data. Encryption enforced; sub-labels define access scope.
Container labels: Labels can be scoped to Microsoft 365 Groups, SharePoint sites, and Teams.
Site-level sensitivity labels integrate with SharePoint tenant settings — see the
SharePoint settings reference for
DisableDocumentLibraryDefaultLabeling and related SpoTenant controls.
Default Label Publishing
The Default Label Publishing policy publishes
every baseline parent and sub label — publishing parent groups alone is not enough for encrypted flyout options to appear in Office apps.
CONFIG365 syncs the full label list on each baseline update.
Recipients only → Outlook / Exchange only
The Recipients only sub labels (Confidential and Highly Confidential) use ContentType=Email so they appear when labeling mail in Outlook — not in SharePoint, OneDrive, or Teams document libraries.
Any user (internal or external)
Standalone top-level label for routine external collaboration (Authenticated users template). It is not duplicated under Confidential or Highly Confidential flyouts.
No mandatory or restriction policies: CONFIG365 does not deploy mandatory labeling or user-facing restriction policies by default — those are left to MSP choice in Purview if needed.
Backup & Deploy Paths
Nightly backup exports live Purview configuration to the tenant repo under backups/information-protection/.
Promote desired settings to baseline/baseline/information-protection/ via the policy viewer.
information-protection/sensitivity-labels/ One JSON per label — display name, priority, encryption, content marking, and sub-label hierarchy.
information-protection/label-policies/ Publishing policies that make labels available to users in Office apps and Outlook.
information-protection/label-policy-rules/ Rules within publishing policies — location scopes, mandatory labeling, and default label settings.
information-protection/auto-label-policies/ Auto-labeling policy definitions for Exchange, SharePoint, OneDrive, and Teams.
information-protection/auto-label-rules/ Conditions and actions for auto-labeling (sensitive info types, keyword dictionaries, etc.).
information-protection/dlp-policies/ Data loss prevention policy shells — workload scope and mode.
information-protection/dlp-rules/ DLP rule conditions, actions, and exceptions within each policy.
Deploy processing order
- 1 Sensitivity labels (parent labels before sub-labels)
- 2 Label publishing policies
- 3 Label policy rules
- 4 Auto-labeling policies
- 5 Auto-labeling rules
Exchange Message Encryption
IRM (Rights Management) and OME (Office Message Encryption) configuration is backed up under
exchange/irm-configuration/ and
exchange/ome-configuration/.
These deploy with the deployExchange toggle, not
deployInformationProtection.
IRM Configuration
Internal rights management templates and transport-level IRM settings for Exchange Online.
OME Configuration
Office Message Encryption branding, templates, and transport rules that trigger OME on outbound mail.
Requirements & Permissions
Deploy and backup use Security & Compliance PowerShell (IPPS) via the portal-connected delegated account. The account needs Compliance Administrator or Information Protection Administrator (or equivalent). Label changes trigger an Azure AD label sync; CONFIG365 reconnects the IPPS session automatically if Graph/EXO connections interrupt it mid-run.