LemonBits

  • Home
  • About
  • Contact me
Microsoft 365, Office 365

Extended senstibitiy labels to the files that are downloaded from SharePoint

Frane Borozan - October 29, 2025

Ever shared a file from SharePoint and wondered, “What happens when someone downloads this?” 🤔
Spoiler alert: traditional SharePoint permissions stop at the door. Once that file leaves the site, it’s like sending your kid off to college—no curfew, no rules.

But don’t panic! Microsoft Purview has a neat trick: Sensitivity Labels that extend permissions beyond SharePoint. Think of it as giving your files a security backpack that travels with them. 🎒


✅ Why Should You Care?

Imagine this:

  • You upload a confidential strategy doc to SharePoint.
  • Someone downloads it, emails it to their personal account, and boom—your sensitive info is out in the wild.

With Sensitivity Labels, you can make sure that SharePoint permissions stick to the file even after download. That means:

  • If you had read-only access, you can’t suddenly edit it offline.
  • If you weren’t supposed to see it, you still can’t open it—even if you somehow got the file.

Pretty cool, right? 😎


🛠 How Does It Work?

Here’s the magic in simple terms:

  • Unlabeled files in a SharePoint library can automatically get a sensitivity label.
  • Files without encryption can be relabeled for consistent protection.
  • When someone downloads the file, the label applies the same permissions they had in SharePoint.

So if John from Finance had view-only rights, he can’t suddenly become an editor after downloading. And if Sarah from Marketing didn’t have access, she’s still locked out. 🔒


🔍 Behind the Scenes

  • The label uses Microsoft Information Protection (MIP) to enforce rules.
  • Permissions sync dynamically—if you remove someone’s access in SharePoint, they lose access to the downloaded file too.
  • Files can’t be copied or moved to other sites without losing their label.

This is persistent protection, not just a one-time lock.


🧩 Real-Life Example

Picture this:
Your HR team uploads salary reports to SharePoint. Normally, if someone downloads them, they could share them freely. With sensitivity labels:

  • Only HR staff can open the file—even offline.
  • If someone leaves the company, their access disappears automatically.

That’s like having a digital bouncer for your files. 🕶


⚙️ How to Set It Up (Step-by-Step)

Here’s the quick guide:

  1. Go to Microsoft Purview Compliance Portal.
  2. Navigate to Information Protection > Labels.
  3. Create or edit a label and enable Apply label to SharePoint and OneDrive files.
  4. Configure Auto-labeling policies for your document libraries.
  5. Test with a pilot group before rolling out company-wide.

💡 Pro Tip: Start with non-critical libraries to avoid accidental lockouts.


🚧 Things to Keep in Mind

  • This feature is in preview, so expect updates.
  • Copilot can’t access unopened files with these labels (for now).
  • Requires proper licensing (Microsoft 365 E5 or equivalent).

🎨 Visualizing It

Imagine this flow:
📂 SharePoint Library → 🏷 Sensitivity Label Applied → 💻 File Downloaded → 🔐 Permissions Persist


 

 0 0
Share Now

Frane Borozan

Helping SBC administrators kick-ass Google+

Leave a Reply Cancel Reply

Your email address will not be published. Required fields are marked *

Previous Post Subscribing to M365 Insider preview manually

Connect with me on

Latest Posts

  • Extended senstibitiy labels to the files that are downloaded from SharePoint

  • Subscribing to M365 Insider preview manually

  • Your guide to a SharePoint Online Site

    SharePoint alerts retirement

  • Introducing Teams Client Health: Proactive Monitoring for Microsoft Teams

  • Tracking and monitoring user access in Microsoft Teams and Shared channels

    Restricted content discovery or how Copilot can see that site too?

  • SharePoint Agents: Revolutionizing Workplace Collaboration

  • Microsoft Data Security Posture Management for AI

  • SharePoint agents are very use to create and use

  • SharePoint Agents

  • BEWARE OF THE INACTIVE ONEDRIVE ACCOUNTS!!!

Recent Comments

  • Nigel Sampath on Installing Remote Desktop Services 2016
  • Christoph Juli on VPN doesn’t work aka how to clear ARP cache on the computer when you connect to the VPN
  • Amir on The curious case of saved-critical Hyper-V machines in Hyper-V Manager or Incomplete VM Configuration in Virtual Machine Manager
  • Frane Borozan on Downloads folder slow to load/sort in Windows 10
  • güvenlik kamerası on Downloads folder slow to load/sort in Windows 10
  • Laki Lakovic on Opening group policy editor on a remote computer and forcing GP Update
  • Diane on Opening group policy editor on a remote computer and forcing GP Update
  • Manoj B on Differences between L1, L2, L3 system administrator guidlines
  • Travis Vroman on Teams slow
  • Yossi B on Remote Desktop Services Manager 2016
  • astha on SharePoint audit logs
  • Frane Borozan on Installing Remote Desktop Services 2016
  • Joe Zhou on Installing Remote Desktop Services 2016
  • Pino on Installing standalone Remote Desktop Gateway on the Windows Server 2012 R2 without complete Remote Desktop Services infrastructure
  • Eddy Wilson on Windows 10: Share a VPN Connection
  • haleybri.com on Remote Desktop Services Manager 2016
  • Atif on Remote Desktop Services Manager 2016
  • Tan Vu on KB2919355 The update is not applicable to your computer
  • Vinay on Installing Remote Desktop Services 2016
  • JOEL FERDY FEUBI TABOUE on KB2919355 The update is not applicable to your computer
  • Delmar on Installing standalone Remote Desktop Gateway on the Windows Server 2012 R2 without complete Remote Desktop Services infrastructure
  • Luke Welden on KB2919355 The update is not applicable to your computer
  • LM on Installing standalone Remote Desktop Gateway on the Windows Server 2012 R2 without complete Remote Desktop Services infrastructure
  • Anonymous987 on KB2919355 The update is not applicable to your computer
  • ANonyommus987 on KB2919355 The update is not applicable to your computer
  • Alan on Remote Desktop Services Manager 2016
  • Jagz on Installing Remote Desktop Services 2016
  • VG on SharePoint audit logs
  • VG on SharePoint audit logs
  • Kalle on SharePoint audit logs
  • 3 pandas on SQL Server security best practices
  • Kalle on SharePoint audit logs
  • Frane Borozan on Installing standalone Remote Desktop Gateway on the Windows Server 2012 R2 without complete Remote Desktop Services infrastructure
  • Erin Platt on Installing standalone Remote Desktop Gateway on the Windows Server 2012 R2 without complete Remote Desktop Services infrastructure
  • Tad Benoit on Remote Desktop Services Manager 2016

Copyright © 2023 Frane Borozan. All rights reserved