Microsoft Information Protection SDK - classification label concepts

As part of a comprehensive data protection strategy, organizations need a data classification system. The system outlines the levels of data sensitivity within the organization and maps document attributes to those classifications.

Attributes related to classification typically involve the risk to the organization if that document or data is lost or seen by unintended audiences. The familiar United States government classification system has three classification levels. Each has a definition that describes when to apply that classification:

  • Top Secret: Applied to information when unauthorized disclosure reasonably could be expected to cause exceptionally grave damage to the national security that the original classification authority can identify or describe.
  • Secret: Applied to information when unauthorized disclosure reasonably could be expected to cause serious damage to the national security that the original classification authority can identify or describe.
  • Confidential: Applied to information when unauthorized disclosure reasonably could be expected to cause damage to the national security that the original classification authority can identify or describe.
  • Unclassified: The absence of one of the previous examples.

In a commercial or private sector application, you can define a list similar to the default in Microsoft Purview Information Protection, with monetary values attached.

  • Highly Confidential: Applied to information when unauthorized disclosure reasonably could be expected to cause damage greater than USD $1M.
  • Confidential: Applied to information when unauthorized disclosure reasonably could be expected to cause damage greater than USD $100,000.
  • General: Applied to information when unauthorized disclosure reasonably could be expected to cause little measurable damage.
  • Public: Applied to information intended for public, external consumption.
  • Non-Business: Applied to information that isn't related to company business, direct or indirect.

Each classification describes the risk to the business if unauthorized disclosure of that information occurs. After identifying these classifications and conditions, identify attributes that help data owners understand which classification to apply.

Labeling

Labeling associates a data classification with a set of information. Because the MIP SDK applies classification labels to documents, this article refers to labels rather than classifications. A user or process classifies the data based on knowledge of the information. The MIP SDK then labels the information.

Labels in the MIP SDK

Labels are a fundamental component of the MIP SDK. Labels drive the tagging, protection, and content marking of all documents touched by the SDK. The SDK can:

  • Apply labels to documents.
  • Read existing labels on documents.
  • Change an existing label and mandate justification if required by policy.
  • Remove a label from a document.

The label applies protection and content marking based on the configuration in the Microsoft Purview portal.

mip::Label vs. mip::ContentLabel

The MIP SDK uses two label types: Label and ContentLabel.

  • Label: A label applied by a user or process as defined in the organizational policy.
  • ContentLabel: A label that already exists on a document or information. You can read, update, or remove it.

In other words, ContentLabel represents a Label applied to an object.

Querying label protection types

Starting in MIP SDK 1.18, the mip::Label class provides methods to determine what type of protection a label applies before using the label. This information is useful when building user interfaces that need to display protection details or when filtering labels by behavior.

Method Description
HasDoNotForwardProtection() Returns true if the label applies Do Not Forward protection.
HasEncryptOnlyProtection() Returns true if the label applies Encrypt Only protection.
HasAdhocProtection() Returns true if the label applies custom (ad hoc) protection defined by the user.

These methods extend the existing HasRightsManagementPolicy() method, which indicates whether a label applies any form of Rights Management protection. The new methods provide more granular detail about the specific protection type.

For more information, see Label protection types.

Metadata

The SDK also supports adding extra metadata to documents in the form of key-value pairs. If your organization has subclassifications or tags that describe the information more specifically, you can use the SDK to apply that metadata.

Next steps

For more information about the United States government classification system, see Classified National Security Information.