How to get an alert when documents' or mails' sensitivity label is changed ?

Mohand BENHADDAD 0 Reputation points
2023-04-03T13:19:19.8333333+00:00

Hello,

I would like to know if there is a way through the Microsoft Purview platform to generate an alert and receive it through email when a user changes the sensitivity label of documents when he receives it.

Thank you.

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
560 questions
Outlook | Windows | Classic Outlook for Windows | For business
Microsoft 365 and Office | SharePoint | For business | Windows
Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-04-04T20:43:26.8933333+00:00

    Hi @Mohand Benhaddad ,

    To get an alert when a sensitivity label is changed and monitor sensitivity label events/activities in Microsoft Purview, you can use Microsoft Sentinel.

    If you use the Microsoft Purview Information Protection connector in Microsoft Sentinel, you can collect audit log data from Microsoft Purview and query for activities related to sensitivity labels: for example, SensitivityLabelRemoved, SensitivityLabelUpdated, SensitivityLabelPolicyMatched, and SensitivityLabelFileOpened.

    Then you can create a rule to generate an alert when a sensitivity label is changed. For instance, you can create a rule that triggers an alert when the SensitivityLabelUpdated activity is detected in the audit log.

    Here is a link to the Microsoft documentation that provides more information on the audit log record types and activities supported in Sentinel: https://docs.microsoft.com/azure/sentinel/microsoft-purview-record-types-activities

    Note that in Microsoft Purview, the Smart Alerts feature is coming to public preview soon, and this will allow you to get built-in alerts based on risky behavior.

    Alternatively, without using Microsoft Purview, you can create an alert policy based on user activity as described here, or check the Activity logs.

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar information.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.