Purview encryption

Rafana Fatima 0 Reputation points
2025-05-05T23:09:36.79+00:00

Hi Team,

I have a question if I configure Encryption for a label and users assign permissions who can access the files etc.

What happens to the file when the owner of the file leaves the organisation. Who will have full permissions on the file.

Thanks

Rafana

Microsoft Purview
Microsoft Purview
A Microsoft data governance service that helps manage and govern on-premises, multicloud, and software-as-a-service data. Previously known as Azure Purview.
1,583 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Gurram 7,020 Reputation points Microsoft External Staff Moderator
    2025-05-06T01:51:12.4466667+00:00

    @Rafana Fatima

    When you configure encryption for a sensitivity label and a user applies it to a file with assigned permissions, the access control is enforced by Microsoft Purview Information Protection (formerly AIP). If the owner of the file leaves the organization, access to the file depends on how permissions were configured:

    What happens when the owner leaves:

    The file remains protected by the label's encryption settings. If permissions were granted to specific users or groups, those users continue to have access. If only the departing user had full permissions, and no additional access was granted, others may not be able to access the file.

    Recommendations:

    "If the user who protected the content is no longer with your organization and no other user has rights to the content, you must use the super user feature to access the content." Source – Microsoft Learn: Rights Management super users

    Microsoft recommends using the Rights Management super user feature, which allows designated administrators to access all protected content, even if the original owner is no longer available.

    Best Practices:

    Assign access to groups instead of individuals whenever possible. Ensure the Rights Management super user role is configured for recovery and compliance scenarios.

    For more details refer: Source – Microsoft Learn: Rights Management super users

    Sensitivity label encryption for Australian Government compliance with PSPF

    Restrict access to content by using sensitivity labels to apply encryption

    I hope this information helps.

    Kindly consider upvoting the comment if the information provided is helpful. This can assist other community members in resolving similar issues. 

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.