User can't open file with label that is assigned to that user

Mark Sannuti (C-Admin) 130 Reputation points
2025-06-16T16:10:21.69+00:00

The user is able to use and open the labeled file using the , Sensitivity tabs and add those labels to a file (MS Word). The user can also open any Word document that is not labeled.

Issue is, when sending the user a labeled file that the user is assigned to via SharePoint share or Email he gets the error message (attached to this ticket). User is assigned in the Label policy and Sensitive Label policy, but is not able to open up the labeled file that the user is assigned to. Screen Shot 2025-06-04 at 11.31.40 AM.png

Microsoft Security | Microsoft Purview
{count} votes

Accepted answer
  1. Chandra Boorla 14,685 Reputation points Microsoft External Staff Moderator
    2025-06-16T19:13:07.7966667+00:00

    @Mark Sannuti (C-Admin)

    Thank you for reaching out and for providing the details.

    From your description, the user is able to apply and open sensitivity labels using the Word app (via the Sensitivity tab), and can open non-labeled documents without any issues. However, the user encounters an error when attempting to open a labeled file that was shared with them via SharePoint or email, even though they are included in both the Label policy and Sensitivity label policy.

    This issue is most likely related to how protection (encryption) permissions are configured in the label itself.

    Key clarification

    Being included in a sensitivity label policy allows a user to see and apply the label but does not automatically grant access to open files protected by that label. To open such a file, the user must be granted explicit access permissions (such as View or Edit) defined within the label’s encryption settings.

    Recommended checks:

    Review Label Encryption Settings - Please verify that the user (or a group they belong to) is included in the encryption configuration for the sensitivity label. You can check this via: Microsoft Purview compliance portal > Information Protection > Labels > [Label Name] > Encryption.
    Group Membership Validation - If permissions are granted through an Azure AD group, confirm that the user is a current member of that group and that group memberships are synced correctly.
    Policy Propagation Time - If the user was recently added to the label’s permission group, please allow up to 24 hours for the change to propagate. Signing out and back in, or restarting the device, can also help refresh permissions.
    Opening Method - Have the user try opening the file using Word Online (via Office.com) to rule out any client-side issues.
    Error Message Details - If the issue persists, kindly share the full error message or code shown, as that can provide more insight into the root cause.

    For more details, please refer to the following Microsoft documentation for useful insights.

    I hope this information helps. Please do let us know if you have any further queries.

    Kindly consider upvoting the comment if the information provided is helpful. This can assist other community members in resolving similar issues.

    Thank you.


1 additional answer

Sort by: Most helpful
  1. Mark Sannuti (C-Admin) 130 Reputation points
    2025-07-02T15:35:40.32+00:00

    Sorry about the screen shot...that was the wrong one. However, I went ahead and removed that user from all the policies and then added that user back to the policies and it seems to be working correctly. User is now able to view and download labeled files.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.