Introduction
Relecloud handles Woodgrove Bank's regulated financial and personal data across its Microsoft 365 tenant, and that data can't rely on labels that merely exist—it needs a classification scheme you specify and verify, so labels behave predictably and protect exactly what's intended, for both the people who handle the data and Microsoft 365 Copilot when it grounds a response in that content.
Consider a case that lands on your desk: Relecloud's finance team handles Woodgrove Bank's regulated transaction records and account data every day, records that can't go unlabeled or under-protected without anyone noticing. You set up two separate sensitivity label policies that both apply to that team, expecting them to reinforce each other—one requires a justification before someone removes a label, the other doesn't. When a user covered by both policies removes a label from a document, there's zero friction, no justification prompt at all. Which policy won, and why did the other one seem to just vanish?
What you'll learn
- Choose between sensitive information types (SITs), exact data match (EDM), and trainable classifiers based on whether the content is a predictable pattern, a fixed list, or free-form.
- Create sensitivity labels scoped to items (files, emails, meetings) or to containers (groups and sites), and configure the tenant setting each depends on.
- Publish sensitivity label policies to the right users and predict which policy wins when a user is covered by more than one.
- Verify classification results with Content explorer and Activity explorer before Copilot grounds responses in that labeled content.
- Recognize where Microsoft 365 Copilot respects labels and where it doesn't—including Double Key Encryption, Teams meeting chat, and container-scoped labels.
By the end of this module, you can specify, apply, and verify a Microsoft Purview classification and labeling scheme that protects Relecloud's regulated data consistently, for both people and Copilot.