Summary

Completed

In this module, you classify Relecloud's Woodgrove Bank data with the right Microsoft Purview technique, scope and publish sensitivity labels, then verify that classification, labeling, and Microsoft 365 Copilot grounding all work the way you specified.

What you learned

  • Sensitive information types detect predictable patterns, exact data match confirms values against a fixed list with the fewest false positives, and trainable classifiers recognize free-form content that fits neither approach—and SITs, trainable classifiers, EDM, and document fingerprinting can all drive auto-labeling.
  • An item scope (Files & other data assets, Emails, or Meetings) protects content itself wherever it travels, while the Groups & sites scope protects a collaboration space and requires container labeling turned on tenant-wide before you can configure it.
  • A user under more than one label policy sees the union of every published label, but conflicting settings never merge—only the highest-priority policy's setting applies, and label-policy priority is separate from label-list priority.
  • Content explorer confirms what's classified right now, Activity explorer shows how that classification changes over 30 days of activity, and viewing the tab versus viewing its contents requires two separate tiers of permission.
  • Microsoft 365 Copilot respects the usage rights and highest-priority label a user already holds, but Double Key Encryption blocks Copilot outright, and Teams meeting chat and container-scoped labels each leave a gap Copilot doesn't close.

Learn more