Summary
In this module, you classify Relecloud's Woodgrove Bank data with the right Microsoft Purview technique, scope and publish sensitivity labels, then verify that classification, labeling, and Microsoft 365 Copilot grounding all work the way you specified.
What you learned
- Sensitive information types detect predictable patterns, exact data match confirms values against a fixed list with the fewest false positives, and trainable classifiers recognize free-form content that fits neither approach—and SITs, trainable classifiers, EDM, and document fingerprinting can all drive auto-labeling.
- An item scope (Files & other data assets, Emails, or Meetings) protects content itself wherever it travels, while the Groups & sites scope protects a collaboration space and requires container labeling turned on tenant-wide before you can configure it.
- A user under more than one label policy sees the union of every published label, but conflicting settings never merge—only the highest-priority policy's setting applies, and label-policy priority is separate from label-list priority.
- Content explorer confirms what's classified right now, Activity explorer shows how that classification changes over 30 days of activity, and viewing the tab versus viewing its contents requires two separate tiers of permission.
- Microsoft 365 Copilot respects the usage rights and highest-priority label a user already holds, but Double Key Encryption blocks Copilot outright, and Teams meeting chat and container-scoped labels each leave a gap Copilot doesn't close.
Learn more
- Learn about sensitive information types
- Learn about exact data match based sensitive information types
- Get started with sensitivity labels
- Use sensitivity labels to protect collaborative workspaces (groups and sites)
- Learn about sensitivity labels
- Get started with Content Explorer
- Considerations to manage Microsoft 365 Copilot and Channel Agent in Teams for security and compliance