Exercise - Configure and publish a sensitivity label policy, then verify priority resolution
You've specified that Woodgrove Bank's transaction records need item-level protection, published to the finance team through a label policy that requires mandatory labeling and a sensible default label. Before rollout, you also need to confirm those settings still resolve as intended once a second, lower-priority policy is introduced for a broader audience.
Important
Prerequisites for this exercise:
- Access to a Microsoft 365 E5 tenant with permissions to create sensitivity labels and label policies in the Microsoft Purview portal.
- Two test groups: one representing the finance team (narrow scope) and one representing a broader audience (for example, all employees).
If your lab tenant already has sensitivity labels published, create a new label specifically for this exercise so you don't disturb existing policies.
Task 1: Create an item-scoped sensitivity label with protection
- Sign in to the Microsoft Purview portal at purview.microsoft.com, then go to Information protection > Sensitivity labels > Create a label.
- Name it
Woodgrove Confidential – Transaction Records, scope it to Files & other data assets (not Groups & sites or Meetings), and select Next. - Under Protection settings, choose Encrypt files and emails, assign permissions so only the finance team group and a designated admin can access protected content, and enable Content marking with a footer reading
Confidential – Woodgrove transaction data. - Review and create the label.
Task 2: Publish a label policy for the finance team
- Go to Information protection > Label policies > Publish labels.
- Select the label you just created, and choose the finance team group as the scope.
- On the policy settings step, turn on Users must provide a justification to remove a label or lower its classification, set Require users to apply a label to their email and documents to On (mandatory labeling), and set the default label to the label you created.
- Name the policy
Finance – Woodgrove transaction labelingand publish it.
Task 3: Introduce a lower-priority policy and verify resolution
- Create a second label policy—reuse an existing general-purpose label, or create a simple new one—and publish it scoped to the broader audience group, with mandatory labeling turned off and no default label set.
- In Label policies, confirm the finance-team policy shows a higher priority (lower priority number) than the broader-audience policy. If needed, drag the finance-team policy above the other in the priority list and save.
- For a test user who belongs to both the finance team group and the broader audience group, confirm in Word or Outlook that mandatory labeling is enforced and the default label is your Woodgrove transaction label—not the broader policy's settings.
- Reflect: when a user is in scope for multiple label policies, only the highest-priority policy's mandatory-labeling and default-label settings apply to them—the settings don't merge or average across policies. Confirming this now, before rollout, is exactly the verification step this module builds toward.
You've now configured an item-scoped, encrypted sensitivity label, published it to the finance team with mandatory labeling and a default, and verified it wins over a lower-priority policy for users in both scopes—Woodgrove's transaction records are protected the way you specified.