Module 7 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: why protection should travel with the data, sensitivity labels and what they enforce, a three-label taxonomy for small businesses, DLP policies for Australian sensitive information, and a simulation-first rollout in the Purview portal.
Data Protection with Microsoft Purview
Protection that travels with the file
Everything in this pathway so far has been about guarding the building: who can sign in, which devices get through the door, where files are allowed to be shared from. That matters, and you have done the hard yards. But there is a catch. The moment a file leaves the building, all of those controls stay behind.
Someone attaches the client spreadsheet to an email. Someone copies the payroll file to a personal OneDrive to finish it over the weekend. None of it malicious, all of it perfectly ordinary, and every folder permission you set so carefully now protects an empty shelf.
This module flips the model. Instead of protecting the place a file lives, Microsoft Purview lets you attach the protection to the file itself, so it travels wherever the file goes. Two tools do the work: sensitivity labels, which classify and protect the data, and data loss prevention (DLP), which watches for sensitive information heading out the door and steps in.
A locked filing cabinet is wonderful security right up until someone photocopies the file and posts it. A sensitivity label is more like sealing the document in an envelope only the right people can open. Copy it, email it, lose the laptop it sits on, and the envelope is still sealed.
A sensitivity label is a classification you attach to an email, document, or meeting invite: Public, Internal, Confidential, whatever names you choose. On its own it is just a tag. The power comes from the protection settings you bolt onto each label, which Purview then enforces automatically wherever the content goes.
Here is what a label can enforce the moment it is applied.
The label encrypts the file or email so only the people you choose can open it. Forward a Confidential email to the wrong address and the recipient gets a locked door, not your numbers.
Watermarks, headers, and footers stamped onto documents automatically. Everyone who opens the file sees CONFIDENTIAL across the page, which quietly changes how they treat it.
Decide who can do what: view only, edit, print, forward, and for how long. You can even let a partner firm read a document without being able to copy a word of it.
Who applies the label?
Labels get onto content one of two ways, and the difference matters for your licence tier.
People pick the label themselves
Users choose a label from a dropdown in Word, Excel, PowerPoint, and Outlook. Simple, and it works well once your label names are obvious. Included with Microsoft 365 Business Premium, E3, and E5.
- Included in Business Premium, E3, and E5
- A default label can apply automatically to everything new
- Works in Office apps on desktop, web, and mobile
- Relies on people choosing well, so keep the names plain
Purview picks the label for them
Purview spots sensitive content (say, a document full of tax file numbers) and applies or recommends the right label on its own. Powerful at scale, but it needs Microsoft 365 E5 or the equivalent Purview add-on licensing.
- Requires E5 or equivalent Purview add-ons
- Can recommend a label or apply it silently
- Catches the files people forget to label
- Worth revisiting once manual labelling is habit
Here is where label projects live or die. A label set designed by a committee ends up with eleven options, nobody can tell Restricted from Sensitive from Official, and everyone quietly picks the top one and moves on. The fix is discipline: three to five labels with names a new hire understands on day one.
Microsoft's own default set (Public, General, Confidential, Highly Confidential) is a solid starting point. For most small businesses we trim it to three. Climb the ladder only when the data genuinely needs it.
Lives here: Marketing brochures, price lists, anything already on your website.
The label enforces: No restrictions. The label mostly exists so people have a home for the harmless stuff.
Lives here: Meeting notes, procedures, rosters, most of the everyday paperwork.
The label enforces: A footer marking the document Internal. Make this the default label so unlabelled files stop existing.
Lives here: Payroll, client financials, contracts, anything with TFNs or bank details.
The label enforces: Encryption so only your staff can open it, plus a CONFIDENTIAL watermark. Forwarded outside, it stays locked.
Rules of thumb for a taxonomy that sticks
- Three to five labels, never more. If you need an eleven-label scheme, you are probably a government department, and there is a whole framework for you.
- Name labels for the audience, not the bureaucracy. Public, Internal, and Confidential explain themselves; Tier 2 Restricted does not.
- Set Internal as the default label so every new document starts classified, and people only think about it when something is genuinely public or genuinely sensitive.
- If you need a fourth label, a Confidential sub-label for specific people only (board papers, salary reviews) earns its keep. That is usually the ceiling.
Purview treats the label list as a ranking, lowest sensitivity at the top and highest at the bottom. Set yours up in that order from the start, because it drives warnings when someone downgrades a label, and re-shuffling later is a job you will not enjoy.
Labels rely on classification. Data loss prevention is the backstop for the day classification fails: the unlabelled spreadsheet, the TFN pasted straight into an email, the export nobody thought twice about. A DLP policy inspects content as it moves through Exchange email, SharePoint, OneDrive, and Teams messages, looking for patterns of sensitive information, and acts before it leaves.
The patterns are called sensitive information types, and Microsoft ships hundreds of them ready to use, including a proper Australian set. These are not dumb keyword searches; the tax file number type, for example, checks the digits against the actual TFN checksum before it fires.
Microsoft also bundles these into ready-made Australian policy templates, including Australia Privacy Act and Australia Financial Data, so you rarely start from scratch.
What happens on a match: the escalation ladder
When a policy finds something, you choose how firm the response is. The trick is to start soft and only climb when the audit data says you should.
Nothing is blocked. DLP quietly records every match so you can see the real picture first.
The user sees a gentle warning in Outlook or Teams before they hit send. Most incidents end right here.
The action is stopped, but the user can proceed with a business reason. You review the reasons later.
The email or share simply does not go. Reserved for the matches you never want leaving, full stop.
A tip that says "this email appears to contain a tax file number" at the moment someone hits send teaches better than any annual training slide ever will. It catches the honest mistake, which in our experience is nearly all of them, without making anyone feel like a suspect.
Everything here happens in the Microsoft Purview portal at purview.microsoft.com. Do labels first, then DLP, and resist the urge to switch anything to blocking mode in week one. The businesses that succeed with Purview are the ones that watch before they enforce.
- 1Sign in to the Microsoft Purview portal at purview.microsoft.com and open the Information Protection solution.
- 2Under Sensitivity labels, start from Microsoft's default label set or create your own three-label taxonomy from the previous unit.
- 3Configure each label's protection: markings only for Internal, encryption plus a watermark for Confidential.
- 4Publish the labels with a label policy to a small pilot group first, and set Internal as the default label.
- 5Once the pilot is comfortable, publish to everyone and show the team the dropdown in Word and Outlook.
- 1In the Purview portal, open Data Loss Prevention, then Policies, and create a new policy.
- 2Pick an Australian template such as Australia Financial Data, which covers TFNs, bank details, and credit cards out of the box.
- 3Choose the locations to watch: Exchange email, SharePoint sites, and OneDrive accounts (add Teams messages if your licensing covers it).
- 4At the final step, choose Run the policy in simulation mode. Nothing is enforced; matches land in a dashboard for you to review.
- 5After a week or two, review the matches, tune out the false positives, then re-run simulation with policy tips switched on.
- 6Only when the results look right, turn the policy on, starting with audit or block-with-override rather than a hard block.
Simulations can run for up to 15 days, so give them time to see a real fortnight of business. A policy that goes straight to blocking on day one mostly teaches people creative ways around it.
Sensitivity labels and DLP are not in the cheap seats. Manual labelling and DLP for email, SharePoint, and OneDrive come with Microsoft 365 Business Premium, E3, and E5. Auto-labelling, DLP for Teams messages, and DLP on devices need E5 or the equivalent Purview add-ons. On Business Basic or Standard, this module is a reason to upgrade, and Business Premium is usually the sensible landing spot for a small business.
- Microsoft Learn: Learn about sensitivity labels
- Microsoft Learn: Default sensitivity labels and policies to protect your data
- Microsoft Learn: Learn about data loss prevention
- Microsoft Learn: Create and deploy data loss prevention policies
- Microsoft Learn: Sensitive information type entity definitions
Capabilities and licensing were current at the time of writing (July 2026). Microsoft occasionally moves things around the Purview portal and shuffles what sits in which plan, so double-check before you buy.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Why do sensitivity labels beat folder permissions for protecting sensitive data?
2. Which of these can a sensitivity label enforce on a document?
3. What does a good SMB label taxonomy look like?
4. You have just built your first DLP policy. What is the smart first move?
5. Which licence tier gives a small business manual sensitivity labels plus DLP for email, SharePoint, and OneDrive?