Configure encryption with sensitivity labels

As the global consulting firm continues strengthening its data protection efforts, they now focus on using encryption settings within sensitivity labels. This allows them to:

  • Control who can access sensitive content, even when it’s shared or stored outside the organization.
  • Define editing rights and expiration dates for highly confidential documents.
  • Protect Teams meetings, emails, and files without relying on manual encryption steps.

Administrators can either assign permissions during label configuration or let users define access when applying labels, depending on the use case.

How encryption works with sensitivity labels

Sensitivity labels use the Azure Rights Management service (Azure RMS) to enforce encryption. This ensures that content stays protected through encryption, identity verification, and policy enforcement.

Labels that apply to Teams meetings use a separate encryption method tailored to protect real-time audio and video streams.

Prerequisites

Before enabling encryption with sensitivity labels, ensure:

  • Azure Information Protection is activated in your tenant.
  • Network configurations and Microsoft Entra ID support encrypted content access.
  • Exchange is configured for Azure Information Protection to enable email and calendar invite encryption.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *