MC1477181 - Microsoft Purview | Information Protection: Apply default SharePoint library sensitivity labels to data at rest

Microsoft 365 Message Center announcement MC1477181.

MS Message Center's Summary

Microsoft Purview is introducing an optional auto labeling policy in October 2026 that applies default SharePoint document library sensitivity labels to existing historical files without requiring user action. Administrators should review current library configurations and verify that labels are published before enabling this feature for up to 10 SharePoint sites per tenant.

Administrator impact
Administrators must configure the opt in policy and ensure they hold the Compliance Administrator or SharePoint Administrator role.
End user impact
Existing files in selected libraries receive default sensitivity labels automatically without requiring users to open or edit documents.
Importance
4/10: This is a targeted opt in feature that improves information protection coverage for historical SharePoint files.

Automatically apply a sensitivity label to Microsoft 365 data

Microsoft Summary

Microsoft Purview will enable an auto-labeling policy to apply default SharePoint library sensitivity labels to existing files, improving labeling coverage without user action. This opt-in feature, rolling out in October 2026, requires administrator configuration and supports up to 10 SharePoint sites per policy.

Message Center ID
MC1477181
Category
stay Informed
Severity
normal
Services
Microsoft 365 suite, Microsoft Purview
Tags
New feature, User impact, Admin impact
Roadmap ID
559105
Platforms
Web
Published
2026-09-22
Last updated
2026-09-22
Expires
2026-11-19

[What and why] Microsoft Purview is introducing a new auto-labeling policy that applies a SharePoint document library's default sensitivity label to existing files stored in that library. Previously, default library sensitivity labels were applied only to new or modified files. With this update, organizations can extend labeling to historical content, including files that existed before the default library sensitivity label was configured for the site, without requiring users to open or edit files and without creating content inspection rules. This capability helps improve labeling coverage, reduce the number of unlabeled files, and support information protection objectives across existing SharePoint content. [Rollout schedule] General Availability (Worldwide): Beginning in early October 2026 and expected to complete by mid-October 2026 [Impact on your organization] Who is affected Microsoft Purview administrators who manage sensitivity labels and auto-labeling policies Organizations using SharePoint document libraries with default sensitivity labels configured Users are affected only if administrators enable and configure this new policy Platforms and services Microsoft Purview Information Protection Microsoft Purview Auto-labeling SharePoint Online What will happen After an administrator creates and enables this policy: Auto-labeling will evaluate existing files in selected SharePoint document libraries. Files that do not have a sensitivity label applied will receive the library's default sensitivity label. Files that existed in a library before the default sensitivity label was configured can now be labeled automatically. Files that have a lower-priority sensitivity label applied may be upgraded to the library's default sensitivity label (depending on the policy setting). Users are not required to open or edit files for labeling to occur. Content inspection conditions, such as sensitive information types or trainable classifiers, are not required for this policy. Labeling occurs as a background service process and is not immediate. The same default sensitivity label already applied to new or modified files in the library is used for existing files. The feature is opt-in and requires administrator configuration. The following limits apply: One policy of this type can be configured per tenant. A maximum of 10 SharePoint sites can be included in a policy. The user configuring the policy must have either the Compliance Administrator or SharePoint Administrator role so the policy can read the default SharePoint library label. [Action required and recommendations] No action is required unless your organization plans to use this capability. If you intend to use this feature: Review SharePoint document libraries and identify those that have a default sensitivity label configured. Verify that the required sensitivity labels have been published to users before configuring the policy. Update internal information protection guidance, if applicable. Learn more: Automatically apply a sensitivity label to Microsoft 365 data | Microsoft Learn [Compliance considerations] Question Answer Does the change alter how existing customer data is processed, stored, or accessed? Yes. Existing SharePoint files can be evaluated and automatically assigned the library's default sensitivity label. Does the change modify Information Protection labels or sensitive information types? No Does the change include an admin control and can it be controlled through Entra ID group membership? Yes. Administrators must create and enable the auto-labeling policy for the capability to take effect.