|
1 | 1 | ---
|
2 |
| -title: Control external access to resources in Azure Active Directory with sensitivity labels. |
3 |
| -description: Use sensitivity labels as a part of your overall security plan for external access. |
| 2 | +title: Control external access to resources in Azure Active Directory with sensitivity labels |
| 3 | +description: Use sensitivity labels as a part of your overall security plan for external access |
4 | 4 | services: active-directory
|
5 | 5 | author: janicericketts
|
6 | 6 | manager: martinco
|
7 | 7 | ms.service: active-directory
|
8 | 8 | ms.workload: identity
|
9 | 9 | ms.subservice: fundamentals
|
10 | 10 | ms.topic: conceptual
|
11 |
| -ms.date: 08/19/2022 |
| 11 | +ms.date: 02/01/2023 |
12 | 12 | ms.author: jricketts
|
13 | 13 | ms.reviewer: ajburnle
|
14 | 14 | ms.custom: "it-pro, seodec18"
|
15 | 15 | ms.collection: M365-identity-device-management
|
16 | 16 | ---
|
17 | 17 |
|
18 |
| -# Control access with sensitivity labels |
| 18 | +# Control external access to resources in Azure Active Directory with sensitivity labels |
19 | 19 |
|
20 |
| -[Sensitivity labels](/microsoft-365/compliance/sensitivity-labels) help you control access to your content in Office 365 applications, and in containers like Microsoft Teams, Microsoft 365 Groups, and SharePoint sites. They can protect your content without hindering your users’ collaboration and production abilities. Sensitivity labels allow you to send your organization’s content across devices, apps, and services, while protecting your data and meeting your compliance and security policies. |
21 |
| - |
22 |
| -With sensitivity labels you can: |
23 |
| - |
24 |
| -* **Classify content without adding any protection settings**. You can assign a classification to content (like a sticker) that persists and roams with your content as it’s used and shared. You can use this classification to generate usage reports and see activity data for your sensitive content. |
25 |
| - |
26 |
| -* **Enforce protection settings such as encryption, watermarks, and access restrictions**. For example, users can apply a Confidential label to a document or email, and that label can [encrypt the content](/microsoft-365/compliance/encryption-sensitivity-labels) and add a “Confidential” watermark. In addition, you can [apply a sensitivity label to a container](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites) like a SharePoint site, and enforce whether external users can access the content it contains. |
27 |
| - |
28 |
| -Sensitivity labels on email and other content travel with the content. Sensitivity labels on containers can restrict access to the container, but content in the container doesn't inherit the label. For example, a user could take content from a protected site, download it, and then share it without restrictions unless the content also had a sensitivity label. |
29 |
| - |
30 |
| - >[!NOTE] |
31 |
| ->To apply sensitivity labels users must be signed into their Microsoft work or school account. |
32 |
| -
|
33 |
| -## Permissions necessary to create and manage sensitivity levels |
34 |
| - |
35 |
| -Members of your compliance team who will create sensitivity labels need permissions to the Microsoft 365 Defender portal, Microsoft Purview compliance portal, or Office 365 Security & Compliance Center. |
36 |
| - |
37 |
| -By default, global administrators for your tenant have access to these admin centers and can give compliance officers and other people access, without giving them all the permissions of a tenant admin. For this delegated limited admin access, add users to the Compliance Data Administrator, Compliance Administrator, or Security Administrator role group. |
38 |
| - |
39 |
| -## Determine your sensitivity label strategy |
| 20 | +Use sensitivity labels to help control access to your content in Office 365 applications, and in containers like Microsoft Teams, Microsoft 365 Groups, and SharePoint sites. They protect content without hindering user collaboration. Use sensitivity labels to send organization-wide content across devices, apps, and services, while protecting data. Sensitivity labels help organizations meet compliance and security policies. |
| 21 | + |
| 22 | +See, [Learn about sensitivity labels](/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide&preserve-view=true) |
40 | 23 |
|
41 |
| -As you think about governing external access to your content, determine the following: |
| 24 | +## Assign classification and enforce protection settings |
42 | 25 |
|
43 |
| -**For all content and containers** |
| 26 | +You can classify content without adding any protection settings. Content classification assignment stays with the content while it’s used and shared. The classification generates usage reports with sensitive-content activity data. |
44 | 27 |
|
45 |
| -* How will you define what is High, Medium, or Low Business Impact (HBI, MBI, LBI)? Consider the impact to your organization if specific types of content are shared inappropriately. |
| 28 | +Enforce protection settings such as encryption, watermarks, and access restrictions. For example, users apply a Confidential label to a document or email. The label can encrypt the content and add a Confidential watermark. In addition, you can apply a sensitivity label to a container like a SharePoint site, and help manage external users access. |
46 | 29 |
|
47 |
| - * Content with specific types of inherently [sensitive content](/microsoft-365/compliance/apply-sensitivity-label-automatically), such as credit cards or passport numbers |
| 30 | +Learn more: |
48 | 31 |
|
49 |
| - * Content created by specific groups or people (for example, compliance officers, financial officers, or executives) |
| 32 | +* [Restrict access to content by using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels?view=o365-worldwide&preserve-view=true) |
| 33 | +* [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites) |
50 | 34 |
|
51 |
| - * Content in specific libraries or sites. For example, containers hosting organizational strategy or private financial data |
| 35 | +Sensitivity labels on containers can restrict access to the container, but content in the container doesn't inherit the label. For example, a user takes content from a protected site, downloads it, and then shares it without restrictions, unless the content had a sensitivity label. |
52 | 36 |
|
53 |
| - * Other criteria |
| 37 | + >[!NOTE] |
| 38 | +>To apply sensitivity labels users sign into their Microsoft work or school account. |
54 | 39 |
|
55 |
| -* What categories of content (for example HBI content) should be restricted from access by external users? |
| 40 | +## Permissions to create and manage sensitivity levels |
56 | 41 |
|
57 |
| - * Restrictions can include actions like restricting access to containers, and encrypting content. |
| 42 | +Team members who need to create sensitivity labels require permissions to: |
58 | 43 |
|
59 |
| -* What defaults should be in place for HBI data, sites, or Microsoft 365 Groups? |
| 44 | +* Microsoft 365 Defender portal, |
| 45 | +* Microsoft Purview compliance portal, or |
| 46 | +* [Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center?view=o365-worldwide&preserve-view=true) |
60 | 47 |
|
61 |
| -* Where will you use sensitivity labels to [label and monitor](/microsoft-365/compliance/sensitivity-labels), versus to [enforce encryption](/microsoft-365/compliance/encryption-sensitivity-labels) or to [enforce container access restrictions](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)? |
| 48 | +By default, tenant Global Administrators have access to admin centers and can provide access, without granting tenant Admin permissions. For this delegated limited admin access, add users to the following role groups: |
62 | 49 |
|
63 |
| -**For email and content** |
| 50 | +* Compliance Data Administrator, |
| 51 | +* Compliance Administrator, or |
| 52 | +* Security Administrator |
64 | 53 |
|
65 |
| -* Do you want to [automatically apply sensitivity labels](/microsoft-365/compliance/apply-sensitivity-label-automatically) to content, or do so manually? |
| 54 | +## Sensitivity label strategy |
66 | 55 |
|
67 |
| - * If you choose to do so manually, do you want to [recommend that users apply a label](/microsoft-365/compliance/apply-sensitivity-label-automatically)? |
| 56 | +As you plan the governance of external access to your content, consider content, containers, email, and more. |
68 | 57 |
|
69 |
| -**For containers** |
| 58 | +### High, Medium, or Low Business Impact |
70 | 59 |
|
71 |
| -* What criteria will determine if M365 Groups, Teams, or SharePoint sites require access to be restricted by using sensitivity labels? |
| 60 | +To define High, Medium, or Low Business Impact (HBI, MBI, LBI) for data, sites, and groups, consider the effect on your organization if the wrong content types are shared. |
72 | 61 |
|
73 |
| -* Do you want to only label content in these containers moving forward, or do you want to [automatically label](/microsoft-365/compliance/apply-sensitivity-label-automatically) existing files in SharePoint and OneDrive? |
| 62 | +* Credit card, passport, national-ID numbers |
| 63 | + * [Apply a sensitivity label to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide&preserve-view=true) |
| 64 | +* Content created by corporate officers: compliance, finance, executive, etc. |
| 65 | +* Strategic or financial data in libraries or sites. |
74 | 66 |
|
75 |
| -See these [common scenarios for sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels) for other ideas on how you can use sensitivity labels. |
| 67 | +Consider the content categories that external users can't have access to, such as containers and encrypted content. You can use sensitivity labels, enforce encryption, or use container access restrictions. |
76 | 68 |
|
77 |
| -### Sensitivity labels on email and content |
| 69 | +### Email and content |
78 | 70 |
|
79 |
| -When you assign a sensitivity label to a document or email, it's like a stamp that's applied to content that is customizable, clear text, and persistent. |
| 71 | +Sensitivity labels can be applied automatically or manually to content. |
80 | 72 |
|
81 |
| -* **Customizable** means you can create labels appropriate for your organization and determine what happens when they're applied. |
| 73 | +See, [Apply a sensitivity label to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide&preserve-view=true) |
82 | 74 |
|
83 |
| -* **Clear text** means it’s a part of the item’s metadata and is readable by applications and services so that they can apply their own protective actions. |
| 75 | +#### Sensitivity labels on email and content |
84 | 76 |
|
85 |
| -* **Persistent** means the label and any associated protections roam with the content, and become the basis for applying and enforcing policies. |
| 77 | +A sensitivity label in a document or email is customizable, clear text, and persistent. |
86 | 78 |
|
87 |
| - |
| 79 | +* **Customizable** - create labels for your organization and determine the resulting actions |
| 80 | +* **Clear text** - is incorporated in metadata and readable by applications and services |
| 81 | +* **Persistency** - ensures the label and associated protections stay with the content, and help enforce policies |
88 | 82 |
|
89 | 83 | > [!NOTE]
|
90 |
| -> Each item of content can have a single sensitivity label applied to it. |
91 |
| -
|
92 |
| - |
93 |
| -### Sensitivity labels on containers |
94 |
| - |
95 |
| -You can apply sensitivity labels on containers such as [Microsoft 365 Groups](../enterprise-users/groups-assign-sensitivity-labels.md), [Microsoft Teams](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites), and [SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites). When you apply this sensitivity label to a supported container, the label automatically applies the classification and protection settings to the connected site or group. Sensitivity labels on these containers can control the following aspects of containers: |
96 |
| - |
97 |
| -* **Privacy**. You can choose who can see the site: specific users, all internal users, or anyone. |
| 84 | +> Each content item can have one sensitivity label applied. |
98 | 85 |
|
99 |
| -* **External user access**. Controls whether the group owner can add guests to the group. |
| 86 | +### Containers |
100 | 87 |
|
101 |
| -* **Access from unmanaged devices**. Determines if and how unmanaged devices can access content. |
102 |
| - |
103 |
| - |
104 |
| - |
105 |
| - |
106 |
| - |
107 |
| - |
| 88 | +Determine the access criteria if Microsoft 365 Groups, Teams, or SharePoint sites are restricted with sensitivity labels. You can label content in containers or use automatic labeling for files in SharePoint, OneDrive, etc. |
108 | 89 |
|
109 |
| -When you apply a sensitivity label to a container such as a SharePoint site, it is not applied to content there: sensitivity labels on containers control access to the content within the container. |
| 90 | +Learn more: [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide&preserve-view=true) |
110 | 91 |
|
111 |
| -* If you want to automatically apply labels to the content within the container, see [Apply a sensitivity to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically). |
| 92 | +#### Sensitivity labels on containers |
112 | 93 |
|
113 |
| -* If you want users to be able to manually apply labels to this content, be sure that you‘ve [enabled sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files). |
| 94 | +You can apply sensitivity labels to containers such as Microsoft 365 Groups, Microsoft Teams, and SharePoint sites. Sensitivity labels on a supported container apply the classification and protection settings to the connected site or group. Sensitivity labels on these containers can control: |
114 | 95 |
|
115 |
| -### Plan to implement sensitivity labels |
| 96 | +* **Privacy** - select the users who can see the site |
| 97 | +* **External user access** - determine if group owners can add guests to a group |
| 98 | +* **Access from unmanaged devices** - decide if and how unmanaged devices access content |
116 | 99 |
|
117 |
| -Once you have determined how you want to use sensitivity labels, and to what content and sites you want to apply them, see the following documentation to help you perform your implementation. |
| 100 | +  |
118 | 101 |
|
119 |
| -1. [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels) |
| 102 | +Sensitivity labels applied to a container, such as a SharePoint site, aren't applied to content in the container; they control access to content in the container. Labels can be applied automatically to the content in the container. For users to manually apply labels to content, enable sensitivity labels for Office files in SharePoint and OneDrive. |
120 | 103 |
|
121 |
| -2. [Create a deployment strategy](/microsoft-365/compliance/get-started-with-sensitivity-labels) |
| 104 | +Learn more: |
122 | 105 |
|
123 |
| -3. [Create and publish sensitivity labels](/microsoft-365/compliance/create-sensitivity-labels) |
| 106 | +* [Enable sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files?view=o365-worldwide&preserve-view=true). |
| 107 | +* [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites) |
| 108 | +* [Assign sensitivity labels to Microsoft 365 groups in Azure AD](../enterprise-users/groups-assign-sensitivity-labels.md) |
124 | 109 |
|
125 |
| -4. [Restrict access to content using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels) |
| 110 | +### Implement sensitivity labels |
126 | 111 |
|
127 |
| -5. [Use sensitivity labels with teams, groups, and sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites) |
| 112 | +After you determine use of sensitivity labels, see the following documentation for implementation. |
128 | 113 |
|
129 |
| -6. [Enable sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files) |
| 114 | +* [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide&preserve-view=true) |
| 115 | +* [Create and publish sensitivity labels](/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide&preserve-view=true) |
| 116 | +* [Restrict access to content by using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels?view=o365-worldwide&preserve-view=true) |
130 | 117 |
|
131 |
| -### Next steps |
| 118 | +## Next steps |
132 | 119 |
|
133 |
| -See the following articles on securing external access to resources. We recommend you take the actions in the listed order. |
| 120 | +See the following articles to learn more about securing external access to resources. We recommend you follow the listed order. |
134 | 121 |
|
135 |
| -1. [Determine your desired security posture for external access](1-secure-access-posture.md) |
| 122 | +1. [Determine your security posture for external access](1-secure-access-posture.md) |
136 | 123 |
|
137 |
| -2. [Discover your current state](2-secure-access-current-state.md) |
| 124 | +2. [Discover the current state of external collaboration in your organization](2-secure-access-current-state.md) |
138 | 125 |
|
139 |
| -3. [Create a governance plan](3-secure-access-plan.md) |
| 126 | +3. [Create a security plan for external access](3-secure-access-plan.md) |
140 | 127 |
|
141 |
| -4. [Use groups for security](4-secure-access-groups.md) |
| 128 | +4. [Secure external access with groups in Azure AD and Microsoft 365](4-secure-access-groups.md) |
142 | 129 |
|
143 |
| -5. [Transition to Azure AD B2B](5-secure-access-b2b.md) |
| 130 | +5. [Transition to governed collaboration with Azure AD B2B collaboration](5-secure-access-b2b.md) |
144 | 131 |
|
145 |
| -6. [Secure access with Entitlement Management](6-secure-access-entitlement-managment.md) |
| 132 | +6. [Manage external access with Azure AD entitlement management](6-secure-access-entitlement-managment.md) |
146 | 133 |
|
147 |
| -7. [Secure access with Conditional Access policies](7-secure-access-conditional-access.md) |
| 134 | +7. [Manage external access with Conditional Access policies](7-secure-access-conditional-access.md) |
148 | 135 |
|
149 |
| -8. [Secure access with Sensitivity labels](8-secure-access-sensitivity-labels.md) (You are here.) |
| 136 | +8. [Control external access to resources in Azure AD with sensitivity labels](8-secure-access-sensitivity-labels.md) (You're here) |
150 | 137 |
|
151 |
| -9. [Secure access to Microsoft Teams, OneDrive, and SharePoint](9-secure-access-teams-sharepoint.md) |
| 138 | +9. [Secure external access to Microsoft Teams, SharePoint, and OneDrive for Business](9-secure-access-teams-sharepoint.md) |
0 commit comments