Skip to content

Commit 9bc471e

Browse files
authored
Merge pull request #225931 from v-edmckillop/patch-102
Update 8-secure-access-sensitivity-labels.md
2 parents 1326f8c + 45c6377 commit 9bc471e

File tree

1 file changed

+73
-86
lines changed

1 file changed

+73
-86
lines changed
Lines changed: 73 additions & 86 deletions
Original file line numberDiff line numberDiff line change
@@ -1,151 +1,138 @@
11
---
2-
title: Control external access to resources in Azure Active Directory with sensitivity labels.
3-
description: Use sensitivity labels as a part of your overall security plan for external access.
2+
title: Control external access to resources in Azure Active Directory with sensitivity labels
3+
description: Use sensitivity labels as a part of your overall security plan for external access
44
services: active-directory
55
author: janicericketts
66
manager: martinco
77
ms.service: active-directory
88
ms.workload: identity
99
ms.subservice: fundamentals
1010
ms.topic: conceptual
11-
ms.date: 08/19/2022
11+
ms.date: 02/01/2023
1212
ms.author: jricketts
1313
ms.reviewer: ajburnle
1414
ms.custom: "it-pro, seodec18"
1515
ms.collection: M365-identity-device-management
1616
---
1717

18-
# Control access with sensitivity labels
18+
# Control external access to resources in Azure Active Directory with sensitivity labels
1919

20-
[Sensitivity labels](/microsoft-365/compliance/sensitivity-labels) help you control access to your content in Office 365 applications, and in containers like Microsoft Teams, Microsoft 365 Groups, and SharePoint sites. They can protect your content without hindering your users’ collaboration and production abilities. Sensitivity labels allow you to send your organization’s content across devices, apps, and services, while protecting your data and meeting your compliance and security policies.
21-
22-
With sensitivity labels you can:
23-
24-
* **Classify content without adding any protection settings**. You can assign a classification to content (like a sticker) that persists and roams with your content as it’s used and shared. You can use this classification to generate usage reports and see activity data for your sensitive content.
25-
26-
* **Enforce protection settings such as encryption, watermarks, and access restrictions**. For example, users can apply a Confidential label to a document or email, and that label can [encrypt the content](/microsoft-365/compliance/encryption-sensitivity-labels) and add a “Confidential” watermark. In addition, you can [apply a sensitivity label to a container](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites) like a SharePoint site, and enforce whether external users can access the content it contains.
27-
28-
Sensitivity labels on email and other content travel with the content. Sensitivity labels on containers can restrict access to the container, but content in the container doesn't inherit the label. For example, a user could take content from a protected site, download it, and then share it without restrictions unless the content also had a sensitivity label.
29-
30-
>[!NOTE]
31-
>To apply sensitivity labels users must be signed into their Microsoft work or school account.
32-
33-
## Permissions necessary to create and manage sensitivity levels
34-
35-
Members of your compliance team who will create sensitivity labels need permissions to the Microsoft 365 Defender portal, Microsoft Purview compliance portal, or Office 365 Security & Compliance Center.
36-
37-
By default, global administrators for your tenant have access to these admin centers and can give compliance officers and other people access, without giving them all the permissions of a tenant admin. For this delegated limited admin access, add users to the Compliance Data Administrator, Compliance Administrator, or Security Administrator role group.
38-
39-
## Determine your sensitivity label strategy
20+
Use sensitivity labels to help control access to your content in Office 365 applications, and in containers like Microsoft Teams, Microsoft 365 Groups, and SharePoint sites. They protect content without hindering user collaboration. Use sensitivity labels to send organization-wide content across devices, apps, and services, while protecting data. Sensitivity labels help organizations meet compliance and security policies.
21+
22+
See, [Learn about sensitivity labels](/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide&preserve-view=true)
4023

41-
As you think about governing external access to your content, determine the following:
24+
## Assign classification and enforce protection settings
4225

43-
**For all content and containers**
26+
You can classify content without adding any protection settings. Content classification assignment stays with the content while it’s used and shared. The classification generates usage reports with sensitive-content activity data.
4427

45-
* How will you define what is High, Medium, or Low Business Impact (HBI, MBI, LBI)? Consider the impact to your organization if specific types of content are shared inappropriately.
28+
Enforce protection settings such as encryption, watermarks, and access restrictions. For example, users apply a Confidential label to a document or email. The label can encrypt the content and add a Confidential watermark. In addition, you can apply a sensitivity label to a container like a SharePoint site, and help manage external users access.
4629

47-
* Content with specific types of inherently [sensitive content](/microsoft-365/compliance/apply-sensitivity-label-automatically), such as credit cards or passport numbers
30+
Learn more:
4831

49-
* Content created by specific groups or people (for example, compliance officers, financial officers, or executives)
32+
* [Restrict access to content by using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels?view=o365-worldwide&preserve-view=true)
33+
* [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)
5034

51-
* Content in specific libraries or sites. For example, containers hosting organizational strategy or private financial data
35+
Sensitivity labels on containers can restrict access to the container, but content in the container doesn't inherit the label. For example, a user takes content from a protected site, downloads it, and then shares it without restrictions, unless the content had a sensitivity label.
5236

53-
* Other criteria
37+
>[!NOTE]
38+
>To apply sensitivity labels users sign into their Microsoft work or school account.
5439
55-
* What categories of content (for example HBI content) should be restricted from access by external users?
40+
## Permissions to create and manage sensitivity levels
5641

57-
* Restrictions can include actions like restricting access to containers, and encrypting content.
42+
Team members who need to create sensitivity labels require permissions to:
5843

59-
* What defaults should be in place for HBI data, sites, or Microsoft 365 Groups?
44+
* Microsoft 365 Defender portal,
45+
* Microsoft Purview compliance portal, or
46+
* [Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center?view=o365-worldwide&preserve-view=true)
6047

61-
* Where will you use sensitivity labels to [label and monitor](/microsoft-365/compliance/sensitivity-labels), versus to [enforce encryption](/microsoft-365/compliance/encryption-sensitivity-labels) or to [enforce container access restrictions](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)?
48+
By default, tenant Global Administrators have access to admin centers and can provide access, without granting tenant Admin permissions. For this delegated limited admin access, add users to the following role groups:
6249

63-
**For email and content**
50+
* Compliance Data Administrator,
51+
* Compliance Administrator, or
52+
* Security Administrator
6453

65-
* Do you want to [automatically apply sensitivity labels](/microsoft-365/compliance/apply-sensitivity-label-automatically) to content, or do so manually?
54+
## Sensitivity label strategy
6655

67-
* If you choose to do so manually, do you want to [recommend that users apply a label](/microsoft-365/compliance/apply-sensitivity-label-automatically)?
56+
As you plan the governance of external access to your content, consider content, containers, email, and more.
6857

69-
**For containers**
58+
### High, Medium, or Low Business Impact
7059

71-
* What criteria will determine if M365 Groups, Teams, or SharePoint sites require access to be restricted by using sensitivity labels?
60+
To define High, Medium, or Low Business Impact (HBI, MBI, LBI) for data, sites, and groups, consider the effect on your organization if the wrong content types are shared.
7261

73-
* Do you want to only label content in these containers moving forward, or do you want to [automatically label](/microsoft-365/compliance/apply-sensitivity-label-automatically) existing files in SharePoint and OneDrive?
62+
* Credit card, passport, national-ID numbers
63+
* [Apply a sensitivity label to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide&preserve-view=true)
64+
* Content created by corporate officers: compliance, finance, executive, etc.
65+
* Strategic or financial data in libraries or sites.
7466

75-
See these [common scenarios for sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels) for other ideas on how you can use sensitivity labels.
67+
Consider the content categories that external users can't have access to, such as containers and encrypted content. You can use sensitivity labels, enforce encryption, or use container access restrictions.
7668

77-
### Sensitivity labels on email and content
69+
### Email and content
7870

79-
When you assign a sensitivity label to a document or email, it's like a stamp that's applied to content that is customizable, clear text, and persistent.
71+
Sensitivity labels can be applied automatically or manually to content.
8072

81-
* **Customizable** means you can create labels appropriate for your organization and determine what happens when they're applied.
73+
See, [Apply a sensitivity label to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide&preserve-view=true)
8274

83-
* **Clear text** means it’s a part of the item’s metadata and is readable by applications and services so that they can apply their own protective actions.
75+
#### Sensitivity labels on email and content
8476

85-
* **Persistent** means the label and any associated protections roam with the content, and become the basis for applying and enforcing policies.
77+
A sensitivity label in a document or email is customizable, clear text, and persistent.
8678

87-
79+
* **Customizable** - create labels for your organization and determine the resulting actions
80+
* **Clear text** - is incorporated in metadata and readable by applications and services
81+
* **Persistency** - ensures the label and associated protections stay with the content, and help enforce policies
8882

8983
> [!NOTE]
90-
> Each item of content can have a single sensitivity label applied to it.
91-
92-
93-
### Sensitivity labels on containers
94-
95-
You can apply sensitivity labels on containers such as [Microsoft 365 Groups](../enterprise-users/groups-assign-sensitivity-labels.md), [Microsoft Teams](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites), and [SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites). When you apply this sensitivity label to a supported container, the label automatically applies the classification and protection settings to the connected site or group. Sensitivity labels on these containers can control the following aspects of containers:
96-
97-
* **Privacy**. You can choose who can see the site: specific users, all internal users, or anyone.
84+
> Each content item can have one sensitivity label applied.
9885
99-
* **External user access**. Controls whether the group owner can add guests to the group.
86+
### Containers
10087

101-
* **Access from unmanaged devices**. Determines if and how unmanaged devices can access content.
102-
103-
104-
105-
![A screenshot of editing sensitivity labels](media/secure-external-access/8-edit-label.png)
106-
107-
88+
Determine the access criteria if Microsoft 365 Groups, Teams, or SharePoint sites are restricted with sensitivity labels. You can label content in containers or use automatic labeling for files in SharePoint, OneDrive, etc.
10889

109-
When you apply a sensitivity label to a container such as a SharePoint site, it is not applied to content there: sensitivity labels on containers control access to the content within the container.
90+
Learn more: [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide&preserve-view=true)
11091

111-
* If you want to automatically apply labels to the content within the container, see [Apply a sensitivity to content automatically](/microsoft-365/compliance/apply-sensitivity-label-automatically).
92+
#### Sensitivity labels on containers
11293

113-
* If you want users to be able to manually apply labels to this content, be sure that you‘ve [enabled sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files).
94+
You can apply sensitivity labels to containers such as Microsoft 365 Groups, Microsoft Teams, and SharePoint sites. Sensitivity labels on a supported container apply the classification and protection settings to the connected site or group. Sensitivity labels on these containers can control:
11495

115-
### Plan to implement sensitivity labels
96+
* **Privacy** - select the users who can see the site
97+
* **External user access** - determine if group owners can add guests to a group
98+
* **Access from unmanaged devices** - decide if and how unmanaged devices access content
11699

117-
Once you have determined how you want to use sensitivity labels, and to what content and sites you want to apply them, see the following documentation to help you perform your implementation.
100+
![Screenshot of otions and entries under Site and group settings.](media/secure-external-access/8-edit-label.png)
118101

119-
1. [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels)
102+
Sensitivity labels applied to a container, such as a SharePoint site, aren't applied to content in the container; they control access to content in the container. Labels can be applied automatically to the content in the container. For users to manually apply labels to content, enable sensitivity labels for Office files in SharePoint and OneDrive.
120103

121-
2. [Create a deployment strategy](/microsoft-365/compliance/get-started-with-sensitivity-labels)
104+
Learn more:
122105

123-
3. [Create and publish sensitivity labels](/microsoft-365/compliance/create-sensitivity-labels)
106+
* [Enable sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files?view=o365-worldwide&preserve-view=true).
107+
* [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)
108+
* [Assign sensitivity labels to Microsoft 365 groups in Azure AD](../enterprise-users/groups-assign-sensitivity-labels.md)
124109

125-
4. [Restrict access to content using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels)
110+
### Implement sensitivity labels
126111

127-
5. [Use sensitivity labels with teams, groups, and sites](/microsoft-365/compliance/sensitivity-labels-teams-groups-sites)
112+
After you determine use of sensitivity labels, see the following documentation for implementation.
128113

129-
6. [Enable sensitivity labels for Office files in SharePoint and OneDrive](/microsoft-365/compliance/sensitivity-labels-sharepoint-onedrive-files)
114+
* [Get started with sensitivity labels](/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide&preserve-view=true)
115+
* [Create and publish sensitivity labels](/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide&preserve-view=true)
116+
* [Restrict access to content by using sensitivity labels to apply encryption](/microsoft-365/compliance/encryption-sensitivity-labels?view=o365-worldwide&preserve-view=true)
130117

131-
### Next steps
118+
## Next steps
132119

133-
See the following articles on securing external access to resources. We recommend you take the actions in the listed order.
120+
See the following articles to learn more about securing external access to resources. We recommend you follow the listed order.
134121

135-
1. [Determine your desired security posture for external access](1-secure-access-posture.md)
122+
1. [Determine your security posture for external access](1-secure-access-posture.md)
136123

137-
2. [Discover your current state](2-secure-access-current-state.md)
124+
2. [Discover the current state of external collaboration in your organization](2-secure-access-current-state.md)
138125

139-
3. [Create a governance plan](3-secure-access-plan.md)
126+
3. [Create a security plan for external access](3-secure-access-plan.md)
140127

141-
4. [Use groups for security](4-secure-access-groups.md)
128+
4. [Secure external access with groups in Azure AD and Microsoft 365](4-secure-access-groups.md)
142129

143-
5. [Transition to Azure AD B2B](5-secure-access-b2b.md)
130+
5. [Transition to governed collaboration with Azure AD B2B collaboration](5-secure-access-b2b.md)
144131

145-
6. [Secure access with Entitlement Management](6-secure-access-entitlement-managment.md)
132+
6. [Manage external access with Azure AD entitlement management](6-secure-access-entitlement-managment.md)
146133

147-
7. [Secure access with Conditional Access policies](7-secure-access-conditional-access.md)
134+
7. [Manage external access with Conditional Access policies](7-secure-access-conditional-access.md)
148135

149-
8. [Secure access with Sensitivity labels](8-secure-access-sensitivity-labels.md) (You are here.)
136+
8. [Control external access to resources in Azure AD with sensitivity labels](8-secure-access-sensitivity-labels.md) (You're here)
150137

151-
9. [Secure access to Microsoft Teams, OneDrive, and SharePoint](9-secure-access-teams-sharepoint.md)
138+
9. [Secure external access to Microsoft Teams, SharePoint, and OneDrive for Business](9-secure-access-teams-sharepoint.md)

0 commit comments

Comments
 (0)