{"id":906,"date":"2024-01-17T09:17:36","date_gmt":"2024-01-17T09:17:36","guid":{"rendered":"https:\/\/poiseddevelopers.com\/reality-tech\/?p=906"},"modified":"2024-05-06T12:28:11","modified_gmt":"2024-05-06T12:28:11","slug":"safeguarding-collaboration-through-sensitivity-labels-across-microsoft-teams-microsoft-365-groups-and-sharepoint-sites","status":"publish","type":"post","link":"https:\/\/poiseddevelopers.com\/reality-tech\/safeguarding-collaboration-through-sensitivity-labels\/","title":{"rendered":"Safeguarding Collaboration Through Sensitivity Labels Across Microsoft Teams, Microsoft 365 Groups, and SharePoint Sites"},"content":{"rendered":"<p>Beyond safeguarding documents and emails, sensitivity labels offer protection for content within various containers like Microsoft Teams sites, Microsoft 365 groups (previously Office 365 groups), and SharePoint sites. These labels can be applied to manage settings such as:<\/p>\n<ul>\n<li>Privacy (public or private) of team sites and Microsoft 365 groups<\/li>\n<li>External user access, external sharing from SharePoint sites<\/li>\n<li>Access from unmanaged devices<\/li>\n<li>Authentication contexts<\/li>\n<li>Default sharing links for SharePoint sites (configuration via PowerShell only)<\/li>\n<li>Site sharing settings (configuration via PowerShell only) and default labels for channel meetings.<\/li>\n<\/ul>\n<h4>Safeguarding Collaboration: Implementing Sensitivity Labels Across Microsoft Teams, Microsoft 365 Groups, and SharePoint Sites<\/h4>\n<p>Once sensitivity labels for containers are set up, users can view and use them for Microsoft team sites, Microsoft 365 groups, and SharePoint sites. For instance, when making a new team site in SharePoint.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-930 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG1.webp\" alt=\"img-01\" width=\"1024\" height=\"788\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG1.webp 1024w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG1-300x231.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG1-768x591.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<p>Once a sensitivity label has been assigned to a site, changing that label in SharePoint or Teams requires specific roles:<\/p>\n<ul>\n<li>For a group-connected site:\u00a0<strong>Microsoft 365 group Owners<\/strong><\/li>\n<li>For a non-group-connected site:\u00a0<strong>SharePoint site admin<\/strong><\/li>\n<li><strong>Learn the process of activating sensitivity labels for containers and ensuring label synchronization.<\/strong><\/li>\n<\/ul>\n<p>If you haven\u2019t yet enabled sensitivity labels for containers, do the following set of steps as a one-time procedure:<\/p>\n<p>Ensure that this PowerShell snippet is executed with Global Administration privileges.<\/p>\n<pre class=\"php\"> \r\nImport-Module AzureADPreview\r\nConnect-AzureAD\r\n\r\n#Run the code snippet below if you don't have directory settings\r\nGet-AzureADDirectorySettingTemplate\r\n\r\n$TemplateId = (Get-AzureADDirectorySettingTemplate | where { $_.DisplayName -eq \"Group.Unified\" }).Id\r\n\r\n$Template = Get-AzureADDirectorySettingTemplate | where -Property Id -Value $TemplateId -EQ\r\n\r\n$Setting = $Template.CreateDirectorySetting()\r\n\r\n#Use URL of Your Tenant\r\n$Setting[\"UsageGuidelinesUrl\"] = \"https:\/\/Tenant.sharepoint.com\/_layouts\/15\/sharepoint.aspx\"\r\n\r\n$Setting[\"EnableMIPLabels\"] = \"True\"\r\n\r\nNew-AzureADDirectorySetting -DirectorySetting $Setting\r\n\r\n$Setting.Values\r\n\r\n#For existing settings\r\n#$Setting = Get-AzureADDirectorySetting -Id (Get-AzureADDirectorySetting | where -Property DisplayName -Value \"Group.Unified\" -EQ).id\r\n#$Setting.Values\r\n#$Setting[\"EnableMIPLabels\"] = \"True\"\r\n#Set-AzureADDirectorySetting -Id $Setting.Id -DirectorySetting $Setting\r\n<\/pre>\n<p>Once you run this script in Windows PowerShell (run ISE as an Administrator), a pop-up will appear prompting you to input the credentials of the\u00a0<strong>\u201cGlobal Administrative Account\u201d<\/strong>. Following that, review the highlighted outcome below. (Name:\u00a0<strong>EnableMIPLabels<\/strong>\u00a0Value:\u00a0<strong>True<\/strong>)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-948 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG2.webp\" alt=\"img-02\" width=\"1024\" height=\"745\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG2.webp 1024w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG2-300x218.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG2-768x559.webp 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h4><span lang=\"EN-US\" data-uw-rm-lang=\"false\">Optimizing Group and Site Settings: A Configuration Guide<\/span><\/h4>\n<p>Once sensitivity labels are activated for containers as detailed earlier, you can now establish protection settings for groups and sites within the sensitivity labeling setup. Access Microsoft Purview &gt; Information Protection &gt; Labels &gt; Create Label. You\u2019ll notice that the option for \u201cGroup &amp; sites\u201d in the label scope is now enabled.<\/p>\n<p>To access Microsoft Compliance, click here\u00a0<strong><a href=\"https:\/\/compliance.microsoft.com\/\" target=\"_blank\" rel=\"noopener\" aria-label=\"Microsoft Purview - open in a new tab\" data-uw-rm-ext-link=\"\">Microsoft Purview<\/a><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-955 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG3.webp\" alt=\"img-03\" width=\"884\" height=\"533\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG3.webp 884w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG3-300x181.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG3-768x463.webp 768w\" sizes=\"auto, (max-width: 884px) 100vw, 884px\" \/><\/p>\n<p>Next, within the \u201c<strong>Define protection settings for groups and sites<\/strong>\u201d page, choose either or both provided options:<\/p>\n<ul>\n<li>Adjust the \u201c<strong>Privacy and External user access\u201d<\/strong>\u00a0settings to configure Privacy and External user\u2019s access.<\/li>\n<li>Adjust \u201c<strong>External sharing and Conditional Access\u201d<\/strong>\u00a0settings to configure Control external sharing from labeled SharePoint sites and Use Microsoft Endpoint Conditional Access to protect labeled SharePoint sites settings.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-957 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG4.webp\" alt=\"img-04\" width=\"975\" height=\"235\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG4.webp 975w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG4-300x72.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG4-768x185.webp 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><\/p>\n<p>For\u00a0<strong>\u201cPrivacy and external user access settings\u201d<\/strong>:<\/p>\n<ul>\n<li><strong>Public<\/strong>: Allows anyone in your organization access to the labeled site or group.<\/li>\n<li><strong>Private<\/strong>: Limits access to approved members only within your organization.<\/li>\n<li><strong>None<\/strong>: Protects content with the sensitivity label while enabling users to adjust privacy settings themselves.<\/li>\n<\/ul>\n<p>Your chosen setting replaces prior privacy configurations and locks it. Changing requires removing the sensitivity label first. Once removed, the labeled privacy setting remains, and users regain control.<\/p>\n<ul>\n<li><strong>External user access:<\/strong>\u00a0Manages the group owner\u2019s ability to add guests to the group.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-959 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG5.webp\" alt=\"img-05\" width=\"952\" height=\"455\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG5.webp 952w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG5-300x143.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG5-768x367.webp 768w\" sizes=\"auto, (max-width: 952px) 100vw, 952px\" \/><\/p>\n<p>If you\u2019ve chosen External Sharing, proceed to adjust these options:<\/p>\n<ul>\n<li><strong>\u201cControl external sharing from labeled SharePoint sites\u201d:<\/strong>\u00a0Choose from external sharing options like anyone, new and existing guests, existing guests, or only internal users.<\/li>\n<li>If your sensitivity label hasn\u2019t been published yet, proceed by adding it to a sensitivity label policy. Users assigned to this policy, encompassing this label, will gain the ability to choose it for sites and groups.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-960 size-full\" src=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG6.webp\" alt=\"img-06\" width=\"956\" height=\"481\" srcset=\"https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG6.webp 956w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG6-300x151.webp 300w, https:\/\/poiseddevelopers.com\/reality-tech\/wp-content\/uploads\/2024\/03\/IMG6-768x386.webp 768w\" sizes=\"auto, (max-width: 956px) 100vw, 956px\" \/><\/p>\n<p>&nbsp;<\/p>\n<table style=\"border-collapse: collapse; width: 100%; margin-top: 20px;\">\n<thead>\n<tr style=\"background-color: #f2f2f2;\">\n<th style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Select this option:<\/th>\n<th style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">If you want to:<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Anyone<\/td>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Allow site owners and others with full control permission to share the site with people who authenticate. Allow site users to decide when sharing files and folders to require authentication or allow unauthenticated people to access the item. Anyone links to files and folders can be freely forwarded.<\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">New and existing guests<\/td>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Allow site owners and others with full control permission to share the site with people outside the organization. These people will need to sign in and will be added to the directory. Allow site users to share files and folders with people who aren\u2019t in the organization\u2019s directory.<\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Existing guests<\/td>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Allow sharing with only people already in your directory. These users may exist in your directory because they previously accepted sharing invitations or because they were manually added. (These users have #EXT# in their user\u2019s principal name.)<\/td>\n<\/tr>\n<tr>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Only people in your organization<\/td>\n<td style=\"border: 1px solid #dddddd; text-align: left; padding: 8px;\">Prevent all site users from sharing any site content externally.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Beyond safeguarding documents and emails, sensitivity labels offer protection for content within various containers like Microsoft Teams sites, Microsoft 365 groups (previously Office 365 groups), and SharePoint sites. These labels can be applied to manage settings such as: Privacy (public or private) of team sites and Microsoft 365 groups External user access, external sharing from [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":927,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[43,21],"tags":[],"class_list":["post-906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft","category-security-and-compliance"],"acf":[],"_links":{"self":[{"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/posts\/906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/comments?post=906"}],"version-history":[{"count":4,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/posts\/906\/revisions"}],"predecessor-version":[{"id":2837,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/posts\/906\/revisions\/2837"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/media\/927"}],"wp:attachment":[{"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/media?parent=906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/categories?post=906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/poiseddevelopers.com\/reality-tech\/wp-json\/wp\/v2\/tags?post=906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}