Classify and protect information

Sensitivity labels and information protection

A labelling model people can understand — and protection settings you can defend.

Microsoft Purview sensitivity labels and information protection for UK organisations

A label model that survives first contact with users

Sensitivity labels can classify and protect documents, emails and supported collaboration content. Value depends on the structure. Twelve overlapping names get ignored. Encryption that blocks a legitimate counsel review gets worked around.

Ghani Governance designs a Microsoft Purview Information Protection approach from how information is actually created and shared. Microsoft documents the product in the Information Protection documentation; we do the taxonomy, publishing, testing and adoption. A data classification policy is the usual written input; we map it in a Policy-to-Purview design report before labels go live.

What we configure

Label taxonomy

A short hierarchy with names a new joiner can apply without a training day.

Protection settings

Access and encryption choices tied to harm of disclosure, not a default “encrypt everything”.

Publishing strategy

Pilot groups before the whole tenant sees a new prompt.

User testing

We watch whether people understand the names. If they do not, we rename before rollout.

DLP alignment

Labels become something DLP can reason about, instead of two disconnected programmes.

UK and Greater Manchester service area

Indicative ranges

ServicePlanning rangeTypical mid-point
Label strategy workshop£1,200–£2,500£1,850
Sensitivity label pilot£2,500–£5,000£3,750
Full information protection rollout£5,000–£12,000£8,500

Indicative only. Complexity, user groups, existing labels and DLP integration change the figure. Not a quote.

How we deliver labels

Understand the landscape

Existing classifications and the real handling paths.

Design the taxonomy

Hierarchy, purpose, expected user behaviour.

Configure protection

Settings and publishing for the pilot scope.

Test with users

Names, prompts, and what happens when someone opens a labelled file.

Roll out in stages

Wider groups with communication, not a Friday surprise.

Label questions

How many sensitivity labels should we have?

Usually fewer than people first draft. If a user cannot choose in two seconds, they will pick the default or ignore the prompt. We design for that behaviour.

Do labels replace DLP?

No. Labels classify and can protect a file or email. DLP watches movement and sharing. They should be designed together so a “Confidential” label is meaningful to a DLP rule.

Will encryption break collaboration?

It can. Protection settings are tied to the harm of disclosure, not switched on because the checkbox exists.

Book a discovery workshop

A scoping conversation about what you need to protect, what is already configured, and what must not break.

Request a workshop Call 0161 568 3030