What you need to know
Purview sensitivity labels for Teams, Microsoft 365 groups, and SharePoint sites can enforce container settings, but a container label does not automatically label the documents stored inside.
Potentially affected
Organizations using Microsoft Purview sensitivity labels for Teams, Microsoft 365 groups, SharePoint sites, or other supported collaboration containers.
DSE recommendation
Design container and item labeling as related but distinct controls, test privacy and sharing settings, and verify both container configuration and representative file labels.
Bottom line: Microsoft Purview sensitivity labels can apply settings to collaboration containers such as Teams, Microsoft 365 groups, and SharePoint sites. Microsoft explicitly distinguishes the container from the items stored inside it. A labeled Team or site does not, by that fact alone, label or encrypt every file within it.
Source fact: what Microsoft documents
Microsoft’s container-label documentation explains that sensitivity labels with the Groups & sites scope can control supported settings for Microsoft 365 groups, Teams, SharePoint sites, and other listed containers. Depending on current capabilities and configuration, settings can include privacy, external-user access, external sharing, unmanaged-device access, authentication context, and related collaboration controls.
When a label is applied through a supported connected workload, Microsoft coordinates the label on the Microsoft 365 group and connected SharePoint site. The source states that content in these containers does not inherit the container’s sensitivity label. Item-level labeling for files and emails is a separate scope and mechanism. The page documents prerequisites, synchronization, limitations, and effects of renaming or deleting labels, including possible creation failures if a referenced label is removed incorrectly.
What the source does not establish
A container label does not prove that membership is appropriate, existing external sharing is remediated, or every file has item-level protection. It does not classify data automatically unless separate supported labeling features do so. A displayed label name is not evidence that each associated setting applied successfully to every connected service. Licensing and supported settings vary.
Applicability questions
- Is the requirement to control the workspace, label files, encrypt items, or all three?
- Which Teams, groups, SharePoint sites, private or shared channels, and other supported containers are in scope?
- What privacy, guest, external-sharing, unmanaged-device, and authentication-context settings should each label carry?
- How will unlabeled, preexisting, orphaned, or differently labeled files be handled?
- What automation creates containers, and can it select or preserve sensitivity labels correctly?
DSE recommendation: controlled next steps
The following steps are DSE recommendations based on the cited source.
- Define a label taxonomy with separate requirements for containers and items. Do not overload one label name with ambiguous promises.
- Pilot labels on test groups, Teams, sites, private channels, and representative files. Verify connected-service synchronization and settings.
- Inventory existing sharing and membership before applying a restrictive label; plan remediation rather than assuming retroactive cleanup.
- Protect label rename, deletion, publication, and policy-order changes through formal change control.
- Report container labels and item-label coverage separately so stakeholders can see the remaining gap.
Verification and evidence
- Preserve label definitions, scopes, published policies, settings, order, and approvals.
- Capture the label and effective sharing or access configuration on each test container and connected site.
- Inspect representative files to show whether item-level labels and encryption are present or absent.
- Test new container creation, relabeling, external access, and label removal in a nonproduction scope.
Official references
Review the official source
Use sensitivity labels to protect collaborative workspaces (groups and sites) · Verified August 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE