A compliance administrator wants to automatically apply a 'Confidential' sensitivity label to documents that contain tax identification numbers. Which two configurations are required? (Choose two.)
Trap 1: Create a sensitivity label with the desired protection settings
A sensitivity label defines the protection outcome—such as encryption and permissions—but it does not scan content or evaluate conditions on its own. The label must exist before you configure auto-labeling, yet creating it is only a foundational step, not the mechanism that triggers automatic application. The actual labeling is performed by an auto-labeling policy that references this label.
Trap 2: Configure a data loss prevention (DLP) rule
Configuring a DLP rule addresses the prevention of sensitive data loss—blocking, restricting, or alerting on content—not the assignment of sensitivity metadata. DLP actions operate on the outbound data path (Exchange, Teams, endpoints, etc.) and cannot stamp a sensitivity label on the source document. To automatically label content based on SIT conditions, Purview requires a separate auto-labeling policy, not a DLP rule.
- A
Define a sensitive information type for tax IDs
Defining a custom sensitive information type for tax IDs is a mandatory prerequisite for the auto-labeling policy's detection logic. Purview's built-in SITs may not recognize a jurisdiction-specific tax ID format, so you author a regex-based SIT with optional keywords and confidence levels. Without that SIT, the auto-labeling policy has no condition to match, and no automatic label application can occur.
- B
Create a sensitivity label with the desired protection settings
Why it fails: A sensitivity label defines the protection outcome—such as encryption and permissions—but it does not scan content or evaluate conditions on its own. The label must exist before you configure auto-labeling, yet creating it is only a foundational step, not the mechanism that triggers automatic application. The actual labeling is performed by an auto-labeling policy that references this label.
- C
Configure a data loss prevention (DLP) rule
Why it fails: Configuring a DLP rule addresses the prevention of sensitive data loss—blocking, restricting, or alerting on content—not the assignment of sensitivity metadata. DLP actions operate on the outbound data path (Exchange, Teams, endpoints, etc.) and cannot stamp a sensitivity label on the source document. To automatically label content based on SIT conditions, Purview requires a separate auto-labeling policy, not a DLP rule.
- D
Create an auto-labeling policy
Creating an auto-labeling policy is the central configuration step that ties detection to action: it specifies the SITs to match, the target locations (SharePoint, OneDrive, Exchange), and the sensitivity label to apply. The policy supports a simulation mode to assess impact before going live, then automatically labels both new and existing content. This is the component that actually delivers the automatic labeling behavior requested in the question.