Type something to search...
Purview Sensitivity Labels are coming to OneNote

Purview Sensitivity Labels are coming to OneNote


Introduction

Good news for security and compliance teams, Sensitivity Labels are now General Availability in OneNote. This update finally allows you to apply the same classification and protection mechanisms as in Word, Excel, PowerPoint, Outlook or PDF directly to your notes. This was a highly anticipated feature for businesses, especially those using OneNote to document projects, store sensitive information, or share notes within teams.

I will soon be publishing articles on Purview Sensitivity Labels to help you protect your data.


Why is this important ?

In many organizations, OneNote is used to capture critical information :

  • Meeting notes containing strategic decisions
  • Internal project documentation
  • Technical or confidential information

Until now, this information could be stored in OneNote without fully benefiting from the Microsoft Purview classification model.

With this update, organizations can now :

  • Classify sensitive information in OneNote
  • Apply protection policies (encryption, access restrictions)
  • Meet compliance requirements

When a OneNote section receives a sensitivity label, the policies associated with that label are automatically applied, just like in other Microsoft 365 applications.

image


How do labels work in OneNote ?

Unlike standard Office documents, OneNote has a specific structure :

image


Sensitivity Labels apply at the section level. This means :

  • The label does not apply to the entire notebook.
  • It also does not apply to individual pages or sections.
  • All pages within a section automatically inherit the same level of protection.

This model offers some flexibility. For example, within the same notebook you could have :

  • A Public section
  • An Internal section
  • A Highly Confidential section

Each section then applies its own protection rules.


What’s included in this GA release

The first available version already brings several key features :

  • Manual labeling : Users can apply a label directly to a section in OneNote.

  • Integration with Microsoft Purview: OneNote uses the same labels configured for files in Microsoft Purview.

  • Automatic protection : Depending on the label configuration, OneNote can apply :

    • Encryption
    • Access restrictions
    • Compliance policies
  • Cross-Platform Support : This feature is available on :

    • OneNote Windows (Desktop)
    • OneNote Web
    • OneNote Mac
    • OneNote iOS
    • OneNote Android

note

OneNote for Windows 10 (UWP) is not supported.

What’s not yet available

As is often the case with new Microsoft 365 features, some capabilities will arrive later. Currently, OneNote only supports manual labeling.

The following features are not yet available :

  • Content-based auto-labeling
  • Recommended labeling
  • Default labeling
  • Mandatory labeling

These options may be added in future platform updates.


Impact on Copilot and AI

An interesting point concerns integration with AI features. Services like Copilot only access content that the user has permission to access. Therefore, using Sensitivity Labels in OneNote adds an extra layer of governance for content used by AI.

This allows organizations to :

  • Protect sensitive information
  • Maintain compliance
  • Use AI with confidence

Administrator-side activation

Even if your organization already uses Sensitivity Labels in Microsoft Purview, the feature is not automatically enabled in OneNote.

The following PowerShell commands will allow you to enable the service :

Connect-SPOService -Url https://XXXX-admin.sharepoint.com
Set-SPOTenant -EnableSensitivityLabelforOneNote $true

Conclusion

The availability of Sensitivity Labels in OneNote is a significant step for data governance in Microsoft 365. It finally allows for the protection of sensitive information within notes, harmonizes data classification across all applications, and strengthens compliance and security. For organizations that use OneNote extensively, this feature addresses a major blind spot in their data protection strategy.


Sources

Microsoft - Techcommunity

Microsoft - Support

Microsoft Learn - Enable labels


Did you enjoy this post ? If you have any questions, comments or suggestions, please feel free to send me a message from the contact form.

Don’t forget to follow us and share this post.

Related Posts

Email verification of external Teams participants

Email verification of external Teams participants

Introduction Microsoft Teams Premium introduces a new feature to enhance the security and reliability of your meetings: email verification for external participants. This feature allows mee

Read More
How to activate Microsoft 365 Passkey in Entra ID

How to activate Microsoft 365 Passkey in Entra ID

Introduction Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **<

Read More
How to sign in with Passkey to Microsoft 365

How to sign in with Passkey to Microsoft 365

Introduction Microsoft 365 Passkey is an authentication method that replaces passwords with more secure options like facial recognition, fingerprint, or a PIN.Prerequisites **<

Read More
How to enable LAPS on the MTR Admin account via Intune

How to enable LAPS on the MTR Admin account via Intune

Introduction Microsoft's LAPS (Local Administrator Password Solution) is a free tool designed to improve password security for local administrator accounts on workstations, servers and

Read More
Microsoft Purview for Azure Data Lake and Blob Storage

Microsoft Purview for Azure Data Lake and Blob Storage

Introduction Microsoft announced that Microsoft Purview protection policies for Azure Data Lake and Blob Storage are now available in all regions. This advancement allows organization

Read More
Impact analysis of Entra ID conditional access policies

Impact analysis of Entra ID conditional access policies

Introduction Conditional access in Entra is a security policy that allows administrators to control access to applications and resources based on specific conditions. These conditions can i

Read More
How to create a Windows local admin account via Intune LAPS

How to create a Windows local admin account via Intune LAPS

Introduction I wrote an article last February on how to replace the password of your MTR's local account using LAPS (Local Administrator Password Solution) in Intune. I concluded my article

Read More
New security approach for non-compliant emails

New security approach for non-compliant emails

Introduction Microsoft has announced a major update to Defender for Office 365 that strengthens email security by improving the handling of non-RFC compliant emails. This initiative is

Read More
Blocking screenshots during Teams meetings

Blocking screenshots during Teams meetings

Introduction Microsoft Teams continues to strengthen the privacy and security of online meetings. Starting in July 2025, a new feature will be rolled out to prevent screenshots during meeti

Read More
"Anti-Tampering" certification for Defender for Endpoint (2025)

"Anti-Tampering" certification for Defender for Endpoint (2025)

Introduction Microsoft recently announced that Microsoft Defender for Endpoint has successfully passed the 2025 anti-tampering tests conducted by AV-Comparatives, a recognized independe

Read More
How to enable DLP for Teams with Purview

How to enable DLP for Teams with Purview

Introduction In a context where sensitive data, particularly banking information, is increasingly circulating in collaborative tools, businesses must be extra vigilant to avoid accidental o

Read More
How to enable DLP for Outlook with Purview

How to enable DLP for Outlook with Purview

Introduction Last week, I showed you how to enable DLP for Teams with Microsoft Purview to prevent accidental or malicious data leaks (Data Loss Prevention). Purview is a comprehensive

Read More
Entra Private Access for Domain Controllers

Entra Private Access for Domain Controllers

Introduction Microsoft has announced the Public Preview of Microsoft Entra Private Access for Active Directory Domain Controllers, a major step forward in strengthening the security of

Read More
Sensitive content detection in Teams meetings

Sensitive content detection in Teams meetings

Introduction In a world where business interactions increasingly take place via video conferencing, the security of information shared in meetings is becoming a major issue. Microsoft is ad

Read More
How to activate Defender EDR in "Block Mode"

How to activate Defender EDR in "Block Mode"

Introduction In a context of constantly evolving cyber threats, antivirus solutions are no longer sufficient to effectively protect workstations. Microsoft Defender for Endpoint's *Block

Read More
How to enable DSPM for AI with Purview

How to enable DSPM for AI with Purview

Introduction With the rise of generative AI models, the phenomenon of Shadow AI (the use of artificial intelligence tools and services not approved or controlled by organizations) is incr

Read More
How to block a website URL in Edge with Defender

How to block a website URL in Edge with Defender

Introduction Web browsing is one of the most common attack vectors in business environments. To strengthen security, Microsoft Defender for Endpoint offers a powerful feature : blocking m

Read More
How to enable DLP for cloud storage with Purview

How to enable DLP for cloud storage with Purview

Introduction A few months ago, I showed you how to enable DLP for Outlook with Microsoft Purview to prevent accidental or malicious data leaks (Data Loss Prevention). Purview is a com

Read More
Blocking screen captures in Teams meetings

Blocking screen captures in Teams meetings

Introduction In a world where business interactions increasingly take place via video conferencing, the security of information shared in meetings is becoming a major issue. A simple screen

Read More
Extend Zero Trust to AI agent identities in Entra ID

Extend Zero Trust to AI agent identities in Entra ID

Introduction AI agents are becoming increasingly widespread in businesses (incident summaries, log analysis, flow execution, etc.), and it is crucial that their access is continuously evalu

Read More
How to enable DLP for printing with Purview

How to enable DLP for printing with Purview

Introduction A few weeks ago, I showed you how to enable DLP to prevent the copying of financial data to an external cloud storage solution using Microsoft Purview, in order to prevent

Read More
How to enable DLP for AI websites with Purview

How to enable DLP for AI websites with Purview

Introduction Last week, I showed you how to enable DLP to prevent printing of financial data using Microsoft Purview, in order to prevent accidental or malicious data leaks (*Data Loss

Read More
How to enable DLP for copy/paste with Purview

How to enable DLP for copy/paste with Purview

Introduction Last month, I showed you how to enable DLP to prevent financial data from being sent to an AI website using Microsoft Purview, in order to prevent accidental or malicious d

Read More
How to block Teams calls and chats with Purview IB

How to block Teams calls and chats with Purview IB

Introduction Microsoft Purview's Information Barriers allow you to restrict communication and collaboration between specific user groups within a Microsoft 365 environment. Their prim

Read More
External MFA is now available in Entra ID

External MFA is now available in Entra ID

Introduction Microsoft has announced the General Availability of External MFA, in Microsoft Entra ID, formerly known as External Authentication Methods. This feature allows the use

Read More
How to create Sensitivity Labels for emails in Purview

How to create Sensitivity Labels for emails in Purview

Introduction Emails remain one of the primary vectors for information leaks in businesses. Whether it's a message sent to the wrong recipient, an attachment forwarded without proper oversig

Read More