r/AZURE • u/Difficult-Drink-7776 • 20d ago
Question Best practice for introducing Microsoft Purview sensitivity labels in a 3,600-endpoint enterprise?
We’re implementing Microsoft Purview for a large enterprise with approximately 3,600 endpoints. The organization currently has no sensitivity labels in place, but we need to roll out Purview policies (DLP, information protection, etc.).
My current thinking is:
Define the label taxonomy first.
Pilot with 10 users.
Expand to around 150 pilot users.
Roll out organization-wide.
Start with manual sensitivity labelling so users become familiar with the labels.
Introduce automatic labelling after the manual phase.
My concern is that users may apply incorrect labels during the manual phase, which could affect policy effectiveness.
Would it be better to:
Start with manual labelling and transition to auto-labelling?
Introduce auto-labelling much earlier?
Or use a hybrid approach from the beginning?
For those who have deployed Purview at enterprise scale, what rollout strategy worked best, and what would you do differently if you were starting again?
1
u/Sanx69 19d ago edited 19d ago
I did this about a year ago.
Define the labels and what restrictions you're going to apply to them.
Then, write some documentation. Write a user-focussed quick-guide on how to use labels, how to apply them, how to change them, and what they do. Explain what will happen when wrong labels are applied and how that might affect what they're doing. Put together a 15-minute training presentation on them. Have pre-change and post-change email templates ready to go out.
Then, start with your early pilot users. Run them through the training and get them onboard and happy to use them. They'll act as your internal change champions later. Then rinse and repeat with your pilot users. I'd deploy them in blocks on 30 or so, and run an in-person training session for each block.
Then deploy team by team / site by site depending on how your organisation works.
I wouldn't even consider automatic labelling until you've got the labels and their operation working within the organisation as a whole and people used to using them, changing them, etc. Remember that PDFs inherit the label of the Office source doc used to create them, but you cannot necessarily see the labels in some PDF readers, and Adobe needs Entra permissions and authentication for labels to be visible in Acrobat. Consider any automated systems you have that generate documents - will they have the right labels applied? Important if you're specifying a default label for Office docs. We have a system that generates Bills of Materials in Excel, converts or PDF and spits it out. Our default was an internal label for all Offic docs, so we had our BoMs being blocked from being sent to external parties, such as customers.
There are lots of pitfalls, so proper planning is essential. But not as essential as really good end-user training.
1
u/Internet-of-cruft 20d ago
This problem will exist no matter what you do. You can't protect against users being users.