Microsoft Purview label coverage

"Highly Confidential" sits on 12 files. 30% of sensitive files have no label.

Most tenants spend months designing a Purview taxonomy and never measure where it landed. 1Security counts it: how many real files, emails and groups carry each label, which labels actually encrypt and which only print a word in the ribbon, and - the number that matters - how many files with card numbers, IDs or health data carry no label whatsoever.

  • 20-40%
    of files with detected sensitive data carry no sensitivity label in a typical tenant
  • 3
    resource types counted per label - files, emails and groups - live, not as designed
  • 0
    E5 licenses needed: the coverage gap is found by 1Security's own 300+ detectors

The problem

Your labels are designed. Now measure where they landed.

A taxonomy is a design. Coverage is what happened afterwards - and it is worth counting.

The first gap is deployment. A label named Highly Confidential applied to twelve files is not a data protection programme, and that only shows up when somebody counts. In the tenants we connect to, the top-priority label is routinely on fewer than 1% of the files it was designed for.

The second gap is protection. Some labels encrypt and watermark; others display a name and nothing else. Thousands of documents marked Confidential that any recipient can open and forward is the most common false comfort in Microsoft 365, and the two kinds look identical in a list of label names.

The third gap is sensitive data with no label at all. Card numbers in a scanned contract, ID numbers in an HR spreadsheet, credentials in a text file. Whatever users did not label by hand and no auto-labelling rule caught stays unlabelled - typically 20-40% of everything sensitive. 1Security finds it with its own detectors, on any license.

What you get

Six columns that measure the programme.

The labels stay Microsoft's and sync natively. What 1Security adds is the count of where they landed and what they missed.

  • Live counts per label

    Sensitivity labels shows every Purview label with real file, email and group counts. Sort by files and the aspirational labels - designed for the crown jewels, applied to a handful of documents - sink to the bottom.

  • Protection flag

    A column that says whether the label encrypts and watermarks or only displays a name. Filter high priority + no protection + high count: those documents are readable by anyone who receives them.

  • The unlabelled sensitive files

    Files: filter with sensitive info + without label. Found by 1Security's own 300+ detectors with OCR for scans and screenshots - so it works on any Microsoft 365 license and adds OCR coverage for scans and images.

  • Coverage per site

    Sites carries label counts next to sensitive-info counts, so "the HR site holds 4,000 sensitive files and 900 labels" is a row, not a project. Sort by the gap and start there.

  • Taxonomy drift

    Inactive labels still sitting on content from before they were retired, priority orders that stopped making sense two reorganisations ago, labels scoped to formats nobody uses - each a filter.

  • Evidence for auditors

    Per-label deployment numbers and the unlabelled-sensitive count, exportable to CSV, replace "we have a labelling policy" with a control that is demonstrably operating.

How deep it goes

The false-comfort check, in one filter.

The list that comes out is usually short, uncomfortable and fixable in an afternoon.

On Sensitivity labels, filter to your highest-priority labels without protection, sorted by file count. In most tenants one or two labels named Confidential or Internal carry tens of thousands of documents and encrypt none of them. The label is doing reputational work rather than technical work, and everybody involved believes the opposite.

Then the other side. On Files, filter with sensitive info + without label, sort by detections. This is the number every labelling programme needs and rarely has: how much sensitive content nobody classified. It is common to find that a third of files holding card numbers or ID numbers carry no label - and that half of those sit in sites with external users or anyone links.

Both numbers come from the same scan, on a Business Basic tenant. Where you run Purview, its labels and detections are synced alongside and the two engines are compared; where you do not, the measurement still works. Together they turn "are we protected?" into two numbers you can track quarter over quarter.

In practice

Four ways a labelling programme fails - and how each shows up.

A per-label count surfaces each of these on day one. A policy review never does.

  1. 01

    Sort labels by file count

    The aspirational label surfaces immediately: designed for the most sensitive material, applied to a few dozen documents because applying it correctly needs a judgement nobody made. Typical finding: the top-priority label on under 1% of sensitive files.

  2. 02

    Filter to no protection

    The decorative label: high usage, no encryption. The one that produces the most confidence and the least security. Fixing the label definition in Purview once protects every document carrying it.

  3. 03

    Filter to inactive labels with content

    The zombie label: retired in the taxonomy, still on thousands of files from before, sometimes still enforcing an old policy. Re-label or accept, but decide.

  4. 04

    Open Files, sensitive + no label

    The uncovered majority: the sensitive content nobody classified. This list, sorted by exposure, is the work queue - and the "Unlabelled sensitive files" trend keeps the count on a chart so it goes down and stays down.

Working with Purview

Purview labels, measured - not replaced.

Labels sync natively from Purview, so every number here agrees with your configuration.

  • Live counts of the files, emails and groups actually carrying each Purview label
  • A protection column that separates labels that encrypt from labels that only display a name
  • 300+ detectors with OCR find unlabelled sensitive data on Business Basic - no auto-labelling license required
  • Inactive labels still sitting on live content, as one filter
  • Priority orders compared with how the labels are actually used
  • Labels next to sites, users, groups and apps, so a label's reach is one click away
  • A per-site coverage ratio: label counts against sensitive-info counts on the Sites screen
  • Per-label deployment numbers as an export, for auditors who want a control operating rather than a taxonomy document

Licensing

No premium requirement on our side.

A Business Basic tenant is enough for every number on this page, including the sensitive-data detections behind the coverage gap. Taxonomy, auto-labelling and enforcement stay in Purview, where they belong - 1Security shows you exactly where they did and did not land.

  • 300+
    sensitive information types detected by 1Security's own engine, with OCR for images and scans
  • 3
    resource types counted per label - files, emails and groups - synced natively from Purview
  • 90 days
    is the window most teams pick to trend the unlabelled-sensitive count down

Related

Where this fits.

Coverage has two sides. This screen holds the labelled half; the unlabelled half lives with the sensitive files and the sites they sit in.

  • Sensitive data discovery

    Where the card numbers, IDs and health data actually are, and who can reach them - the source of the unlabelled count.

    See sensitive data
  • File permissions

    The Files screen where sensitive + no label lives, with exposure - anyone links, external users - resolved per file.

    See files
  • Purview integration

    How the two products fit together across detections and labels, and what each one needs licensed.

    See Purview

FAQ

Questions teams ask first.

Does this change my labels?

No. Labels are synced natively from Purview and stay Purview's. Taxonomy design, auto-labelling and enforcement are configured there. 1Security adds the measurement of where the labels actually landed and what they missed.

What does the protection flag mean exactly?

Whether the label applies real protection - encryption and watermarking - as opposed to only displaying a classification name. That distinction decides whether a leaked file is readable, and it is invisible in a list of label names.

Do we need E5 to see the unlabelled sensitive files?

No. The coverage gap is found by 1Security's own scanning engine - 300+ detectors plus OCR - so it works on any Microsoft 365 license and adds OCR for scans and images. Business Basic is enough.

How long until we see our numbers?

Label counts appear after the first read-only scan, usually the same day. The unlabelled-sensitive count grows as the sensitivity scan works through the tenant; on large tenants the first sites report within hours and the picture is complete over the following days.

How do I use this with an auditor?

Export per-label deployment counts and the unlabelled-sensitive count. That is evidence of a control operating rather than a control designed - a different conversation from presenting a taxonomy document, and the one auditors increasingly ask for.

Measure the labelling programme you already paid for.

Connect read-only and the per-label counts land the same day. The protection column is usually the uncomfortable one; the unlabelled-sensitive count is the one that gets fixed first.

Or keep trusting the taxonomy document.