Microsoft Defender for Cloud
Cloud and workloads

Customize data sensitivity settings

In brief

The article now directs administrators to review prerequisites and enable sensitive data discovery before configuring settings. It also clarifies that supported types are a subset of Microsoft Purview’s built-in types and updates related wording and navigation.

What Defender admins need to know

Review the prerequisites, enable sensitive data discovery, and consult the supported sensitive information types list before configuring settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Customize data sensitivity settings

This article describes how to customize data sensitivity settings in Microsoft Defender for Cloud. Before you begin, make sure you review the prerequisites and requirements and enable sensitive data discovery in your Defender for Cloud plan.

Data sensitivity settings are used to identify and focus on managing the critical sensitive data in your organization.

  • You can select sensitive information types and sensitivity labels from the Microsoft Purview portal in Defender for Cloud.
  • If you import labels, you can set sensitivity thresholds that determine the minimum threshold sensitivity level for a label to be marked as sensitive in Defender for Cloud.

This configurationCustomizing data sensitivity settings helps you focus on your critical sensitive resources and improve the accuracy of the sensitivity insights.

Before you start

Before you customize data sensitivity settings, ensure the following requirements are met:

Changes in sensitivity settings take effect the next time that resources are discovered.

You can set a threshold to determine the minimum sensitivity level for a label to be marked as sensitive in Defender for Cloud.

  • You can't select a sub label in the threshold. However, you can see the sublabel as the affected label on resources in attack path/Cloud Security Explorer, if the parent label is part of the threshold (part of the sensitive labels selected).
  • The same settings apply to any supported resource (object storage and databases).

Next stepsteps

[!div class="nextstepaction"] Review risks to sensitive data