Microsoft Defender for Cloud Apps
Cloud and workloads

Integrate Microsoft Purview sensitivity labels with Defender for Cloud Apps

In brief

The article now more clearly describes using sensitivity labels to classify, protect, and investigate files, including sensitivity-label scans, direct file labeling, and automatic labeling policies. The title, metadata, and file-drawer screenshot description were also updated.

What Defender admins need to know

Administrators get clearer guidance for configuring and using the integration.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Integrate with Microsoft Purview for information protection

- If you enabled automatic scan, all new or modified files are added to the scan queue and all existing files and repositories will be scanned.
- If you set a file policy to search for sensitivity labels, these files are added to the scan queue for sensitivity labels.
  1. TheseThe sensitivity-label scans described in step 2 cover the sensitivity labels discovered in the initial scan Defender for Cloud Apps does to see which sensitivity labels are used in your tenant. External labels, classification labels set by someone external to your tenant, are added to the list of classification labels. If you don't want to scan for these,external sensitivity labels, select the Only scan files for Microsoft Information Protection sensitivity labels and content inspection warnings from this tenant check box.

  2. After you enable Microsoft Purview on Defender for Cloud Apps, all new files that are added to your connected cloud apps will be scanned for sensitivity labels.

How to integrate Microsoft Purview with Defender for Cloud Apps

The following sections describe how toYou can enable Microsoft Purview integration, apply sensitivity labels directly to files, and configure automatic labeling policies in Defender for Cloud Apps.

Enable Microsoft Purview

  1. You can get more information about these files and their sensitivity labels in the file drawer. Just select the relevant file in the Files page and check whether it has a sensitivity label.

    :::image type="content" source="media/file-policies/file-drawer.png" alt-text="Screenshot showingof the file drawer.drawer displaying file details and whether a sensitivity label is applied." lightbox="media/file-policies/file-drawer.png":::

  2. Then, you can create file policies in Defender for Cloud Apps to control files that are shared inappropriately and find files that are labeled and were recently modified.