Classify and protect information
A labelling model people can understand — and protection settings you can defend.

Sensitivity labels can classify and protect documents, emails and supported collaboration content. Value depends on the structure. Twelve overlapping names get ignored. Encryption that blocks a legitimate counsel review gets worked around.
Ghani Governance designs a Microsoft Purview Information Protection approach from how information is actually created and shared. Microsoft documents the product in the Information Protection documentation; we do the taxonomy, publishing, testing and adoption. A data classification policy is the usual written input; we map it in a Policy-to-Purview design report before labels go live.
A short hierarchy with names a new joiner can apply without a training day.
Access and encryption choices tied to harm of disclosure, not a default “encrypt everything”.
Pilot groups before the whole tenant sees a new prompt.
We watch whether people understand the names. If they do not, we rename before rollout.
Labels become something DLP can reason about, instead of two disconnected programmes.
| Service | Planning range | Typical mid-point |
|---|---|---|
| Label strategy workshop | £1,200–£2,500 | £1,850 |
| Sensitivity label pilot | £2,500–£5,000 | £3,750 |
| Full information protection rollout | £5,000–£12,000 | £8,500 |
Indicative only. Complexity, user groups, existing labels and DLP integration change the figure. Not a quote.
Existing classifications and the real handling paths.
Hierarchy, purpose, expected user behaviour.
Settings and publishing for the pilot scope.
Names, prompts, and what happens when someone opens a labelled file.
Wider groups with communication, not a Friday surprise.
Usually fewer than people first draft. If a user cannot choose in two seconds, they will pick the default or ignore the prompt. We design for that behaviour.
No. Labels classify and can protect a file or email. DLP watches movement and sharing. They should be designed together so a “Confidential” label is meaningful to a DLP rule.
It can. Protection settings are tied to the harm of disclosure, not switched on because the checkbox exists.
A scoping conversation about what you need to protect, what is already configured, and what must not break.