Prevent users from removing or downgrading the labels

Archit Jain 40 Reputation points
2026-09-28T11:05:47.1533333+00:00

Hello guys, I am here to get some understanding on preventing users from removing or downgrading sensitivity labels. Ik we have option of adding justification for that, But I just wanna prevent that action. Is it possible? So I was thinking using the sensitivity labels internal permissions options, if I publish the labels with only restricted editor or view permissions for the whole org wide users and only authorized group with co-author permission, would this work in preventing the user to remove the labels. I am guessing NO, but Just want to have your opinion. Please feel free to provide your suggestion.

Microsoft Security | Microsoft Purview

Answer accepted by question author

AI answer

2026-09-28T11:06:06.8866667+00:00

Yes—this can be prevented, but not by relying only on justification prompts.

For Microsoft Purview sensitivity labels, justification is the default behavior when a user removes a label or replaces it with a lower-priority label. That setting does not block the action; it only requires a reason.

To prevent users from changing or removing protection, the supported approach is to use protected sensitivity labels with encryption and assign permissions so only authorized users have rights that allow label changes.

The relevant rule is:

  • A user can change or remove a protected label only if that user either:
    • applied the label, or
    • has one of these usage rights:
      • OWNER
      • EXPORT
      • EDIT and EDITRIGHTSDATA

For automatically applied labels in Fabric/Power BI scenarios, the requirement can be relaxed to OWNER, EXPORT, or EDIT.

About the permission presets:

  • Viewer cannot change or remove protection.
  • Restricted Editor can edit, but cannot change or remove protection.
  • Editor can view, edit, print, and copy, but cannot change or remove protection.
  • Owner has full control, including changing or removing protection.

So the design being considered is broadly correct:

  • Give most users Viewer, Restricted Editor, or Editor rights.
  • Give only the authorized group Owner-level rights, or otherwise ensure they have the required usage rights.

That will prevent standard users from removing or changing the protected label. However, there is one important limitation:

  • The user who originally applied the protected label can also change or remove it.

Also note:

  • Mandatory labeling can require users to apply a label before saving, but it does not by itself stop label changes.
  • Downgrade justification requires a reason for lowering/removing a label, but it does not block the action.

If the goal is “no downgrade or removal by regular users,” the practical approach is:

  1. Use a sensitivity label with encryption/protection.
  2. Publish it with permissions such as Viewer, Restricted Editor, or Editor for broad users.
  3. Reserve Owner or equivalent change-capable rights for a small authorized group.
  4. Avoid workflows where regular users are the original label appliers if the requirement is that they must never be able to remove the label.

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

2 people found this answer helpful.

1 additional answer

Sort by: Newest
  1. Archit Jain 40 Reputation points
    2026-09-28T11:14:42.15+00:00

    so what if the org has mandatory label apply label policy before saving it, and the suer who applies the label has only editor or restricted editor permission on the label. So as soon as the label is applied the user must inherit the permissions from the label right, then he must not have the ability to remove or change the label although he added the label originalluy? Need clarification

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.