A unified data governance solution that helps manage, protect, and discover data across your organization
Yes—this can be prevented, but not by relying only on justification prompts.
For Microsoft Purview sensitivity labels, justification is the default behavior when a user removes a label or replaces it with a lower-priority label. That setting does not block the action; it only requires a reason.
To prevent users from changing or removing protection, the supported approach is to use protected sensitivity labels with encryption and assign permissions so only authorized users have rights that allow label changes.
The relevant rule is:
- A user can change or remove a protected label only if that user either:
- applied the label, or
- has one of these usage rights:
- OWNER
- EXPORT
- EDIT and EDITRIGHTSDATA
For automatically applied labels in Fabric/Power BI scenarios, the requirement can be relaxed to OWNER, EXPORT, or EDIT.
About the permission presets:
- Viewer cannot change or remove protection.
- Restricted Editor can edit, but cannot change or remove protection.
- Editor can view, edit, print, and copy, but cannot change or remove protection.
- Owner has full control, including changing or removing protection.
So the design being considered is broadly correct:
- Give most users Viewer, Restricted Editor, or Editor rights.
- Give only the authorized group Owner-level rights, or otherwise ensure they have the required usage rights.
That will prevent standard users from removing or changing the protected label. However, there is one important limitation:
- The user who originally applied the protected label can also change or remove it.
Also note:
- Mandatory labeling can require users to apply a label before saving, but it does not by itself stop label changes.
- Downgrade justification requires a reason for lowering/removing a label, but it does not block the action.
If the goal is “no downgrade or removal by regular users,” the practical approach is:
- Use a sensitivity label with encryption/protection.
- Publish it with permissions such as Viewer, Restricted Editor, or Editor for broad users.
- Reserve Owner or equivalent change-capable rights for a small authorized group.
- Avoid workflows where regular users are the original label appliers if the requirement is that they must never be able to remove the label.