0:00–0:10
Warm-up
0:10–0:30
Lecture A
0:30–0:45
Lab Part A
0:45–1:00
Lecture B
1:00–1:30
Lab Parts B–D
1:30–2:00
Debrief & capstone prep
0:00 – 0:10Warm-up · 10 min

What does the Finance label currently do?

0:10 – 0:30Lecture A · 20 min

AzureRMS encryption model

When a user applies a Confidential/Finance label to a Word document, the Microsoft Purview Information Protection client calls the Azure Rights Management service, which generates a content key unique to that file. The content key is encrypted using the tenant's Azure RMS public key and embedded in the file's licence store. When a recipient tries to open the file, their client sends the licence request to Azure RMS, which checks whether their Entra ID account is in the Finance group. If yes: file opens. If not: access denied — even if the file is in their Downloads folder.

0:30 – 0:45Lab 8-D Part A · 15 min

Add encryption to the Confidential/Finance label

Encryption propagation takes up to 24 hours to appear in Office apps. Students can verify the label settings in Purview immediately, but won't see the enforcement in Word/Excel until the next session. This is expected behaviour — not an error.
0:45 – 1:00Lecture B · 15 min

Auto-labelling — simulation mode, location scoping, and how it differs from library defaults

Auto-labelling policies can apply labels to thousands of files before anyone reviews the results — which is why Microsoft requires simulation mode as a mandatory first step. In simulation, the policy scans and identifies files that would be labelled, but makes no changes. The Purview portal shows matched items after 24–48 hours.

Do not turn the policy on during class. Moving from simulation to enforcement will auto-label — and encrypt — every file in the Finance SharePoint site that contains a credit card number, including test files created earlier in the course. Leave in simulation mode. Review results the following day.
1:00 – 1:30Lab 8-D Parts B, C, D · 30 min

Auto-labelling policy → SharePoint library default → DLP label condition

Part B — Auto-labelling policy in simulation (10 min)

Part C — SharePoint Finance library default label (10 min)

Part D — Add label condition to existing DLP policy (10 min)

The complete label governance stack is now active: visual marking (Week 7 Day 5) + encryption (Part A) + auto-labelling in simulation (Part B) + library default (Part C) + DLP label condition (Part D). The label is no longer a sticker — it is a full information protection control.
What today built — the four-layer label stack
Week 7 Day 5 — Visual marking only: Confidential/Finance label with CONFIDENTIAL — FINANCE ONLY header. No enforcement — a sticker.
Part A — Encryption added: AzureRMS encryption — only LL-Finance group members can open. File encrypted at rest and in transit. Admin account is RMS owner.
Part B — Auto-labelling policy (simulation): Scans Finance SharePoint, Exchange, and OneDrive for Credit Card SIT. Would apply the label automatically — not yet enforced.
Part C — SharePoint library default: Finance Documents library stamps every new upload with Confidential/Finance at creation — before content is even written.
Part D — DLP label condition: LL — Financial Data Protection now blocks sharing of labelled files externally, not just SIT-matched content. Two conditions, one policy.
1:30 – 2:00Debrief & capstone prep · 30 min

Remaining governance gaps — warm-up for Day 5 written synthesis

Instructor note: the capstone rubric rewards specificity and breadth — gaps should span at least two different product areas (e.g. identity + compliance), not three DLP variations. Brief students on this now so they write targeted answers tomorrow. There is no single correct answer for Part D.

Learning outcomes — by end of Day 4, students can…

Configure label encryptionAdd AzureRMS encryption to an existing label, set permission levels and offline access, identify the RMS owner's role
Build an auto-labelling policyCreate a simulation-mode policy scoped to specific locations using a sensitive info type condition
Explain simulation modeArticulate why simulation mode is required and describe the review-then-enforce workflow
Set a library defaultConfigure a SharePoint document library to apply a default sensitivity label to new and unlabelled documents
Add a label condition to DLPEdit an existing DLP policy to add a sensitivity label as an additional trigger condition
Describe the full label stackExplain how marking, encryption, auto-labelling, library defaults, and DLP conditions work together as a layered control

What you need ready

Confidential/Finance label exists (Week 7 Day 5) Finance M365 group with members LL — Financial Data Protection DLP policy active Finance SharePoint site URL known E5 trial active (AzureRMS requires E5) Credit Card Number SIT confirmed in DLP (Lab 7-D)
Day 5 →Week 8 Overview