Overview
Microsoft Purview sensitivity labels classify and protect documents, spreadsheets, presentations, and other files in a Microsoft 365 tenant. Labels are tenant-specific: a label that exists in the source tenant does not automatically exist in the target tenant. Without explicit handling, files arrive at the destination without any classification — and encrypted files become inaccessible because the encryption keys are bound to the source tenant's Azure Rights Management service.
Cloudiway's Sensitivity Label Migration solves this by migrating labels alongside the files. Before migration, Cloudiway reads the label catalogue from both tenants and lets you define a mapping between source and target labels. During migration, each file's label is looked up in that mapping and the corresponding target label is applied to the migrated file. Encrypted documents are re-protected with the target tenant's encryption policy, ensuring they remain accessible to users on the new tenant.
Applies to
Prerequisites
- Source connector must be Microsoft 365 (OneDrive / SharePoint)
- Microsoft Graph API application must have the
InformationProtectionPolicy.Read.Allpermission - For reading file-level labels: the
Files.Read.Allpermission - Sensitivity labels must be published in the Microsoft Purview compliance portal on both tenants
- Target connector should be Microsoft 365 for automatic target label discovery (optional — manual mapping is always available)
How It Works
The process flows through four stages: Discover Labels → Auto-Match by Name → Review & Map → Migrate with Labels. The sensitivity label migration itself consists of three phases.
Phase 1 — Label catalogue synchronisation
Cloudiway connects to the Microsoft Graph API on both the source and target tenants to retrieve all published sensitivity labels, including their hierarchy (parent and sub-labels), encryption settings, priority, and descriptions. This step runs automatically when you run a Get List for File, Site, or Group migrations. You can also trigger it manually from the Label Mapping page to refresh the catalogue independently.
Phase 2 — Mapping
Cloudiway automatically matches source labels to target labels by name (case-insensitive). If both tenants have a label named "Confidential", they are automatically linked. Labels that cannot be auto-matched remain unmapped and must be resolved manually in the Label Mapping page before migration starts. Bulk mapping via CSV import is available for tenants with a large number of labels.
Phase 3 — Migration
During file migration, Cloudiway reads the sensitivity label of each source file, looks it up in the mapping table, and applies the corresponding target label to the migrated file. For encrypted files, the target label's Azure Rights Management policy is applied, re-protecting the document with the target tenant's encryption keys so it remains accessible to users on the new tenant. If a source label has no mapping, the file is migrated without a label and a warning is logged.
Step-by-Step Guide
- Configure Microsoft 365 connectors. Set up source and target connector pools with the required Microsoft Graph API permissions. The application registration must have the
InformationProtectionPolicy.Readpermission to read sensitivity labels. - Run Get List (automatic discovery). Navigate to Files > Users (or Sites > Site List) and click Get List. If the source connector is Microsoft 365, sensitivity labels are automatically discovered from both tenants before the user/site listing begins.
- Review the Label Mapping page. Go to Files > Label Mapping. You will see all source labels with their auto-matched target labels. The Status column shows Mapped (ready to migrate) or Unmapped (needs attention).
- Map unmapped labels. Click Edit on any unmapped label. Choose a target label from the dropdown list (populated from the target tenant's labels), or switch to freestyle mode to enter the target label ID and name manually. Click Save.
- Verify encryption alignment. Check the encryption icons next to each label — a locked icon indicates encryption, an open icon indicates no encryption. Ensure encrypted source labels are mapped to target labels with equivalent encryption configured in the target tenant's Microsoft Purview compliance portal.
- Start migration. Proceed with your file or site migration as usual. Cloudiway will apply the mapped sensitivity labels to each migrated file automatically.
Label Mapping Page Features
| Feature | Description |
|---|---|
| Get List | Manually trigger label discovery. Select a source pool (required) and optionally a target pool. Only Microsoft 365 connectors are shown. |
| Export CSV | Download the current mapping as a CSV file for offline review or editing. |
| Import CSV | Upload a CSV file to bulk-update label mappings. The CSV must contain ExternalLabelId and TargetExternalLabelId columns. |
| Hierarchy View | Toggle between a flat list and a hierarchical view that shows parent labels with their sub-labels indented below. |
| Inline Edit | Click Edit to modify a mapping. Choose from a dropdown of target labels or switch to freestyle text input for custom IDs. |
| Help | Click the ? icon in the page title for contextual documentation. |
Understanding Sensitivity Labels
Label Hierarchy
Sensitivity labels in Microsoft 365 can be organized in a parent-child hierarchy. For example:
- Confidential (parent)
- Confidential \ All Employees
- Confidential \ Anyone (unrestricted)
- Highly Confidential (parent)
- Highly Confidential \ All Employees
- Highly Confidential \ Specific People
Cloudiway discovers and preserves this hierarchy. When using the Hierarchy View in the Label Mapping page, sub-labels are displayed indented under their parent.
Encryption
Some sensitivity labels apply encryption (Azure Rights Management) to protect file content. These labels are marked with a lock icon in the Cloudiway interface. When mapping encrypted labels:
- The target label should have equivalent encryption settings configured
- Users on the target tenant must have the appropriate permissions to open encrypted files
- Encryption policies are managed in the Microsoft Purview compliance portal, not in Cloudiway
Priority
Each label has a priority number that determines precedence when multiple labels could apply. The priority is displayed in the Label Mapping page for reference but does not affect the migration mapping logic.
Important Notes
Unmapped labels are not applied on the target
Verify mappings before starting migration
Auto-discovery runs before every Get List
CSV import for bulk mapping
Frequently Asked Questions
What happens if the source and target labels have different names?
Auto-matching works by exact name comparison (case-insensitive). If names differ, the label appears as unmapped. You can manually map it by clicking Edit and selecting the correct target label from the dropdown, or by importing a CSV with the correct mapping.
Can I migrate labels between different connectors, such as Google to Microsoft 365?
Sensitivity labels are a Microsoft 365 feature. Label discovery and mapping only work when the source connector is Microsoft 365. For migrations from Google Workspace, Box, or Dropbox, sensitivity labels do not apply.
Do I need to run Get Label List manually?
No. Label discovery runs automatically before every File, Site, or Group Get List when the source connector is Microsoft 365. You can also trigger it manually from the Label Mapping page to refresh labels independently.
What if a label is encrypted on the source but the target label is not?
Cloudiway maps the labels as configured, but the file on the target will not have encryption protection. Review the encryption status (lock icon) in the Label Mapping page and ensure equivalent protection is configured on the target tenant via the Microsoft Purview compliance portal.
Can I update label mappings after migration has started?
Yes, you can update mappings at any time. However, files already migrated are not retroactively updated. Only files migrated after the mapping change use the new target label. To re-apply labels to already-migrated files, re-trigger migration for those items.
How are sub-labels handled?
Sub-labels (child labels) are discovered and mapped independently from their parents. Each sub-label must have its own mapping to a target sub-label. The Hierarchy View in the Label Mapping page helps visualize the parent-child relationships.