Sensitivity Label Migration

10 min read Updated on June 4, 2026 Cloudiway Team

Overview

Microsoft Purview sensitivity labels classify and protect documents, spreadsheets, presentations, and other files in a Microsoft 365 tenant. Labels are tenant-specific: a label that exists in the source tenant does not automatically exist in the target tenant. Without explicit handling, files arrive at the destination without any classification — and encrypted files become inaccessible because the encryption keys are bound to the source tenant's Azure Rights Management service.

Cloudiway's Sensitivity Label Migration solves this by migrating labels alongside the files. Before migration, Cloudiway reads the label catalogue from both tenants and lets you define a mapping between source and target labels. During migration, each file's label is looked up in that mapping and the corresponding target label is applied to the migrated file. Encrypted documents are re-protected with the target tenant's encryption policy, ensuring they remain accessible to users on the new tenant.

Applies to

File Migration (OneDrive, SharePoint) and Site Migration between Microsoft 365 tenants. Sensitivity label migration requires Microsoft 365 connectors on both the source and the target.

Prerequisites

  • Source connector must be Microsoft 365 (OneDrive / SharePoint)
  • Microsoft Graph API application must have the InformationProtectionPolicy.Read.All permission
  • For reading file-level labels: the Files.Read.All permission
  • Sensitivity labels must be published in the Microsoft Purview compliance portal on both tenants
  • Target connector should be Microsoft 365 for automatic target label discovery (optional — manual mapping is always available)

How It Works

The process flows through four stages: Discover Labels → Auto-Match by Name → Review & Map → Migrate with Labels. The sensitivity label migration itself consists of three phases.

Phase 1 — Label catalogue synchronisation

Cloudiway connects to the Microsoft Graph API on both the source and target tenants to retrieve all published sensitivity labels, including their hierarchy (parent and sub-labels), encryption settings, priority, and descriptions. This step runs automatically when you run a Get List for File, Site, or Group migrations. You can also trigger it manually from the Label Mapping page to refresh the catalogue independently.

Phase 2 — Mapping

Cloudiway automatically matches source labels to target labels by name (case-insensitive). If both tenants have a label named "Confidential", they are automatically linked. Labels that cannot be auto-matched remain unmapped and must be resolved manually in the Label Mapping page before migration starts. Bulk mapping via CSV import is available for tenants with a large number of labels.

Phase 3 — Migration

During file migration, Cloudiway reads the sensitivity label of each source file, looks it up in the mapping table, and applies the corresponding target label to the migrated file. For encrypted files, the target label's Azure Rights Management policy is applied, re-protecting the document with the target tenant's encryption keys so it remains accessible to users on the new tenant. If a source label has no mapping, the file is migrated without a label and a warning is logged.

Step-by-Step Guide

  1. Configure Microsoft 365 connectors. Set up source and target connector pools with the required Microsoft Graph API permissions. The application registration must have the InformationProtectionPolicy.Read permission to read sensitivity labels.
  2. Run Get List (automatic discovery). Navigate to Files > Users (or Sites > Site List) and click Get List. If the source connector is Microsoft 365, sensitivity labels are automatically discovered from both tenants before the user/site listing begins.
  3. Review the Label Mapping page. Go to Files > Label Mapping. You will see all source labels with their auto-matched target labels. The Status column shows Mapped (ready to migrate) or Unmapped (needs attention).
  4. Map unmapped labels. Click Edit on any unmapped label. Choose a target label from the dropdown list (populated from the target tenant's labels), or switch to freestyle mode to enter the target label ID and name manually. Click Save.
  5. Verify encryption alignment. Check the encryption icons next to each label — a locked icon indicates encryption, an open icon indicates no encryption. Ensure encrypted source labels are mapped to target labels with equivalent encryption configured in the target tenant's Microsoft Purview compliance portal.
  6. Start migration. Proceed with your file or site migration as usual. Cloudiway will apply the mapped sensitivity labels to each migrated file automatically.

Label Mapping Page Features

Feature Description
Get List Manually trigger label discovery. Select a source pool (required) and optionally a target pool. Only Microsoft 365 connectors are shown.
Export CSV Download the current mapping as a CSV file for offline review or editing.
Import CSV Upload a CSV file to bulk-update label mappings. The CSV must contain ExternalLabelId and TargetExternalLabelId columns.
Hierarchy View Toggle between a flat list and a hierarchical view that shows parent labels with their sub-labels indented below.
Inline Edit Click Edit to modify a mapping. Choose from a dropdown of target labels or switch to freestyle text input for custom IDs.
Help Click the ? icon in the page title for contextual documentation.

Understanding Sensitivity Labels

Label Hierarchy

Sensitivity labels in Microsoft 365 can be organized in a parent-child hierarchy. For example:

  • Confidential (parent)
    • Confidential \ All Employees
    • Confidential \ Anyone (unrestricted)
  • Highly Confidential (parent)
    • Highly Confidential \ All Employees
    • Highly Confidential \ Specific People

Cloudiway discovers and preserves this hierarchy. When using the Hierarchy View in the Label Mapping page, sub-labels are displayed indented under their parent.

Encryption

Some sensitivity labels apply encryption (Azure Rights Management) to protect file content. These labels are marked with a lock icon in the Cloudiway interface. When mapping encrypted labels:

  • The target label should have equivalent encryption settings configured
  • Users on the target tenant must have the appropriate permissions to open encrypted files
  • Encryption policies are managed in the Microsoft Purview compliance portal, not in Cloudiway

Priority

Each label has a priority number that determines precedence when multiple labels could apply. The priority is displayed in the Label Mapping page for reference but does not affect the migration mapping logic.

Important Notes

Unmapped labels are not applied on the target

If a source file has a sensitivity label that is not mapped, the file is migrated successfully but without a sensitivity label on the target tenant. A warning is logged.

Verify mappings before starting migration

Incorrect label mappings cannot be retroactively fixed by re-running the migration. Delta passes only detect changes in the source document. If a label mapping is corrected after migration, files that were already migrated will not have their labels updated automatically.

Auto-discovery runs before every Get List

When you run a File, Site, or Group Get List with a Microsoft 365 source, labels are automatically refreshed. New labels added to either tenant are picked up and auto-matched.

CSV import for bulk mapping

For tenants with many labels, export the mapping to CSV, fill in the target label IDs in a spreadsheet, and import it back. This is faster than editing labels one by one.

Frequently Asked Questions

What happens if the source and target labels have different names?

Auto-matching works by exact name comparison (case-insensitive). If names differ, the label appears as unmapped. You can manually map it by clicking Edit and selecting the correct target label from the dropdown, or by importing a CSV with the correct mapping.

Can I migrate labels between different connectors, such as Google to Microsoft 365?

Sensitivity labels are a Microsoft 365 feature. Label discovery and mapping only work when the source connector is Microsoft 365. For migrations from Google Workspace, Box, or Dropbox, sensitivity labels do not apply.

Do I need to run Get Label List manually?

No. Label discovery runs automatically before every File, Site, or Group Get List when the source connector is Microsoft 365. You can also trigger it manually from the Label Mapping page to refresh labels independently.

What if a label is encrypted on the source but the target label is not?

Cloudiway maps the labels as configured, but the file on the target will not have encryption protection. Review the encryption status (lock icon) in the Label Mapping page and ensure equivalent protection is configured on the target tenant via the Microsoft Purview compliance portal.

Can I update label mappings after migration has started?

Yes, you can update mappings at any time. However, files already migrated are not retroactively updated. Only files migrated after the mapping change use the new target label. To re-apply labels to already-migrated files, re-trigger migration for those items.

How are sub-labels handled?

Sub-labels (child labels) are discovered and mapped independently from their parents. Each sub-label must have its own mapping to a target sub-label. The Hierarchy View in the Label Mapping page helps visualize the parent-child relationships.

Was this article helpful?

Need more help? Contact our support team

We value your feedback

Help us improve your experience

What would you like to share with us?

Need direct support? Open a ticket