Create and apply MSIP labeled classifications mapped to LabelInfo stream using Custom Property (Trellix DLP Network)

Prev Next

You can use Custom property in MSIP labeled classifications to identify and track sensitive content in co-authored and auto-save enabled documents using Labelinfo. Use the Labelinfo in MSIP classifications to read MIP label information or metadata in co-authored and auto-save enabled document.

  1. Make sure that your Azure server is defined in Registered Servers in ePO - On-prem. For more information about registering Azure servers, see Configure the registered Azure server in ePO - On-prem for Microsoft Information Protection with Trellix DLP Network.

  2. Create and configure sensitivity labels and their policies in Microsoft Purview. For more information, see https://learn.microsoft.com/en-us/microsoft-365/compliance/create-sensitivity-labels?view=o365-worldwide#create-and-configure-sensitivity-labels.

  3. Get Label IDs of sensitivity labels needed to create MSIP labels (Labelinfo stream). See, https://learn.microsoft.com/en-us/powershell/module/exchange/get-label?view=exchange-ps.

  1. Create a classification definition with MSIP label:

    1. In ePO - On-prem, go to MenuData ProtectionClassificationDefinitions.

    2. Under the Data category, click Document Properties and click ActionsNew Item.

    3. Click Custom Property. In the Custom property dialog box, enter MSIP_Label_<labelID>_Enabled and click Add and then OK.

    4. For each of the MSIP_Label_<labelID>_Enabled document property, enter the comparison as EQUALS and the value as True and click Save.

    MSIP labels with the sensitivity label IDs are created.

  2. Include the MSIP Labelinfo in a classification:

    1. To a create a new classification, navigate to MenuData ProtectionClassification or you an edit an existing classification.

    2. Click New Classification and type a unique name and an optional description. Click Save.

    3. Click Actions, then select New Content Classification Criteria.

    4. Browse to File conditionsDocument Properties. Click ... to select the MSIP label created in Step 1.

    5. Enter a name for the classification criteria and click Save.

    In the Automatic Classification field, you can see the newly created MSIP classification criteria.

  3. Create an Email protection rule or Web protection rule using the classification with MSIP label.

    For information about how to create a rule, see Create a rule with classification grouping.

  4. Assign the rule to a rule set and then assign the rule set to policies.

    See, Create a rule set.