Purview Label Coverage
TL;DR: This skill reports what proportion of documents in SharePoint libraries carry a Microsoft Purview sensitivity label, reading label metadata without changing labels or content. It flags libraries with many unlabelled contracts, invoices and HR records so you can prioritise remediation.
How does the Purview Label Coverage skill measure sensitivity labelling?
This skill scans the document libraries in the sites in scope and reports the proportion of documents that carry a Microsoft Purview sensitivity label versus those that do not. It works from file and label metadata, calculates coverage per library, and identifies libraries with high concentrations of unlabelled sensitive content (contracts, invoices, HR records and financial spreadsheets) that should carry a label but currently do not. Labels matter for Agentic AI and Microsoft 365 Copilot readiness because Copilot and agents recognise and respect sensitivity labels on the content they use.
When should you run this skill?
- “Check Purview label coverage”
- “Where are our unlabelled documents?”
- “Run a sensitivity label gap report”
How this skill works, step by step
- Enumerate document libraries in the sites in scope
- For each library, count: total documents, labelled documents, unlabelled documents
- Within unlabelled, flag content types that strongly suggest sensitivity: contracts, invoices, HR records, financial spreadsheets (a heuristic defined by this skill, based on file names and content types)
- Calculate coverage % per library
- Rank libraries with coverage below 70% as priority for remediation (70% is this skill’s default threshold, not a Microsoft figure; adjust it to your target)
Output format
| Site | Library | Total | Labelled | Unlabelled | Coverage % | Priority |
|---|
Followed by a summary:
- Average label coverage: N%
- Libraries below 70%: N
- Estimated sensitive-content gaps: N
Scope and safety
Read-only in intent: it makes no changes to labels, permissions or content. The Graph extractSensitivityLabels call is a POST that may refresh SharePoint’s stored label metadata for the item. It does NOT:
- Apply, change or remove sensitivity labels (remediate with Microsoft Purview auto-labelling policies)
- Retrieve or analyse document contents
- Make changes in the Microsoft Purview portal
Known limits when reading label state through Microsoft Graph:
- The extractSensitivityLabels API works only for supported file extensions. Report files with unsupported extensions as “not assessed” and exclude them from the coverage denominator.
- It may read the label from the file service-side if stored metadata is out of date.
- It returns 423 Locked for files that are double-key encrypted or cannot be decrypted by SharePoint, so report those files as “not assessed” rather than “unlabelled”.
- It is not supported for Microsoft SharePoint Embedded containers.
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Create sensitivity labels and apply them manually in Office and SharePoint files | Microsoft 365 E3 |
| Default labels for SharePoint libraries | Microsoft 365 E5, Microsoft 365 E5 Compliance or Microsoft 365 E5 Information Protection and Governance (per the Microsoft Purview service description) |
| Automatic labelling | Microsoft 365 E5, E5 Compliance, E5 Information Protection and Governance or Azure Information Protection Premium P2 (per the auto-labelling page) |
Service-side auto-labelling policies for SharePoint, OneDrive and Exchange are not available in every region. If the Auto-labeling page is missing in the Microsoft Purview portal, your tenant’s region is unsupported.
Least-privilege roles
- Sensitivity Label Reader: read-only access to sensitivity label configuration in the Microsoft Purview portal
- Global Reader: read-only Microsoft Entra role that can view settings across Microsoft 365, including the Microsoft Purview portal
Microsoft Graph permissions (read-only)
- Listing sites and drives needs further Graph permissions not covered by the pages cited here; confirm them in the Microsoft Graph permissions reference
Files.Read.Allis the least-privileged permission documented fordriveItem: extractSensitivityLabels, which returns the sensitivity labels on a file (Sites.Read.Allis also accepted for this call)InformationProtectionPolicy.Read.All(application) reads the organisation’s sensitivity label definitions through the beta sensitivityLabels endpoint; the v1.0 tenant endpoint listsSensitivityLabel.ReadandSensitivityLabels.Read.Allinstead. Confirm which endpoint you use before granting consent
Sensitivity label configuration is administered in the Microsoft Purview portal; this skill only reads label state via Microsoft Graph.
Related skills
- Data Classification and SIT Coverage: before: reports how often sensitive information types and trainable classifiers match content
- Tenant DLP Coverage and Effectiveness Audit: after: shows where Data Loss Prevention policies protect sensitive data across workloads
- SharePoint Oversharing Audit: after: flags external or Anyone access on SharePoint Online
- DSPM for AI Remediation: after: turns a DSPM for AI assessment into an owner-assigned remediation checklist
- Microsoft 365 Copilot Readiness Guide for SharePoint and Data: pillar: readiness means fixing oversharing before Microsoft 365 Copilot surfaces content
Notes
- Remediation: pair with Microsoft Purview auto-labelling policies (Microsoft Purview portal > Solutions > Information Protection > Policies > Auto-labeling policies)
- Learn about sensitivity labels
- Get started with sensitivity labels (licensing and permissions)
- Automatically apply a sensitivity label to Microsoft 365 data
- driveItem: extractSensitivityLabels (Microsoft Graph)
- Permissions in the Microsoft Purview portal
- Microsoft Purview service description
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-10-01 · Published 2026-06-02