---
name: Purview Label Coverage
description: Scans SharePoint libraries for the proportion of documents carrying a Purview sensitivity label and flags libraries with unlabelled sensitive content.
lastReviewed: 2026-10-01
---

# Purview Label Coverage

> **TL;DR:** This skill reports what proportion of documents in SharePoint libraries carry a Microsoft Purview sensitivity label, reading label metadata without changing labels or content. It flags libraries with many unlabelled contracts, invoices and HR records so you can prioritise remediation.

## How does the Purview Label Coverage skill measure sensitivity labelling?

This skill scans the document libraries in the sites in scope and reports the proportion of documents that carry a Microsoft Purview sensitivity label versus those that do not. It works from file and label metadata, calculates coverage per library, and identifies libraries with high concentrations of unlabelled sensitive content (contracts, invoices, HR records and financial spreadsheets) that should carry a label but currently do not. Labels matter for Agentic AI and Microsoft 365 Copilot readiness because Copilot and agents recognise and respect sensitivity labels on the content they use.

## When should you run this skill?

- "Check Purview label coverage"
- "Where are our unlabelled documents?"
- "Run a sensitivity label gap report"

## How this skill works, step by step

1. Enumerate document libraries in the sites in scope
2. For each library, count: total documents, labelled documents, unlabelled documents
3. Within unlabelled, flag content types that strongly suggest sensitivity: contracts, invoices, HR records, financial spreadsheets (a heuristic defined by this skill, based on file names and content types)
4. Calculate coverage % per library
5. Rank libraries with coverage below 70% as priority for remediation (70% is this skill's default threshold, not a Microsoft figure; adjust it to your target)

## Output format

| Site | Library | Total | Labelled | Unlabelled | Coverage % | Priority |
| --- | --- | --- | --- | --- | --- | --- |

Followed by a summary:

- Average label coverage: N%
- Libraries below 70%: N
- Estimated sensitive-content gaps: N

## Scope and safety

Read-only in intent: it makes no changes to labels, permissions or content. The Graph extractSensitivityLabels call is a POST that may refresh SharePoint's stored label metadata for the item. It does NOT:

- Apply, change or remove sensitivity labels (remediate with Microsoft Purview auto-labelling policies)
- Retrieve or analyse document contents
- Make changes in the Microsoft Purview portal

Known limits when reading label state through Microsoft Graph:

- The extractSensitivityLabels API works only for supported file extensions. Report files with unsupported extensions as "not assessed" and exclude them from the coverage denominator.
- It may read the label from the file service-side if stored metadata is out of date.
- It returns 423 Locked for files that are double-key encrypted or cannot be decrypted by SharePoint, so report those files as "not assessed" rather than "unlabelled".
- It is not supported for Microsoft SharePoint Embedded containers.

## Licensing and permissions

### Licences and add-ons

| Capability used | Minimum licence |
| --- | --- |
| Create sensitivity labels and apply them manually in Office and SharePoint files | Microsoft 365 E3 |
| Default labels for SharePoint libraries | Microsoft 365 E5, Microsoft 365 E5 Compliance or Microsoft 365 E5 Information Protection and Governance (per the Microsoft Purview service description) |
| Automatic labelling | Microsoft 365 E5, E5 Compliance, E5 Information Protection and Governance or Azure Information Protection Premium P2 (per the auto-labelling page) |

Service-side auto-labelling policies for SharePoint, OneDrive and Exchange are not available in every region. If the Auto-labeling page is missing in the Microsoft Purview portal, your tenant's region is unsupported.

### Least-privilege roles

- Sensitivity Label Reader: read-only access to sensitivity label configuration in the Microsoft Purview portal
- Global Reader: read-only Microsoft Entra role that can view settings across Microsoft 365, including the Microsoft Purview portal

### Microsoft Graph permissions (read-only)

- Listing sites and drives needs further Graph permissions not covered by the pages cited here; confirm them in the Microsoft Graph permissions reference
- `Files.Read.All` is the least-privileged permission documented for `driveItem: extractSensitivityLabels`, which returns the sensitivity labels on a file (`Sites.Read.All` is also accepted for this call)
- `InformationProtectionPolicy.Read.All` (application) reads the organisation's sensitivity label definitions through the beta sensitivityLabels endpoint; the v1.0 tenant endpoint lists `SensitivityLabel.Read` and `SensitivityLabels.Read.All` instead. Confirm which endpoint you use before granting consent

Sensitivity label configuration is administered in the Microsoft Purview portal; this skill only reads label state via Microsoft Graph.

## Related skills

- [Data Classification and SIT Coverage](/purview/data-classification-sit-coverage): before: reports how often sensitive information types and trainable classifiers match content
- [Tenant DLP Coverage and Effectiveness Audit](/purview/tenant-dlp-coverage-audit): after: shows where Data Loss Prevention policies protect sensitive data across workloads
- [SharePoint Oversharing Audit](/sharepoint/sharepoint-oversharing-audit): after: flags external or Anyone access on SharePoint Online
- [DSPM for AI Remediation](/purview/dspm-for-ai-remediation): after: turns a DSPM for AI assessment into an owner-assigned remediation checklist
- [Microsoft 365 Copilot Readiness Guide for SharePoint and Data](/sharepoint/copilot-readiness-guide): pillar: readiness means fixing oversharing before Microsoft 365 Copilot surfaces content

## Notes

- Remediation: pair with Microsoft Purview auto-labelling policies (Microsoft Purview portal > Solutions > Information Protection > Policies > Auto-labeling policies)
- [Learn about sensitivity labels](https://learn.microsoft.com/en-us/purview/sensitivity-labels)
- [Get started with sensitivity labels (licensing and permissions)](https://learn.microsoft.com/en-us/purview/get-started-with-sensitivity-labels)
- [Automatically apply a sensitivity label to Microsoft 365 data](https://learn.microsoft.com/en-us/purview/apply-sensitivity-label-automatically)
- [driveItem: extractSensitivityLabels (Microsoft Graph)](https://learn.microsoft.com/en-us/graph/api/driveitem-extractsensitivitylabels?view=graph-rest-1.0)
- [Permissions in the Microsoft Purview portal](https://learn.microsoft.com/en-us/purview/purview-permissions)
- [Microsoft Purview service description](https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-purview-service-description)
