Skip to content
Browse all topics
Microsoft Teams

Sensitivity labels for Teams meetings

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

How sensitivity labels apply to Teams meetings — controlling who can join, what's allowed, and how the meeting is protected.

5 min read

Share as imagePNG

Sensitivity labels in Microsoft Purview historically applied to files and emails. Microsoft has progressively extended them to Microsoft Teams meetings, letting organisations apply consistent protection to confidential conversations — and to the recordings, transcripts, and chats that come with them.

What sensitivity labels can enforce in meetings

When a label is applied to a meeting (either at scheduling time or auto-applied based on content), it can control:

  • Lobby behaviour — who can bypass the lobby, who must wait.
  • Anonymous join — allowed or blocked.
  • Phone dial-in — allowed or blocked.
  • Recording — disabled, enabled with watermark, end-to-end encryption.
  • Transcription — disabled, enabled.
  • Chat — disabled, restricted to participants, allowed.
  • Copy/paste of meeting links — restricted.
  • Watermarking of shared content and video (Teams Premium feature).
  • End-to-end encryption for the meeting media (Teams Premium).
  • Allowed participants — restricted to specific groups or people only.

The label drives a single coherent set of protections, configured once and applied consistently.

Why this matters

For confidential meetings — board discussions, M&A conversations, security incident response, customer-data reviews — these controls used to be ad-hoc:

  • Each organiser remembered to disable recording manually.
  • Each organiser configured the lobby manually.
  • Inconsistency meant occasional accidental leaks (the meeting that was recorded when it shouldn't have been).

With sensitivity labels, the organiser picks the label — "Confidential — Executive" — and the right protections apply. Consistent, audited, harder to mess up.

Configuration

In Purview, sensitivity labels can be scoped to Teams meetings:

  1. Create or edit a sensitivity label.
  2. Under scope, enable Teams meetings.
  3. Configure meeting protections — lobby, recording, chat, watermarking, end-to-end encryption, allowed-participants.
  4. Publish the label to relevant users / groups.

Users see the label in the Teams meeting scheduling UI; picking it applies the protections automatically.

Auto-application

Labels can be auto-applied based on:

  • Meeting subject matching specific patterns.
  • Participants (executives, specific groups).
  • Content classification (more limited for meetings than for files).

Auto-application catches the user-forgot-to-apply scenarios.

Audit

Every label application, change, and meeting event is logged in Purview audit — useful for forensic investigations and compliance evidence.

Operational considerations

  • Teams Premium is required for the most advanced protections — watermarks, end-to-end encryption for scheduled meetings, advanced lobby controls.
  • User experience — labelled meetings show their label in the meeting UI. Communicate to users what each label means and when to use it.
  • External participants — invited externals from other Microsoft 365 tenants honour the meeting protections (within their client's capabilities); external users from non-Microsoft systems may have a degraded experience.
  • Recording storage — recordings of labelled meetings inherit appropriate sensitivity labels on the underlying file, so retention and access controls follow.

Common patterns

  • Confidential — All Hands — recorded yes (for replay), anonymous no, watermarking yes.
  • Confidential — Executive — recording no, lobby strict, end-to-end encrypted, named participants only.
  • Confidential — Legal Privilege — extra-strict; named participants only, no recording, no transcription, no external join.

When this is the right tool

For organisations regularly running meetings about confidential matters — boards, executive committees, legal teams, security incident responders — sensitivity labels for meetings dramatically simplify the consistent application of protections. The setup time is small; the ongoing operational benefit is substantial.

For organisations running mostly low-sensitivity meetings, the default Teams meeting policies are usually enough.

Rollout order

The deployments that actually get used land in this sequence:

  1. Pilot with one label and one team. Create Confidential — Executive first, publish it only to the executive assistants and the executive team, use it on real meetings for a month before adding a second label.
  2. Watch what breaks. Anonymous joiners will hit the lobby when they used to walk straight in; recording will silently not start when the organiser thought it did. Fix the communication before enabling the label for broader groups.
  3. Add the auto-apply rule last. Auto-applying Confidential — Legal Privilege to any meeting whose subject contains "board" catches accidents and creates surprises. Ship the rule after the manual label is well understood.
  4. Extend to Teams and sites in the same pass. Meetings labels live inside a broader Purview taxonomy — publishing Confidential — Executive for meetings while Executive is a different label for documents produces confusion. Align the taxonomy first.

What the label cannot do

  • Retroactively protect an already-scheduled meeting if the label was not applied at scheduling. Change the label on the meeting series to update future occurrences; past ones are unchanged.
  • Enforce anything on a fully external meeting where the organiser is in another tenant. The organiser's tenant policies apply.
  • Prevent screen recording on the endpoint. Watermarking is a deterrent, not an enforcement — screen recording by a determined user cannot be stopped by Teams.
  • Encrypt recordings end-to-end in the same way as live media. Recordings go to Stream on SharePoint and inherit file-level sensitivity, which is a different protection model.

Common wrong turns

  • Enabling every protection on every label. Anonymous-block, dial-in-block, external-block, and end-to-end encryption on Confidential — General locks out legitimate business meetings. Reserve the strict protections for the labels that need them.
  • Skipping the user-education pass. Users who pick Confidential — Executive for their weekly stand-up produce noise. The label description in the picker matters — write it as the guidance a colleague would give.
  • Ignoring recording-file inheritance. The meeting label sets protection on the meeting; the recording file inherits a sensitivity label on the SharePoint site it lands in. Publish a compatible site-scoped label so the recording is protected in storage, not just in the call.
  • Not planning for third-party endpoints. SIP-connected room systems and some certified devices can lose functionality with strict labels. Test on the actual hardware before enforcing.

Signals worth watching

  • Purview audit → SensitivityLabelApplied events on Teams.Meeting object types — the operational log of who is labelling what.
  • Teams admin center → Meetings → Reports for meetings where recording was blocked, watermark was enabled, anonymous joiners were rejected — the enforcement view.
  • Support ticket volume in the first two weeks after each rollout wave — expect a spike; if it does not settle, the label is too aggressive for its audience.

Frequently asked questions

Can I apply a sensitivity label to a Teams meeting?
Yes — once the label is scoped to Teams meetings in Purview and published to the organiser, they can pick it in the Teams scheduling UI. The label then drives lobby behaviour, recording, transcription, chat, watermarking, end-to-end encryption, and allowed-participants settings for that specific meeting.
Do meeting sensitivity labels need Teams Premium?
The label itself needs a Purview P1 or E5 licence. Advanced protections — watermarking, end-to-end encryption for scheduled meetings, some advanced lobby controls — need Teams Premium per organiser. Basic lobby, recording, and chat controls work without Premium.
How do meeting labels behave for external participants?
Guests from other Microsoft 365 tenants honour the meeting label's protections within their own client's capabilities. Anonymous joiners get the lobby experience the label enforces. Third-party clients (some SIP endpoints, older VTC systems) may be blocked from labelled meetings if the label restricts anonymous or SIP dial-in.

Was this useful?

Spot something wrong or want a topic covered? Send it through the contact form.