First Step to Deploy an Auto-Labeling Policy for Encrypted Emails?

Implement Microsoft Purview information protection and data lifecycle management
Answer Correct answer: A — Run the auto-labeling policy in simulation mode first, then review the matched sensitive information before turning the policy on.

You have a Microsoft 365 E5 tenant. You create an auto-labeling policy to encrypt emails that contain a sensitive info type. You specify the locations where the policy will be applied. You need to deploy the policy. What should you do first?

  1. Run the policy in simulation mode. Correct Answer
  2. Turn on co-authoring for files with sensitivity labels.
  3. Review the sensitive information in Activity explorer.
  4. Turn on the policy.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the deployment sequence for a Microsoft Purview auto-labeling policy, and the common trap is treating 'deploy' as immediately turning the policy on instead of validating it in simulation mode first.

Auto-labeling policies in Microsoft Purview can encrypt emails that contain a sensitive info type after you specify their locations, and the policy must first run in simulation mode before it is deployed. This page establishes that simulation mode (A) is the required first step, with expert analysis and community consensus.

The most common wrong choice is D, turning on the policy immediately, because learners equate deploying the policy with enabling enforcement and skip the simulation mode review that Microsoft's auto-labeling workflow expects.

Community Discussion (3 comments)

Ody 👍 3 Selected: A
The only options are Simulation Mode and Off. On the Simulation mode there is an option to default it to "on" after 7 days.
Khanbaba43 👍 2 Selected: A
Repeated question. Answer: A
Murad01 👍 3
Repeated question in previous section. Given answer is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Purview auto-labeling policies are deployed through a controlled workflow: after you define the sensitive info type and locations, the policy first runs in simulation mode so that matching emails are identified without applying the encryption label. Simulation mode lets you review what would be encrypted, adjust the rule if needed, and then turn the policy on or let it auto-enable after seven days. Because the question asks what to do first to deploy the policy, running it in simulation mode (A) is the correct action. Community voters and commenters, including Ody and Khanbaba43, consistently select A for this reason.

Why the Other Options Are Wrong

Option B is unrelated: turning on co-authoring for files with sensitivity labels affects file collaboration and does not deploy an email auto-labeling policy. Option C is a monitoring step; Activity explorer can show label activity, but it is not the required first action to deploy the policy, and it does not validate the new auto-labeling rule before enforcement. Option D is the later stage: turning on the policy enforces encryption immediately, so doing that first skips the simulation and review step that Microsoft's auto-labeling workflow expects.

Community Comment Notes

Ody explained that "The only options are Simulation Mode and Off" and noted that simulation mode includes an option to default the policy to on after seven days, which matches the Microsoft Purview deployment model. Murad01 called this a repeated question and said the "Given answer is correct", reinforcing that the source key aligns with product behavior. Khanbaba43 also wrote "Repeated question. Answer: A", and the unanimous A votes reflect the same consensus without contradicting the official workflow.

Official Reference

Exam Strategy

When you see an auto-labeling deployment question, look for the validation step before enforcement: create the policy, run it in simulation mode, review the matches, then turn it on. Do not choose co-authoring or Activity explorer unless the question specifically asks about file collaboration or post-deployment monitoring.

Frequently Asked Questions

Why should an auto-labeling policy run in simulation mode before turning it on?

Simulation mode identifies which emails match the sensitive info type and would be encrypted, letting you validate the rule without enforcing encryption prematurely.

What is the difference between simulation mode and turning on the auto-labeling policy?

Simulation mode only reports matches and does not apply encryption; turning the policy on enforces the sensitivity label and encryption on matching emails.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide