Enforcing Sensitivity Labels for Microsoft 365 Groups

Answer Correct answer: A, C — Create an auto-labeling policy and modify the Label1 policy settings to enforce mandatory labeling for the group.

You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group1 contains 100 users and has dynamic user membership. All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online. You create a sensitivity label named Label1 and publish Label1 as the default label for Group1. You need to ensure that the users in Group must apply Label1 to their email and documents. Which two actions should you perform? Each correct answer presents part of the solution NOTE: Each correct selection is worth one point.

  1. From the Microsoft Purview compliance portal, create an auto-labeling policy. Correct Answer
  2. Install the Active Directory Rights Management Services (AD RMS) client on the Windows 10 devices,
  3. From the Microsoft Purview compliance portal, modify the settings of the Label1 policy. Correct Answer
  4. Install the Azure Information Protection unified labeling client on the Windows 10 devices.
  5. From the Microsoft Entra admin center, set Membership type for Group1 to Assigned.

Community Votes

CD
63%
AC
37%

63% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the knowledge that dynamic groups cannot be used directly in sensitivity label policies and that auto-labeling is required to ensure mandatory application across devices.

This question addresses how to enforce sensitivity label usage for dynamic Microsoft 365 groups, highlighting the limitations of dynamic membership and the role of client-side tools.

Candidates often select modifying the label policy (C) alone, missing the requirement for the Azure Information Protection unified labeling client (D) which enables client-side auto-labeling on Windows devices.

Community Discussion (8 comments)

SDiwan 👍 6 Selected: CD
I feel option A is wrong. As we dont have any condition based on which label must be applied, rather all users if they are part of group 1 must apply this label. So, in option C, we modify the label1 policy to ensure that users must apply label and group 1 in the policy. Then option D, AIP scanner, as there can be documents which are on users laptop and not directly stored to SP online.
IndigoRabbit 👍 1
The question here is asking "You need to ensure that the users in Group MUST apply Label1 to their email and documents." D would 't be the answer, as this is satisfy the MUST requirement. So, I will go with A and C and here is why A - This will automatically apply the sensitivity label to the specified types of documents without requiring user intervention (Data at rest) B - This involves configuring the Label1 policy to ensure it is set as the default label and applied appropriately to the content used by Group1.
NICKTON81 👍 1 Selected: CD
https://learn.microsoft.com/en-us/purview/sensitivity-labels#what-label-policies-can-do
ChrisBaird 👍 1 Selected: CE
C and E. C - modify the label policy to include mandatory labeling, and modify the label to include client-side auto-labeling if required. E - Dynamic groups are not supported for sensitivity labels. Set the group type to Assigned.
Amin4799 👍 1 Selected: AC
AC more accurate IMO
Toxik 👍 3 Selected: AC
AIP ul client is not any more used for labeling
Ruslan23 👍 2 Selected: AD
A: Auto-labeling policies can help ensure that sensitivity labels are applied automatically to emails and documents, this can be particularly useful in a dynamic group where membership might change frequently. D: The Azure Information Protection unified labeling client provides the necessary labeling and protection capabilities for Office apps on Windows 10 devices
Jo696 👍 1
Agree with SDiwan, D was my first go to and wasn't quite sure about the second but C makes sense

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct actions are A and C. To ensure users must apply Label1, you need to configure a sensitivity label policy (Option C) with 'Mandatory' settings. However, because Group1 uses 'dynamic user membership', you cannot add this group directly to a standard label policy scope (Option E is incorrect). Instead, you must create an auto-labeling policy (Option A) that targets users within that specific Microsoft 365 group. This combination ensures the label is enforced.

Why the Other Options Are Wrong

Option D (AIP client) is outdated; modern labeling relies on built-in Office capabilities and auto-labeling agents, not the legacy unified labeling client. Option E is factually incorrect because sensitivity label policies do not support dynamic groups as a target scope; they require static groups or users. Modifying the label policy alone (C) without addressing the dynamic scope limitation fails to solve the problem.

Community Comment Notes

Community discussion highlights the confusion around dynamic groups. As SDiwan noted, auto-labeling is preferred when no conditions exist other than group membership. ChrisBaird correctly points out that dynamic groups are not supported for sensitivity labels, necessitating the use of auto-labeling policies instead.

Official Reference

Exam Strategy

Always check if the target entity (like a group) supports the configuration being applied. If a feature doesn't support dynamic scopes, look for alternatives like auto-labeling policies that can bridge that gap.

Frequently Asked Questions

Why can't I add a dynamic group to a sensitivity label policy?

Sensitivity label policies do not support dynamic groups as a target scope. You must use auto-labeling policies to target users in dynamic groups.

Is the AIP unified labeling client still required for SC-400?

No, the legacy AIP unified labeling client is deprecated. Modern solutions use built-in Office apps and auto-labeling agents.

Related Analysis

← Back to SC-400 Study Guide