Enforcing Sensitivity Labels for Microsoft 365 Groups
You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group1 contains 100 users and has dynamic user membership. All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online. You create a sensitivity label named Label1 and publish Label1 as the default label for Group1. You need to ensure that the users in Group must apply Label1 to their email and documents. Which two actions should you perform? Each correct answer presents part of the solution NOTE: Each correct selection is worth one point.
Community Votes
63% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the knowledge that dynamic groups cannot be used directly in sensitivity label policies and that auto-labeling is required to ensure mandatory application across devices.
This question addresses how to enforce sensitivity label usage for dynamic Microsoft 365 groups, highlighting the limitations of dynamic membership and the role of client-side tools.
Candidates often select modifying the label policy (C) alone, missing the requirement for the Azure Information Protection unified labeling client (D) which enables client-side auto-labeling on Windows devices.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct actions are A and C. To ensure users must apply Label1, you need to configure a sensitivity label policy (Option C) with 'Mandatory' settings. However, because Group1 uses 'dynamic user membership', you cannot add this group directly to a standard label policy scope (Option E is incorrect). Instead, you must create an auto-labeling policy (Option A) that targets users within that specific Microsoft 365 group. This combination ensures the label is enforced.Why the Other Options Are Wrong
Option D (AIP client) is outdated; modern labeling relies on built-in Office capabilities and auto-labeling agents, not the legacy unified labeling client. Option E is factually incorrect because sensitivity label policies do not support dynamic groups as a target scope; they require static groups or users. Modifying the label policy alone (C) without addressing the dynamic scope limitation fails to solve the problem.Community Comment Notes
Community discussion highlights the confusion around dynamic groups. As SDiwan noted, auto-labeling is preferred when no conditions exist other than group membership. ChrisBaird correctly points out that dynamic groups are not supported for sensitivity labels, necessitating the use of auto-labeling policies instead.Official Reference
Exam Strategy
Always check if the target entity (like a group) supports the configuration being applied. If a feature doesn't support dynamic scopes, look for alternatives like auto-labeling policies that can bridge that gap.
Frequently Asked Questions
Why can't I add a dynamic group to a sensitivity label policy?
Sensitivity label policies do not support dynamic groups as a target scope. You must use auto-labeling policies to target users in dynamic groups.
Is the AIP unified labeling client still required for SC-400?
No, the legacy AIP unified labeling client is deprecated. Modern solutions use built-in Office apps and auto-labeling agents.