Share via

Microsoft Information Protection - Attachment Label Overridden by Email Label | MIP

Rufus Daniel J 0 Reputation points
2026-04-20T07:43:24.3633333+00:00

Published Labels:

  • Severity 0 - Public: Can be shared with anyone
  • Severity 1 - Internal: Restricted to internal users only
  • Severity 2 - Confidential: Accessible to internal and authorized users only
  • Severity 3 - Highly Confidential: Strictly limited to internal and authorized users only

No inheritance enabled

Description:
During validation, we identified an issue related to label inheritance between emails and their attachments.

Expected Behavior:
If an email is labeled Confidential (Encrypted) and the attachment is already labeled Internal (Encrypted), the attachment should retain its original label and associated permissions.

Actual Behavior:
Attachments that are already labeled and encrypted are incorrectly inheriting the email’s label.

Example Scenario:

  • Email label: Confidential (Encrypted)
  • Attachment label: Internal (Encrypted)

Observed Result:
The attachment label is overridden and updated to match the email label, instead of preserving its original classification.

Additional Findings:
This behavior was tested across multiple tenants. Some tenants reflect this new behavior, while others continue to exhibit the expected behavior. This inconsistency suggests a possible recent change or phased rollout; however, no official documentation or communication has been identified.

Impact:
This issue may result in unintended changes to data classification and access permissions for attachments.

Request:
Kindly investigate and confirm whether this behavior is expected or a defect. Additionally, please clarify if this is part of a recent update or rollout, as no official documentation is currently available. Guidance or a resolution would be appreciated.

Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Most helpful
  1. SAI JAGADEESH KUDIPUDI 2,625 Reputation points Microsoft External Staff Moderator
    2026-04-20T08:34:22.61+00:00

    Hi Rufus Daniel J,
    Thank you for sharing this scenario — this is a valid concern, and I understand how unexpected label changes on attachments can impact classification and access controls.

    Based on current Microsoft Purview / Information Protection behavior, when an email is labeled with encryption, attachments added to that email can inherit the email’s encryption settings, even if the attachment was previously labeled and protected. This behavior is by design and is intended to ensure that all content leaving the mailbox maintains a consistent protection boundary, especially for encrypted emails and “Do Not Forward”–style labels.

    That said, the experience can appear inconsistent across tenants. Microsoft has introduced and enhanced label inheritance and enforcement through phased rollouts tied to Outlook native labeling and Purview policy updates, which explains why some tenants still observe the older behavior where attachments retain their original label.
    this means

    If the email label enforces encryption, the service may re‑protect attachments at send time using the email’s label.

    1. There is currently no supported tenant‑level setting to prevent attachment inheritance when encryption is applied through a sensitivity label.
      This behavior is not documented as a product defect at this time. To avoid unintended label changes on attachments, Microsoft recommends one of the following approaches:
      • Apply the final (highest required) sensitivity label directly to the file before attaching it to the email, ensuring permissions are already correct.
      • Share sensitive files via OneDrive or SharePoint instead of attaching them to encrypted emails, and provide access using links and permissions. This preserves the file’s original label and access model.
    2. Review your label strategy to confirm which email labels truly require encryption, and reserve encrypted labels for cases where attachment inheritance is acceptable.

    In summary, the behavior you’re seeing aligns with how Microsoft Purview enforces encryption for labeled emails. Differences across tenants are most likely due to service updates or policy enforcement changes, not misconfiguration. If this behavior causes compliance or operational concerns in your environment, raising a Microsoft support case would allow the Product Group to review your specific tenant configuration in detail.
    Microsoft references

    Email encryption in Microsoft Purview
    Sensitivity labels and encryption behavior
    Configure sensitivity label inheritance for emails and attachments

    Hope this helps. If you have any follow-up questions, please let me know. I would be happy to help.
    Please do not forget to "Accept Answer" and "up-vote" wherever the information provided helps you, as this can be beneficial to other community members.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.