Teams Sensitivity Labels for Incident Data Prompt
Apply Microsoft Purview sensitivity labels and container labels to Teams incident channels so war-room chats, shared files, and postmortems are auto-classified, encrypted, and guest-access controlled by default.
- Target user
- Security and compliance engineers governing Teams incident data
- Difficulty
- Beginner
- Tools
- Claude, ChatGPT
The prompt
You are a security and compliance engineer who has applied Microsoft Purview sensitivity labels to Teams incident channels so sensitive war-room content is protected by default, without slowing responders down. I will provide: - The incident-channel provisioning flow (template, Graph API, Power Automate) - Data classes that show up in incidents (customer PII, secrets, security findings) - Existing Purview labels and whether container labeling is enabled - Guest/partner access requirements during incidents Your job: 1. **Label taxonomy** — recommend a small, legible set of labels for incident work (e.g., General, Confidential, Highly Confidential / Security-Sensitive) and explain the difference between item labels (on messages/files) and container labels (on the Team/group controlling privacy, guest access, and unmanaged-device access). 2. **Default-by-template** — when an incident channel/Team is provisioned, apply the appropriate container label automatically so guest access and external sharing are restricted from minute one; show where this hooks into the provisioning flow. 3. **Auto-labeling** — define auto-label policies that classify files and messages containing customer PII or security findings, and the protective actions (encryption, access scoping) each label triggers. 4. **Guest access trade-off** — reconcile the need to pull in a vendor during an incident with the container label that blocks guests; document the approved exception path rather than disabling the label. 5. **Postmortem handling** — ensure the exported/SharePoint postmortem inherits or is re-labeled correctly so the writeup isn't more open than the incident itself. 6. **Monitoring** — use Purview audit/activity explorer to catch mislabeled or downgraded incident content and alert. 7. **Responder UX** — keep it frictionless: sensible defaults, minimal prompts, clear guidance so engineers don't fight the labels mid-incident. Output as: (a) the recommended label set with item-vs-container roles, (b) the provisioning hook for default container labeling, (c) the auto-label policy definitions, (d) the guest-exception process, (e) the postmortem labeling rule, (f) the monitoring/alert plan. Bias toward: secure defaults at provisioning, a documented exception path over disabled controls, minimal responder friction.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Audit Teams Membership and Ownership via Graph Prompt
Generate a Microsoft Graph audit script that reports owners, members, and guests across every Team so you can catch ownerless teams, over-privileged guests, and stale service teams before they become a compliance finding.
-
Microsoft Graph Export API for Teams eDiscovery Compliance Prompt
Build a compliance-grade exporter that pulls Teams messages and chats through the Graph protected (export) APIs for eDiscovery and legal hold, without consuming per-user seeded license quota.
-
Teams Meeting Watermark and Protected Content Policy Prompt
Design and roll out a Teams meeting policy that applies watermarks and end-to-end protection to sensitive incident war-room meetings, balancing security against app and recording limitations.
-
Teams Channel Archival & Lifecycle Policy Prompt
Design a Teams channel lifecycle policy — naming conventions, sprawl prevention, automated dormancy detection, archival, restoration, and deletion — with compliance retention.
More Microsoft Teams prompts & error guides
Browse every Microsoft Teams prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.