Skip to main content

Purview sensitivity label and label policy CRUD tools

Add full CRUD coverage (list, get, create, update, delete, each with its own safety flags) for Purview sensitivity labels and label policies, to the same standard as Conditional Access and Safe Links. No Purview connector exists: MsGraph has zero tools for sensitivity labels, DLP policies, Insider Risk, Communication Compliance, custom Sensitive Information Types, or eDiscovery. The only current path to the rest is graph_raw_get / graph_raw_request against Graph beta, or cipp_graph_request, which the docs flag as bypassing CIPP's safety prompts and as unstable (beta shapes change without notice). Use case: audit which labels exist and which are published to which users before applying a new one. Both this and the Exchange request close the same kind of gap: right now, anything not already wrapped as a named tool in these two workloads is either unreachable or reachable only through an unguarded raw call. Full accessibility here brings Purview and Exchange to the same standard already set for Conditional Access, Intune, and Safe Links.

Status: Closed1 comment

Log in to comment and vote

Comments1

  • Christopher Scaminaci

    Team•

    Oct 5

    All six shipped in one release. Every CIPP tool here needs CIPP 10.5.0 or later.

    Sensitivity labels and label policies: list, deploy (create or update), edit and remove labels. Label policies are read and deployed with the label. CIPP has no label policy delete.

    DLP: list, deploy with rules, edit and remove policies; read rules. CIPP has no standalone rule delete; disable a rule through the deploy.

    Retention: every read you asked for (the rule and scope detail on the retention policy list needs CIPP 10.10.0 or later), plus retention policy deploy, edit and remove on CIPP. Retention label create, update and delete are on Microsoft Graph (graph_create_retention_label, graph_update_retention_label, graph_delete_retention_label).

    Insider Risk Management: alerts ship as graph_list_insider_risk_alerts. IRM policies have no Microsoft API or PowerShell cmdlet.

    Communication Compliance: policy and rule reads ship. Microsoft does not support creating or managing these policies from PowerShell or any API.

    Custom sensitive information types: list, rule package read, deploy from a regex or a rule pack, remove. These need CIPP 10.6.0 or later.

    The Graph label tools use two new Microsoft permissions. Each Microsoft connection picks them up on its next sign-in; in a tenant where users cannot approve admin permissions, an admin approves once.