Microsoft Purview Information Protection admins can now exclude modern Microsoft 365 groups and include dynamic, non-mail-enabled security groups in sensitivity label policies. This expands policy targeting flexibility without impacting users unless policies are updated. Rollout begins April 2026 with general availability in late May 2026.
Introduction
Purview Information Protection admins can now exclude modern Microsoft 365 groups and scope sensitivity label policies to dynamic and non-mail enabled security groups. These capabilities give admins more flexibility, expanding policy targeting beyond individual users and mail-enabled groups.
This message is associated with Microsoft 365 Roadmap ID 558685.
When this will happen:
How this affects your organization:
Who is affected:
What will happen:
What you can do to prepare:
Learn more: Create and publish sensitivity labels | Microsoft Learn (will be updated before rollout)
Compliance considerations:
| Compliance question | Explanation |
| Does the change modify Information Protection labels or policy configuration capabilities? | This update expands how sensitivity label publishing policies can be scoped by allowing admins to exclude modern Microsoft 365 groups and include non-mail-enabled security groups. |
| Does the change include an admin control and can it be controlled through Entra ID group membership? | Admins can scope sensitivity label publishing policies using non-mail-enabled security groups, including dynamic security groups in Microsoft Entra ID. |