MicrosoftMicrosoft Purview

    Information Protection

    Classify, label, and protect sensitive data with encryption that travels with it.

    Microsoft Purview Information Protection discovers, classifies, and protects sensitive data with sensitivity labels that apply encryption and access controls that travel with the file — wherever it goes, inside or outside the organisation. It makes protection persistent and data-centric. Faltrox designs the classification taxonomy and operates it as managed information protection.

    Overview

    What Information Protection is

    Protecting sensitive data only while it sits in your environment is not enough — once a file is shared or downloaded, perimeter controls no longer apply. Microsoft Purview Information Protection makes protection data-centric: it classifies and labels sensitive data and applies encryption and access controls that travel with the file itself.

    It provides sensitivity labels that classify data by sensitivity, apply visual markings, and enforce encryption and usage rights (who can open, edit, print, forward), automatic and recommended labelling using sensitive information types and trainable classifiers, and protection that persists wherever the file goes — even outside the organisation. It underpins Purview DLP and integrates across Microsoft 365 and beyond. Faltrox designs the classification taxonomy and label policy and operates it as managed information protection.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Sensitive Data

    Discovers and classifies sensitive and regulated data across the estate.

    02

    Persistent Encryption

    Encryption and access controls that travel with the file wherever it goes.

    03

    Usage Rights

    Controls who can open, edit, print, and forward protected files.

    04

    Automatic Labelling

    Automatic and recommended labelling using classifiers and information types.

    05

    Beyond the Perimeter

    Protection persists outside the organisation, not just internally.

    06

    Microsoft 365 & Beyond

    Labels apply across Microsoft 365, files, and third-party integrations.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Discover

      It discovers and classifies sensitive data using sensitive information types and trainable classifiers.

    2. 02

      Label

      Sensitivity labels are applied automatically, by recommendation, or by users to classify data.

    3. 03

      Protect

      Labels apply encryption, access controls, and visual markings that travel with the file.

    4. 04

      Persist

      Protection persists wherever the file goes, inside or outside the organisation.

    5. 05

      Operate

      Faltrox designs the taxonomy and label policy and operates it as managed information protection.

    Capabilities

    Key capabilities

    Sensitivity Labels

    Classify data by sensitivity with visual markings, encryption, and access controls.

    Persistent Protection

    Encryption and controls travel with the file wherever it goes.

    Usage Rights

    Controls who can open, edit, print, and forward protected files.

    Automatic Labelling

    Automatic and recommended labelling using information types and trainable classifiers.

    Data Discovery

    Discovers and classifies sensitive data across the estate.

    DLP Foundation

    Underpins Purview DLP with consistent classification and labels.

    Broad Coverage

    Labels apply across Microsoft 365, files, and third-party integrations.

    Purview Integration

    Part of the unified Microsoft Purview data security and compliance platform.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Information Protection for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What is a sensitivity label?

    A classification applied to data that carries protection with it — visual markings, encryption, and access controls (who can open, edit, print, forward). Because the protection is embedded in the file, it persists wherever the file goes, even outside your organisation, which perimeter controls cannot do.

    02How does the encryption "travel with the file"?

    The label applies encryption and usage rights to the file itself, so the protection stays with it when it is shared, downloaded, or emailed externally. Only authorised users can open it, and the controls (like blocking printing or forwarding) apply wherever it lands.

    03Do users have to label everything manually?

    No — automatic and recommended labelling uses sensitive information types and trainable classifiers to label data based on its content, so much of the classification happens automatically. Users can also apply labels, coached by recommendations. Faltrox designs that balance.

    04How does it relate to DLP?

    Information Protection provides the classification and labels; DLP uses them (alongside content inspection) to enforce policy. Together they give consistent, data-centric protection — labels travel with the data, and DLP controls where labelled data can go.

    05How does Faltrox operate it?

    We design the classification taxonomy and label policy, configure automatic and recommended labelling, and operate it — delivering managed information protection so your sensitive data is classified and protected consistently, wherever it goes.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us