Forum Discussion

Alisea_MI's avatar
Alisea_MI
Icon for Resolver II rankResolver II
2 years ago
Solved

Sensitivity Lables - Allow a Team (AD-group) to Remove

Hi, Community!   A developer in our team has applied sensitivity labels on the data sources and she seems to be the only person to be able to remove them. Me, as a global Power BI Admin is not allo...
  • Anonymous's avatar
    Anonymous
    2 years ago

    Hi Alisea_MI 

     

    Firstly, it's important to clarify that sensitivity label management can indeed be person-bound to an extent, but there are administrative capabilities that allow for broader management across the organization. To allow your entire developer team the ability to remove sensitivity labels, you would need to ensure that the members of the team are assigned at least one of the following usage rights to the sensitivity label in the Microsoft Purview compliance portal: OWNER, EXPORT, or EDIT and EDITRIGHTSDATA. These rights will enable authorized users to change or remove sensitivity labels applied.

     

    Here's a concise action plan to achieve this:

    1. Identify the Sensitivity Labels: Determine which sensitivity labels are applied that your team needs access to change or remove.
    2. Assign Usage Rights: In the Microsoft Purview compliance portal, navigate to Classification > Sensitivity labels. Here, you can manage the sensitivity labels and assign the necessary usage rights (OWNER, EXPORT, EDIT, and EDITRIGHTSDATA) to your developer team. This might require creating or modifying an existing label policy to include your developer team as authorized users.

     

    The key action is to adjust the usage rights for the sensitivity labels as mentioned above. This is something your Microsoft 365/Office security administrator can assist with. This cannot be changed in Power BI Settings. 

    ReferenceConfigure usage rights for Azure Information Protection (AIP)

     

    In addition, as a global Power BI Admin, you can use Power BI admin REST APIs to set and remove sensitivity labels on large numbers of Power BI artifacts programatically. See the following documentations. This also requires that you have sufficient usage rights to delete labels. 

    Set or remove sensitivity labels programmatically with admin APIs

    Admin - InformationProtection RemoveLabelsAsAdmin

     

    Other documentations that may be helpful:

    Apply encryption using sensitivity labels

    Configure super users for Azure Rights Management - AIP

    Remove labels using the Azure Information Protection unified labeling client

     

    Best Regards,
    Jing
    If this post helps, please Accept it as Solution to help other members find it. Appreciate your Kudos!