shortcutaub.ie/datalabel
Auburn University uses Microsoft Purview sensitivity labels to help protect university information and ensure data is handled according to the Auburn University Data Classification Policy. The labels make it easier for faculty, staff, and students to identify the appropriate level of protection for documents and email messages. The policy classifies data into three primary categories: Public, Operational, and Confidential.
When you apply a sensitivity label, Microsoft 365 can automatically apply protections such as encryption, access restrictions, content markings, and sharing controls to help ensure data is handled appropriately.
Use for information intentionally made available to the general public.
Public data may be freely shared without potential harm to Auburn University or its affiliates.
Use for routine university business information intended for internal Auburn use.
Operational data is not openly shared with the public but generally does not require the heightened protections associated with confidential information.
Use for information that requires strict protection due to legal, regulatory, contractual, research, privacy, or security requirements.
Confidential data includes information where unauthorized disclosure could have a serious adverse impact on Auburn University, individuals, or affiliates. Examples include Social Security numbers, payment card data, protected health information, export-controlled information, non-directory student records, and certain protected research data.
Auburn uses two Confidential label variants:
For confidential information that will only be shared with Auburn users.
This label applies the strongest internal protections and is intended for sensitive information that does not need to leave the university.
For confidential information that must be shared outside Auburn University while remaining protected.
This label applies protections that allow authorized external recipients to access the content while maintaining security controls such as encryption and access restrictions.
Sensitivity labels can be applied in Microsoft Word, Excel, PowerPoint, and other Microsoft 365 applications.
| If the document contains... | Use this label |
| Information approved for public release | Public |
| Routine internal business information | Operational |
| Confidential data only Auburn personnel should access | Confidential / Internal-Access |
| Confidential data that must be securely shared outside Auburn | Confidential / External-Access |
When a document contains information from multiple classifications, apply the label that corresponds to the highest sensitivity level contained in the document.
Sensitivity labels should also be applied to email messages based on the information being communicated.
| Scenario | Recommended Label |
| Campus-wide announcement | Public |
| Internal departmental discussion | Operational |
| Email containing student records, personnel data, or other protected information shared only with Auburn users | Confidential / Internal-Access |
| Email containing protected information sent to an approved external partner | Confidential / External-Access |
Choose the label that reflects the most sensitive information in the file or email. If you are unsure, consult your supervisor, IT provider, or the Information Security Office.
Yes. Labels can be changed as business requirements change, provided you have permission to do so.
Labels help:
If you need help determining the appropriate classification or handling requirements for University data, contact the Information Security Office at infosec@auburn.edu or work with your IT provider. Guidance on data classifications and handling requirements is maintained by Auburn's Information Security Office.