Does labelling a Team or SharePoint site also label the files inside it?
No. A container label applied to a Team, Microsoft 365 Group, or SharePoint site controls the container itself — who can be invited, from which devices, its privacy setting — not the files stored inside it. Files and emails carry their own labels, set independently. A site labelled Confidential full of files labelled General is normal and correct, not a misconfiguration.
What a container label controls
- Who can be invited to the Team, group, or site, and from which devices.
- External sharing and guest access posture for that container.
- Conditional Access authentication-context binding, where configured.
What it does not control
- Encryption, markings, or DLP conditions on the files inside — those come from each file's own label.
- Whether Copilot can surface a file in an answer — that depends on the file's own label and the user's usage rights, not the container's label.
Read next
- Microsoft Purview sensitivity labels — a deep dive— How Purview sensitivity labels classify and protect content, how to design a taxonomy that survives contact with users, and the rollout order that works.
- SharePoint external sharing— The layered controls that decide who outside your organisation can access SharePoint and OneDrive content — and a sane baseline configuration.
- Microsoft 365 Group naming and expiration policies— Naming conventions and expiration policies keep group sprawl manageable. Here's how each works.