When a Microsoft Purview sensitivity label is deleted from Secure & Govern, Egnyte automatically removes it from all files it was applied to. This happens in the background with no additional configuration required. This article explains what happens during removal, what to expect, and how to verify the results.
Label Removal from Files
- Navigate to Settings -> Document Labels.
- Click on the three-dots icon of a label to delete and click on Delete.
- Click on Delete to confirm label deletion.
Key Points to Note for Deleting a Label
- When a label is deleted from Secure & Govern, Egnyte identifies every file it previously labeled (or attempted to label) under the labeling policies and creates a new, unlabeled version of each file.
- If the deleted label applies encryption, removal also removes the encryption. The new version of each Egnyte-labeled file is unencrypted and readable. Files that were access-protected before the deletion will open freely afterward. It is therefore recommended to confirm this is the intended outcome before deleting an encryption label. If files should stay protected, apply a replacement label before deleting the old one.
- Labels applied manually in Microsoft apps remain on files that never matched a labeling policy. Those users will still see a label that no longer appears in the Secure & Govern label list. Removing those labels requires Microsoft tooling.
- Check for digitally signed PDFs. A signed PDF cannot be modified without invalidating its signature, so these files cannot be cleaned and keep the label. Each one is recorded as a failed removal in the audit events; failures are not retried automatically.
- Plan the timing. Removal is limited to 200,000 files per domain per day. A label on a very large number of files takes multiple days to fully clear. For example, one million files take at least five days. Each cleaned file is also a new version, which generates sync traffic and consumes storage, so for large file sets consider deleting the label at the start of a low-activity period (such as a weekend).
- Ask users to avoid restoring old versions during cleanup. If a user promotes an older, labeled version of a file to be the latest version while cleanup is in progress, that file can end up labeled again. There will be no further automatic cleanup for it.
- Removal is gradual and there is no completion notification. Immediately after deleting a label, users may see a mix of labeled and unlabeled files. For a short period, a file's metadata tags may still show the label even after its content has been cleaned; the tags update automatically shortly afterward.
- The file audit events are the authoritative record. It is recommended to use them, rather than the tag display, to check an individual file's status.
What Label Removal Does Not Do
Removing a Microsoft Purview Sensitivity Label does not remove labels that Egnyte never attempted to apply. A label applied in Word, Outlook, or the Purview client on files that never matched a labeling policy stays in place.
Version history is not affected. Earlier versions of a file retain their original label and any associated encryption, so downloading or restoring a previous version will bring that label, and its protections back. Each removal is recorded in the file audit events.
Additionally, it does not retry failures. A file that could not be cleaned (for example, a signed PDF) keeps the label until the user addresses it directly.
Verifying Results and Troubleshooting
The file audit events are the complete record of every success and failure. To confirm a label is fully removed, review the audit events for the period after the deletion.
-
Some files still show the label days later
- Why: The file may have been labeled outside Egnyte with no policy match, it may be a signed PDF, or cleanup may still be in progress.
- What to do: Check audit events. Remove remaining labels using Microsoft tooling if needed.
-
A cleaned file shows the label again
- Why: An older, labeled version was restored or promoted.
- What to do: Re-check version history. Avoid version restores during cleanup.
-
An old version downloaded by the user still has the label
- Why: Version history is not modified by removal.
- What to do: This is expected behavior.
-
Metadata tags still show the label on a cleaned file
- Why: Tags update shortly after the file content.
- What to do: Wait, then verify using audit events.
-
Files under a deleted encryption label are no longer encrypted
- Why: Removal includes removal of protection.
- What to do: Re-apply a label if protection is still required.
-
Unable to find removal activity in Secure & Govern reports
- Why: Removal activity is recorded in the File Audit Report in Collaborate.
- What to do: Use file audit events as the record.