Fix Teams Sensitivity Label Does Not Appear for a Guest Conversation
🔍 WiseChecker

Fix Teams Sensitivity Label Does Not Appear for a Guest Conversation

When you start a new conversation with a guest in Microsoft Teams, the sensitivity label picker may not appear. This prevents you from applying a required data protection label. The problem usually comes from a guest access policy or a labeling configuration that blocks guest sessions. This article explains why the label is missing and gives you the exact steps to fix it in the Teams admin center and the Microsoft Purview compliance portal.

Key Takeaways: Restore the Sensitivity Label for Guest Chats

  • Teams admin center > Users > Guest access: Turn on the guest access switch to allow external users in your tenant.
  • Microsoft Purview > Information protection > Sensitivity labels: Confirm the label is published to the correct users and groups, including guests.
  • Teams admin center > Teams apps > Permission policies: Ensure the Global policy permits the Sensitivity label app for external users.

ADVERTISEMENT

Why the Sensitivity Label Does Not Appear for Guest Conversations

Teams relies on Microsoft Purview sensitivity labels to enforce data protection in chats and channels. When you start a conversation, Teams checks two conditions before showing the label picker. First, the guest user must be enabled for guest access in your tenant. Second, the sensitivity label must be published to a group that includes the guest user or to the “All users” scope.

If either condition fails, the label picker stays hidden. The most common cause is that the label is published only to internal groups. Administrators often forget that guest user accounts are separate from internal user accounts. Even if a guest is a member of a team, the label publication does not automatically apply to the guest’s identity.

Another frequent cause is a Teams app permission policy that blocks the sensitivity label app for external users. The label picker is implemented as an app inside Teams. If the policy denies this app for guests, the picker never appears.

Steps to Diagnose and Fix the Missing Sensitivity Label

Follow these steps in order. Each step addresses a different layer of the configuration. Run all of them, not just the first one that seems related.

  1. Enable guest access in the Teams admin center
    Go to Teams admin center > Users > Guest access. Turn on the “Allow guest access in Microsoft Teams” toggle. Save the change. Wait up to 24 hours for the setting to propagate, though it usually takes effect within a few minutes.
  2. Check the sensitivity label publication scope
    Sign in to the Microsoft Purview compliance portal with an account that has the Information Protection Administrator role. Go to Information protection > Sensitivity labels. Select the label you want to appear. In the “Published to” section, confirm that it includes “All users” or a specific group that contains the guest user. If the label is published only to internal groups, add the guest user to one of those groups or change the scope to “All users”.
  3. Verify the label supports Teams conversations
    In the same sensitivity label settings, open the “Teams meetings and private channels” or “Teams conversations” option. The exact wording depends on your tenant. Ensure the option for applying the label to chats and channels is enabled. If it is disabled, the label will not appear in the conversation picker.
  4. Check the Teams app permission policy for guests
    Go to Teams admin center > Teams apps > Permission policies. Select the Global policy. In the “Microsoft apps” section, find the app named “Sensitivity label” or “Microsoft Purview”. Set its status to “Allowed”. Save the policy. This policy controls whether guest users can see the label picker.
  5. Test with a new conversation
    Ask the guest to sign out and sign back in to Teams. Start a new chat with the guest. The sensitivity label picker should appear in the compose box, usually as a shield icon or a text field below the message box. If it still does not appear, move to the next section.

ADVERTISEMENT

If Teams Still Hides the Sensitivity Label for Guests

Guest User Does Not Have a Microsoft 365 License

Sensitivity labels require a Microsoft 365 E3 or E5 license for the user. Guest accounts may not have a license assigned. Check the guest user in the Microsoft 365 admin center. Assign a license that includes Microsoft Purview Information Protection. Without a license, the label picker will never show.

The Sensitivity Label Is Not Applied to External Users in the Label Policy

Even if the label is published to “All users”, the label policy might have a separate setting that excludes external users. In the Purview portal, open the label policy. Look for the “Scoped to” section. Ensure it does not exclude guests. If it does, edit the policy to include them.

Teams Cache Is Outdated

Sometimes the Teams client caches an old policy. Clear the Teams cache by closing Teams and deleting the files in %appdata%\Microsoft\Teams. Then restart Teams. This forces the client to fetch the latest policies.

New Teams Desktop vs Teams on the Web: Label Behavior for Guests

Item New Teams Desktop Teams on the Web
Label picker visibility Appears in the compose box if all policies allow it Same behavior as desktop
Cache refresh Requires manual cache clear after policy changes Requires a browser refresh
Guest access support Fully supported Fully supported

Now you can enable the sensitivity label picker for guest conversations by checking the guest access toggle, the label publication scope, and the Teams app permission policy. Start with the Teams admin center and Purview portal, then test with a new chat. For persistent issues, verify the guest has a valid license and clear the Teams cache. As a final step, review the audit logs in Purview to confirm the exact policy that denies the label.

ADVERTISEMENT