Commands › Exchange Online

New-Label

Exchange Online ExchangeOnlineManagement New-*

For more information, see Security & Compliance PowerShell. Use the New-Label cmdlet to create sensitivity labels in your organization.

Quick start script

# New-Label — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-Label
$before | Format-List

# 3. Make the change (dry run first)
New-Label -Name <String> -DisplayName <String> -Tooltip <String> -WhatIf
New-Label -Name <String> -DisplayName <String> -Tooltip <String>

# 4. Verify and diff
$after = Get-Label
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

New-Label [-Name] <String> -DisplayName <String> -Tooltip <String>
 [-AdvancedSettings <PswsHashtable>]
 [-ApplyContentMarkingFooterAlignment <Microsoft.Office.CompliancePolicy.Tasks.FlattenLabelActionUtils+ContentAlignment>]
 [-ApplyContentMarkingFooterEnabled <System.Boolean>]
 [-ApplyContentMarkingFooterFontColor <String>]
 [-ApplyContentMarkingFooterFontName <String>]
 [-ApplyContentMarkingFooterFontSize <System.Int32>]
 [-ApplyContentMarkingFooterMargin <System.Int32>]
 [-ApplyContentMarkingFooterText <String>]
 [-ApplyContentMarkingHeaderAlignment <Microsoft.Office.CompliancePolicy.Tasks.FlattenLabelActionUtils+ContentAlignment>]
 [-ApplyContentMarkingHeaderEnabled <System.Boolean>]
 [-ApplyContentMarkingHeaderFontColor <String>]
 [-ApplyContentMarkingHeaderFontName <String>]
 [-ApplyContentMarkingHeaderFontSize <System.Int32>]
 [-ApplyContentMarkingHeaderMargin <System.Int32>]
 [-ApplyContentMarkingHeaderText <String>]
 [-ApplyDynamicWatermarkingEnabled <System.Boolean>]
 [-ApplyWaterMarkingEnabled <System.Boolean>]
 [-ApplyWaterMarkingFontColor <String>]
 [-ApplyWaterMarkingFontName <String>]
 [-ApplyWaterMarkingFontSize <System.Int32>]
 [-ApplyWaterMarkingLayout <Microsoft.Office.CompliancePolicy.Tasks.FlattenLabelActionUtils+WaterMarkingLayout>]
 [-ApplyWaterMarkingText <String>]
 [-ColumnAssetCondition <String>]
 [-Comment <String>]
 [-Conditions <MultiValuedProperty>]
 [-Confirm]
 [-ContentType <MipLabelContentType>]
 [-DefaultContentLabel <String>]
 [-DynamicWatermarkDisplay <String>]
 [-EncryptionAipTemplateScopes <String>]
 [-EncryptionContentExpiredOnDateInDaysOrNever <String>]
 [-EncryptionDoNotForward <System.Boolean>]
 [-EncryptionDoubleKeyEncryptionUrl <String>]
 [-EncryptionEnabled <System.Boolean>]
 [-EncryptionEncryptOnly <System.Boolean>]
 [-EncryptionLinkedTemplateId <String>]
 [-EncryptionOfflineAccessDays <System.Int32>]
 [-EncryptionPromptUser <System.Boolean>]
 [-EncryptionProtectionType <Microsoft.Office.CompliancePolicy.Tasks.FlattenLabelActionUtils+SupportedProtectionType>]
 [-EncryptionRightsDefinitions <EncryptionRightsDefinitionsParameter>]
 [-EncryptionRightsUrl <String>]
 [-EncryptionTemplateId <String>]
 [-Identity <MasterIdParameter>]
 [-IsLabelGroup]
 [-LabelActions <MultiValuedProperty>]
 [-LocaleSettings <MultiValuedProperty>]
 [-MigrationId <String>]
 [-ParentId <ComplianceRuleIdParameter>]
 [-SchematizedDataCondition <String>]
 [-Setting <PswsHashtable>]
 [-Settings <PswsHashtable>]
 [-SiteAndGroupProtectionAllowAccessToGuestUsers <System.Boolean>]
 [-SiteAndGroupProtectionAllowEmailFromGuestUsers <System.Boolean>]
 [-SiteAndGroupProtectionAllowFullAccess <System.Boolean>]
 [-SiteAndGroupProtectionAllowLimitedAccess <System.Boolean>]
 [-SiteAndGroupProtectionBlockAccess <System.Boolean>]
 [-SiteAndGroupProtectionEnabled <System.Boolean>]
 [-SiteAndGroupProtectionLevel <SiteAndGroupProtectionLevelParameter>]
 [-SiteAndGroupProtectionPrivacy <Microsoft.Office.CompliancePolicy.Tasks.FlattenLabelActionUtils+GroupProtectionPrivacy>]
 [-SiteExternalSharingControlType <Microsoft.Office.CompliancePolicy.Tasks.SiteExternalSharingControlType>]
 [-TeamsAllowedPresenters <Microsoft.Office.CompliancePolicy.PolicyConfiguration.AllowedPresenters>]
 [-TeamsAllowMeetingChat <Microsoft.Office.CompliancePolicy.PolicyConfiguration.MeetingChatMode>]
 [-TeamsAllowPrivateTeamsToBeDiscoverableUsingSearch <System.Boolean>]
 [-TeamsBypassLobbyForDialInUsers <System.Boolean>]
 [-TeamsChannelProtectionEnabled <System.Boolean>]
 [-TeamsChannelSharedWithExternalTenants <System.Boolean>]
 [-TeamsChannelSharedWithPrivateTeamsOnly <System.Boolean>]
 [-TeamsChannelSharedWithSameLabelOnly <System.Boolean>]
 [-TeamsCopyRestrictionEnforced <System.Boolean>]
 [-TeamsDetectSensitiveContentDuringScreenSharingEnabled System.Boolean>]
 [-TeamsDisableLobby <System.Boolean>]
 [-TeamsEndToEndEncryptionEnabled <System.Boolean>]
 [-TeamsLobbyBypassScope <Microsoft.Office.CompliancePolicy.PolicyConfiguration.LobbyBypassScope>]
 [-TeamsLobbyRestrictionEnforced <System.Boolean>]
 [-TeamsPresentersRestrictionEnforced <System.Boolean>]
 [-TeamsProtectionEnabled <System.Boolean>]
 [-TeamsRecordAutomatically <System.Boolean>]
 [-TeamsVideoWatermark <Microsoft.Office.CompliancePolicy.PolicyConfiguration.WaterMarkProtectionValues>]
 [-TeamsWhoCanRecord <Microsoft.Office.CompliancePolicy.PolicyConfiguration.WhoCanRecordOptions>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (83)

ParameterTypeRequiredWhat it controls
-Name String yes The Name parameter specifies the unique name for the sensitivity label. The maximum length is 64 characters. If the value contains spaces, enclose the value in quotation marks (").
-DisplayName String yes The DisplayName parameter specifies the display name for the sensitivity label. The display name appears in any client that supports sensitivity labels. This includes Word, Excel, PowerPoint, Outlook, SharePoint,...
-Tooltip String yes The ToolTip parameter specifies the default tooltip and sensitivity label description that's seen by users. It the value contains spaces, enclose the value in quotation marks (").
-AdvancedSettings PswsHashtable The AdvancedSettings parameter enables specific features and capabilities for a sensitivity label.
-ApplyContentMarkingFooterAlignment FlattenLabelActionUtils+ContentAlignment The ApplyContentMarkingFooterAlignment parameter specifies the footer alignment. Valid values are:
-ApplyContentMarkingFooterEnabled Boolean The ApplyContentMarkingFooterEnabled parameter enables or disables the Apply Content Marking Footer action for the label. Valid values are:
-ApplyContentMarkingFooterFontColor String The ApplyContentMarkingFooterFontColor parameter specifies the color of the footer text. This parameter accepts a hexadecimal color code value in the format `#xxxxxx`. The default value is `#000000`.
-ApplyContentMarkingFooterFontName String The ApplyContentMarkingFooterFontName parameter specifies the font of the footer text. If the value contains spaces, enclose the value in quotation marks ("). For example `"Courier New"`.
-ApplyContentMarkingFooterFontSize Int32 The ApplyContentMarkingFooterFontSize parameter specifies the font size (in points) of the footer text.
-ApplyContentMarkingFooterMargin Int32 The ApplyContentMarkingFooterMargin parameter specifies the size (in points) of the footer margin.
-ApplyContentMarkingFooterText String The ApplyContentMarkingFooterText parameter specifies the footer text. If the value contains spaces, enclose the value in quotation marks (").
-ApplyContentMarkingHeaderAlignment FlattenLabelActionUtils+ContentAlignment The ApplyContentMarkingHeaderAlignment parameter specifies the header alignment. Valid values are:
-ApplyContentMarkingHeaderEnabled Boolean The ApplyContentMarkingHeaderEnabled parameter enables or disables the Apply Content Marking Header action for the label. Valid values are:
-ApplyContentMarkingHeaderFontColor String The ApplyContentMarkingHeaderFontColor parameter specifies the color of the header text. This parameter accepts a hexadecimal color code value in the format `#xxxxxx`. The default value is `#000000`.
-ApplyContentMarkingHeaderFontName String The ApplyContentMarkingHeaderFontName parameter specifies the font of the header text. If the value contains spaces, enclose the value in quotation marks ("). For example `"Courier New"`.
-ApplyContentMarkingHeaderFontSize Int32 The ApplyContentMarkingHeaderFontSize parameter specifies the font size (in points) of the header text.
-ApplyContentMarkingHeaderMargin Int32 The ApplyContentMarkingHeaderMargin parameter specifies the size (in points) of the header margin.
-ApplyContentMarkingHeaderText String The ApplyContentMarkingHeaderText parameter specifies the header text. If the value contains spaces, enclose the value in quotation marks (").
-ApplyDynamicWatermarkingEnabled Boolean **Note**: This parameter is Generally Available only for labels with admin-defined permissions. Support for label with user-defined permissions is currently in Public Preview, isn't available in all organizations,...
-ApplyWaterMarkingEnabled Boolean The ApplyWaterMarkingEnabled parameter enables or disables the Apply Watermarking Header action for the label. Valid values are:
-ApplyWaterMarkingFontColor String The ApplyWaterMarkingFontColor parameter specifies the color of the watermark text. This parameter accepts a hexadecimal color code value in the format `#xxxxxx`. The default value is `#000000`.
-ApplyWaterMarkingFontName String The ApplyWaterMarkingFontName parameter specifies the font of the watermark text. If the value contains spaces, enclose the value in quotation marks ("). For example `"Courier New"`.
-ApplyWaterMarkingFontSize Int32 The ApplyWaterMarkingFontSize parameter specifies the font size (in points) of the watermark text.
-ApplyWaterMarkingLayout FlattenLabelActionUtils+WaterMarkingLayout The ApplyWaterMarkingLayout parameter specifies the watermark alignment. Valid values are:
-ApplyWaterMarkingText String The ApplyWaterMarkingText parameter specifies the watermark text. If the value contains spaces, enclose the value in quotation marks (").
-ColumnAssetCondition String This parameter is reserved for internal Microsoft use.
-Comment String The Comment parameter specifies an optional comment. If you specify a value that contains spaces, enclose the value in quotation marks ("), for example: "This is an admin note".
-Conditions MulitValuedProperty This parameter is reserved for internal Microsoft use.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-ContentType MipLabelContentType The ContentType parameter specifies where the sensitivity label can be applied. Valid values are:
-DefaultContentLabel String The DefaultContentLabel specifies a label that can be automatically applied to meetings created in a labeled Teams channel.
-DynamicWatermarkDisplay String **Note**: This parameter is Generally Available only for labels with admin-defined permissions. Support for label with user-defined permissions is currently in Public Preview, isn't available in all organizations,...
-EncryptionAipTemplateScopes String The EncryptionAipTemplateScopes parameter specifies that the label is still published and usable in the AIP classic client. An example value is...
-EncryptionContentExpiredOnDateInDaysOrNever String The EncryptionContentExpiredOnDateInDaysOrNever parameter specifies when the encrypted content expires. Valid values are:
-EncryptionDoNotForward Boolean The EncryptionDoNotForward parameter specifies whether the Do Not Forward template is applied. Valid values are:
-EncryptionDoubleKeyEncryptionUrl String The feature for this parameter is currently in Public Preview, and is not available to everyone.
-EncryptionEnabled Boolean The EncryptionEnabled parameter specifies whether encryption in enabled. Valid values are:
-EncryptionEncryptOnly Boolean The EncryptionEncryptOnly parameter specifies whether the encrypt-only template is applied. Valid values are:
-EncryptionLinkedTemplateId String This parameter is reserved for internal Microsoft use.
-EncryptionOfflineAccessDays Int32 The EncryptionOfflineAccessDays parameter specifies the number of days that offline access is allowed.
-EncryptionPromptUser Boolean The EncryptionPromptUser parameter specifies whether to set the label with user defined permission in Word, Excel, and PowerPoint. Valid values are:
-EncryptionProtectionType FlattenLabelActionUtils+SupportedProtectionType The EncryptionProtectionType parameter specifies the protection type for encryption. Valid values are:
-EncryptionRightsDefinitions EncryptionRightsDefinitionsParameter The EncryptionRightsDefinitions parameter specifies the rights users have when accessing protected. This parameter uses the syntax `Identity1:Rights1,Rights2;Identity2:Rights3,Rights4`. For example,...
-EncryptionRightsUrl String The EncryptionRightsUrl parameter specifies the URL for hold your own key (HYOK) protection.
-EncryptionTemplateId String The EncryptionTemplateId parameter lets you convert an existing protection template from Azure Information Protection to a new sensitivity label. Specify the template by its ID that you can identify by running the...
-Identity MasterIdParameter The Identity parameter is used to migrate an existing Azure Information Protection label by specifying a GUID value.
-IsLabelGroup SwitchParameter {{ Fill IsLabelGroup Description }}
-LabelActions MultiValuedProperty This parameter is reserved for internal Microsoft use.
-LocaleSettings MultiValuedProperty The LocaleSettings parameter specifies one or more localized label names or label Tooltips in different languages. Regions include all region codes supported in Office Client applications. Valid values use the...
-MigrationId String This parameter is reserved for internal Microsoft use.
-ParentId ComplianceRuleIdParameter The ParentId parameter specifies the parent label that you want this label to be under (a sublabel). You can use any value that uniquely identifies the parent sensitivity label. For example:
-SchematizedDataCondition String This parameter is reserved for internal Microsoft use.
-Setting PswsHashtable This parameter is reserved for internal Microsoft use.
-Settings PswsHashtable This parameter is reserved for internal Microsoft use.
-SiteAndGroupProtectionAllowAccessToGuestUsers Boolean The SiteAndGroupProtectionAllowAccessToGuestUsers parameter enables or disables access to guest users. Valid values are:
-SiteAndGroupProtectionAllowEmailFromGuestUsers Boolean The SiteAndGroupProtectionAllowEmailFromGuestUsers parameter enables or disables email from guest users. Valid values are:
-SiteAndGroupProtectionAllowFullAccess Boolean The SiteAndGroupProtectionAllowFullAccess parameter enables or disables full access. Valid values are:
-SiteAndGroupProtectionAllowLimitedAccess Boolean The SiteAndGroupProtectionAllowLimitedAccess parameter enables or disables limited access. Valid values are:
-SiteAndGroupProtectionBlockAccess Boolean The SiteAndGroupProtectionBlockAccess parameter blocks access. Valid values are:
-SiteAndGroupProtectionEnabled Boolean The SiteAndGroupProtectionEnabled parameter enables or disables the Site and Group Protection action for the label. Valid values are:
-SiteAndGroupProtectionLevel SiteAndGroupProtectionLevelParameter This parameter is reserved for internal Microsoft use.
-SiteAndGroupProtectionPrivacy FlattenLabelActionUtils+GroupProtectionPrivacy The SiteAndGroupProtectionPrivacy parameter specifies the privacy level for the labe. Valid values are:
-SiteExternalSharingControlType SiteExternalSharingControlType The SiteExternalSharingControlType parameter specifies the external user sharing setting for the label. Valid values are:
-TeamsAllowedPresenters AllowedPresenters The TeamsAllowedPresenters parameter controls who can present in Teams meetings. Valid values are:
-TeamsAllowMeetingChat MeetingChatMode The TeamsAllowMeetingChat parameter controls whether chat is available in Teams meetings. Valid values are:
-TeamsAllowPrivateTeamsToBeDiscoverableUsingSearch Boolean {{ Fill TeamsAllowPrivateTeamsToBeDiscoverableUsingSearch Description }}
-TeamsBypassLobbyForDialInUsers Boolean The TeamsBypassLobbyForDialInUsers parameter controls the lobby experience for dial-in users who join Teams meetings. Valid values are:
-TeamsChannelProtectionEnabled Boolean {{ Fill TeamsChannelProtectionEnabled Description }}
-TeamsChannelSharedWithExternalTenants Boolean {{ Fill TeamsChannelSharedWithExternalTenants Description }}
-TeamsChannelSharedWithPrivateTeamsOnly Boolean {{ Fill TeamsChannelSharedWithPrivateTeamsOnly Description }}
-TeamsChannelSharedWithSameLabelOnly Boolean {{ Fill TeamsChannelSharedWithSameLabelOnly Description }}
-TeamsCopyRestrictionEnforced Boolean The TeamsCopyRestrictionEnforced parameter controls whether chat messages in Teams meetings can be copied to the clipboard. Valid values are:
-TeamsDetectSensitiveContentDuringScreenSharingEnabled Boolean {{ Fill TeamsDetectSensitiveContentDuringScreenSharingEnabled Description }}
-TeamsDisableLobby Boolean {{ Fill TeamsDisableLobby Description }}
-TeamsEndToEndEncryptionEnabled Boolean The TeamsEndToEndEncryptionEnabled parameter controls video stream encryption in Teams meetings. Valid values are:
-TeamsLobbyBypassScope LobbyBypassScope The TeamsLobbyBypassScope parameter controls who bypasses the lobby when joining Teams meetings. Valid values are:
-TeamsLobbyRestrictionEnforced Boolean The TeamsLobbyRestrictionEnforced parameter controls whether participants bypass the lobby when joining Teams meetings. Valid values are:
-TeamsPresentersRestrictionEnforced Boolean The TeamsPresentersRestrictionEnforced parameter controls whether presenter restrictions are enabled in Teams meetings. Valid values are:
-TeamsProtectionEnabled Boolean The TeamsProtectionEnabled parameter controls whether Teams protection is enabled in Teams meetings. Valid values are:
-TeamsRecordAutomatically Boolean The TeamsRecordAutomatically parameter controls whether Teams meetings are automatically recorded after they start. Valid values are:
-TeamsVideoWatermark WaterMarkProtectionValues The TeamsVideoWatermark parameter controls whether a watermark is shown in Teams meetings. Valid values are:
-TeamsWhoCanRecord WhoCanRecordOptions The TeamsWhoCanRecord parameter controls who can record Teams meetings. Valid values are:
-WhatIf SwitchParameter The WhatIf switch doesn't work in Security & Compliance PowerShell.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.