We’re using labeling to improve the security of OneNote internally here at Microsoft.
Here at Microsoft and at workplaces around the world, OneNote is used for everything from record keeping and note-taking to collaborating across teams. And with Microsoft 365 Copilot making work easier and more efficient across all Microsoft 365 applications, OneNote should be no exception.
However, before we in Microsoft Digital, the company’s IT organization, could fully integrate Copilot into OneNote, we first needed to make it more secure. We recently accomplished this internally at Microsoft by deploying labeling that makes our OneNote notebooks and files more secure. This allowed us to start using Copilot in OneNote without compromising our sensitive or classified data.
“We realized that notebook oversharing was happening significantly and that we were keeping a lot of sensitive data in our notebooks,” says David Johnson, a principal product manager with Microsoft Digital. “OneNote was the only Microsoft 365 program that didn’t support labeling, a gap that we needed to address.”
“OneNote is designed to be the ultimate collaboration tool. So, you can have OneNote as your own personal notebook, or you can share it out with other people and collaborate. People use OneNote for a lot of different things, but at Microsoft especially, it is used for things like troubleshooting guides, post-incident reviews and other very sensitive things that require a high degree of seamless collaboration.”
Faye Harold, principal product manager, Information Protection team, Microsoft Security
Our diverse and heavy use of OneNote throughout Microsoft made closing that gap a critical need.
“OneNote is designed to be the ultimate collaboration tool,” says Faye Harold a principal product manager within the Information Protection Team in Microsoft Security. “So, you can have OneNote as your own personal notebook, or you can share it out with other people and collaborate. People use OneNote for a lot of different things, but at Microsoft especially, it is used for things like troubleshooting guides, post-incident reviews and other very sensitive things that require a high degree of seamless collaboration.”
And the idea that “it’s fine” because no one will ever find your notes in OneNote?
That’s no longer a thing, if it ever was.
In the age of AI, security through obscurity is effectively gone.
“Now the construct is, ‘AI can show you everything you have access to, no matter where it is, including in your colleague’s OneNote notebooks,’” Johnson says. “Without labeling, Copilot can and will show you information that you’re not supposed to see.”
“Bringing sensitivity labels to OneNote marks a major step forward in helping tenant admins safeguard organizational data. It enables consistent enforcement of security policies across the Microsoft 365 suite, giving admins greater confidence that sensitive information in OneNote is protected and governed just like in other Office apps.”
Daniel Beade, senior product manager, OneNote product group
Permissions versus labeling
The current security measures in OneNote are permission-based, determining who can access content at a specific point in time. Labeling adds encryption and policy enforcement to ensure content is protected regardless of where it is stored or shared. And when it comes to AI, labeling establishes confidentiality and security requirements that Copilot must respect. Labeling also helps users understand the sensitivity of content used by Copilot, ensuring they handle the generated responses with appropriate care.
“Bringing sensitivity labels to OneNote marks a major step forward in helping tenant admins safeguard organizational data,” says Daniel Beade, a senior product manager with the OneNote product group. “It enables consistent enforcement of security policies across the Microsoft 365 suite, giving admins greater confidence that sensitive information in OneNote is protected and governed just like in other Office apps.”
Johnson used the analogy of a poisoned apple pie to explain further.
“Imagine if Copilot was baking you a nice apple pie and you weren’t told that the apples it used to make the pie were poison,” he says. “You probably should know that before you take a bite of that pie. Same basic idea here. You’ve got highly confidential content in use that Copilot is using to generate a response. You should be aware of it.”
A triangle deployment model
Security labeling for OneNote was deployed internally to our 300,000 Microsoft employees and vendors in April 2025, and we have updated the Microsoft 365 product roadmap to reflect our plan to make this capability generally available by January 2026 with more information to be shared in the coming months.
“The user awareness aspect of labeling is absolutely critical. When you think about labeling, it’s about user awareness of how sensitive a piece of content should be and the applicability of policies to make sure that the content doesn’t go beyond whatever limits are imposed.”
David Johnson, principal product manager, Microsoft Digital
Our internal deployment happened in two stages. The first stage enabled labeling in the user interface. The second stage rolled out a default policy that labeled all content with a protected label, with options for users to adjust based on the sensitivity of the content.
“The user awareness aspect of labeling is absolutely critical,” Johnson says. “When you think about labeling, it’s about user awareness of how sensitive a piece of content should be and the applicability of policies to make sure that the content doesn’t go beyond whatever limits are imposed.”
“It’s super important to have a labeling capability in OneNote, because down the road labeling is going to help enable more capabilities of Copilot that will allow users to increase their productivity.”
Humberto Arias, senior product manager, Microsoft Digital
The internal deployment strategy involved a triangle model where one organization focused on security requirements, another on tenant management, and his team focused on employee experience.
The model ensured that security measures did not hinder productivity.
“Because Copilot extracts and surfaces content from various sources, it is essential for it to know the sensitivity of the content it uses to generate responses,” says Humberto Arias, a senior product manager in Microsoft Digital. “So that’s why it’s super important to have a labeling capability in OneNote, because down the road labeling is going to help enable more capabilities of Copilot that will allow users to increase their productivity.”
As for those future capabilities, Beade from the product group listed three that will further enhance security within OneNote.
The first, user-defined permissions labels, or UDP, will allow tenants to define permissions at the user level. This means one of our employees could set up a UDP label and then use it to grant edit permissions to one person and read-only access to another. This is similar to what currently exists in Word, PowerPoint and Excel.
The second feature Beade mentioned is auto-labeling. This will allow OneNote to automatically label information based on criteria defined by the tenant admin. Flagging certain content automatically will help prevent Copilot from surfacing sensitive information.
Another security feature coming soon to OneNote is dynamic watermarking.
“Not only will the labeling protection be added into the file, but also watermarking will be added that will ensure everyone knows that the information is confidential,” Beade says. “All three will compliment security labeling and add more protection to OneNote.”
Adding new features to OneNote will now be much easier.
“Labeling is going to make it very seamless for us to deploy new Copilot features in the future,” Arias says. “This was an important step for us to bring OneNote up to par with the rest of the Microsoft 365 apps.”
Key takeaways
When sensitivity labels become publicly available in OneNote in January 2026, here are some of things you will be able to do with them:
Use OneNote features with confidence. OneNote is a powerful tool for collaboration, and security labeling makes sure Copilot does not surface sensitive information from your notebooks.
Foster collaboration without the risk of exposing sensitive data. Permission-based security determines who can access content at a specific point in time. Security labeling adds encryption and policy enforcement, protecting your content regardless of where it is stored or shared.
Be AI-aware when it comes to security. Security labeling ensures Copilot respects confidentiality and security requirements while also helping users understand the sensitivity of content used by Copilot so they handle the generated responses with appropriate care.
Set location label defaults. We set an encrypted protection label, limiting data to tenant members only for all our employees’ OneDrive. That made it so simply rolling out OneNote with labeling resulted in a high percentage of active sections having that default label applied.
Microsoft Digital stories The rate of change in IT is accelerating at a blistering pace. AI-powered capabilities like Microsoft 365 Copilot have enabled a new era of employee productivity. Today, agentic capabilities are supercharging IT…
Microsoft Digital readiness guide AI transformation is one of the most profound business changes in decades. Making the most of AI tools will require careful planning, thoughtful communication, comprehensive employee enablement, and diligent tracking. Fortunately,…
Microsoft Digital technical stories Agentic AI is the frontier of the AI landscape. These tools show enormous promise, but harnessing their power isn’t always as straightforward as prompting a model or accessing data from Microsoft…
Microsoft Digital stories Microsoft SharePoint is one of the most ubiquitous and highly trusted content storage and sharing solutions in modern business. Around the world, organizations add over 2 billion pieces of content to SharePoint…
Microsoft Digital stories This story reflects updated guidance from Microsoft Digital—it was first published in 2024. Imagine having a personal assistant that helps you navigate your daily tasks effortlessly. Microsoft 365 Copilot offers just that, allowing you to work smarter, not harder. And the best part? You don’t need to be a prompt engineer to… Read more
Microsoft OneNote is a tool used every day by millions of people, from school teachers to boardroom executives, to keep their professional lives orderly. In October 2025 some of those lives could become a little more chaotic when Microsoft ends support for the Windows 10 version of OneNote. To prevent that kind of disruption, organizations… Read more
This story was first published in 2018. We periodically update our stories, but we can’t verify that they represent the full picture of our current situation at Microsoft. We leave them on the site so you can see what our thinking and experience was at the time. At Microsoft, we’re increasing the collaborative capability of… Read more
This story reflects updated guidance from Microsoft Digital—it was first published in 2018. At Microsoft, we’re using Microsoft 365 to empower our employees to achieve more by driving better teamwork and collaboration in our teams. We’re using core Microsoft 365 services such as SharePoint Online, Microsoft Teams, Exchange Online, and Viva Engage to support modern… Read more