Microsoft is making it easier for organizations to protect sensitive information when employees send emails from their phones. Starting in late September 2026, Outlook for iOS and Android will be able to automatically apply or recommend email sensitivity labels based on the labels already assigned to attached files.
The update is designed for organizations that use Microsoft Purview sensitivity labels and aims to make information protection more consistent across mobile email. It also addresses a common challenge for employees: remembering to manually classify an email every time they attach sensitive or confidential documents.
For organizations that rely heavily on Microsoft 365 and mobile working, the change could be a small but useful improvement. Instead of treating the email and its attachments as completely separate pieces of information, Outlook will be able to use the sensitivity information attached to the files to help determine the appropriate classification for the message.
What is changing in Outlook for iOS and Android?
The new capability introduces support for Microsoft Purview sensitivity label inheritance from attachments in Outlook’s mobile apps.
In practical terms, imagine an employee is composing an email on an iPhone or Android device and attaches a document that already has a Microsoft Purview sensitivity label. Outlook can use that information, together with the organization’s configured labeling policies, to automatically apply an appropriate sensitivity label to the email or recommend one to the user.
The exact behavior will depend on how an organization has configured its Microsoft Purview sensitivity labeling policies.
This is important because sensitive information does not always exist in the body of an email. Often, the most important information is contained in an attachment — such as a financial report, customer document, internal strategy presentation, contract or confidential spreadsheet.
If that attachment has already been classified, carrying that classification into the email workflow can help reduce the possibility of the surrounding message being given a lower level of protection.
Why does this matter?
Sensitivity labels are an important part of Microsoft’s broader information protection strategy. They help organizations classify data and, depending on configuration, apply protection controls to information based on its sensitivity.
However, classification systems are only effective when employees use them consistently.
Manual labeling can introduce friction. An employee may know that a document is confidential but forget to apply the same classification to the email containing that document. Another employee might simply be unaware that the attachment has a higher sensitivity classification than the message itself.
The new Outlook mobile capability is intended to reduce this gap.
By considering the sensitivity labels attached to files, Outlook can help users make more appropriate decisions when sending messages. For employees, that could mean fewer clicks and fewer decisions during the process of composing an email.
For IT and compliance teams, it could mean greater consistency in how information is classified across the organization.
A particularly useful update for mobile workers
The timing of the feature is also significant.
Employees increasingly work from smartphones and tablets, particularly when they are traveling, working remotely or responding to urgent business requests outside the office. Mobile email can make it harder to follow detailed data protection procedures because users are working with smaller screens and simplified interfaces.
A feature that can automatically identify relevant sensitivity information from an attachment can therefore remove some of the burden from the user.
For example, consider a sales manager who receives a confidential pricing spreadsheet, makes a few changes and sends it to an internal colleague from an Android phone. If the spreadsheet carries a Microsoft Purview sensitivity label, Outlook can use the organization’s policies to help determine whether the email should receive a corresponding label.
The goal isn’t to make employees experts in information classification. Instead, the system can use information that is already available to support better classification decisions.
Organizations don’t need to take administrative action
One of the notable aspects of the announcement is that no admin action is required for the rollout.
Microsoft says the feature will become generally available worldwide, including GCC, GCC High and DoD environments, in late September 2026.
That doesn’t mean organizations should ignore the change.
Companies already using Microsoft Purview sensitivity labels should take the opportunity to review their existing configuration and make sure attachment-based inheritance produces the outcomes they expect.
In particular, IT and compliance teams should review their current label publishing policies, sensitivity label inheritance settings and protection configurations.
The objective should be to ensure that the organization’s existing information protection strategy works as intended when employees send labeled files through Outlook on mobile devices.
What users can expect
From a user’s perspective, the experience should be relatively straightforward.
When an email contains one or more files with Microsoft Purview sensitivity labels, Outlook may automatically apply an appropriate sensitivity label to the email. In other cases, it may recommend a label for the user.
The decision is based on the organization’s configured Microsoft Purview labeling policies.
That distinction is important. The feature isn’t simply going to copy every attachment’s label to every email regardless of context. Instead, Outlook uses the organization’s configured rules to determine the appropriate behavior.
As a result, different organizations may see different experiences depending on how their sensitivity labeling policies are configured.
For employees, however, the broader goal is the same: less manual work and more consistent classification.
A potential compliance benefit
The update could also be valuable from a compliance perspective.
Many organizations have policies requiring sensitive or regulated information to receive specific levels of protection. An email containing a highly sensitive attachment can create a potential classification gap if the document is properly labeled but the email itself is not.
Attachment-based label inheritance is intended to help address that problem.
It doesn’t replace an organization’s broader compliance program, and it shouldn’t be viewed as a guarantee that every message will always receive the correct classification. Organizations still need appropriate policies, user education and governance.
But automating part of the classification process can reduce reliance on users remembering every step themselves.
That can be particularly useful in large organizations where thousands of employees send documents through email every day.
What IT teams should review
Although Microsoft says there is no administrative action required to enable the rollout, organizations using Microsoft Purview should still perform a policy review.
IT administrators and compliance teams should consider checking:
- Existing sensitivity label publishing policies.
- Rules governing sensitivity label inheritance.
- Protection settings associated with existing labels.
- Whether attachment-based inheritance matches internal data classification policies.
- Whether the resulting behavior meets regulatory and compliance requirements.
- Existing documentation and training provided to employees.
Organizations may also want to test the feature with common business scenarios before updating internal guidance.
For example, teams can examine what happens when an email contains multiple attachments with different sensitivity classifications. They can also confirm whether the resulting email label aligns with their organization’s expectations.
What this means for Microsoft 365 users
This update may not look dramatic on the surface, but it reflects a broader trend in enterprise software: security controls are increasingly being built into everyday workflows rather than left entirely to employees.
The less users have to remember, the easier it becomes to apply security policies consistently.
Outlook for iOS and Android already serves as a critical communication tool for employees working outside traditional office environments. Adding more intelligent sensitivity-label behavior gives organizations another way to extend their information protection policies to mobile work.
The feature also helps bring the mobile Outlook experience closer to the broader information protection approach used across Microsoft 365.
Rollout begins in late September 2026
Microsoft plans to begin general availability worldwide in late September 2026, with the rollout also covering GCC, GCC High and DoD environments.
Organizations using Microsoft Purview sensitivity labels should therefore expect the capability to arrive without needing to manually enable it.
The best approach is not necessarily to make immediate configuration changes, but to review current policies and understand how labeled attachments should influence email classification within the organization.
For employees, the biggest change may simply be that Outlook starts doing more of the labeling work in the background.
For security and compliance teams, the bigger story is consistency.
When sensitive documents are already classified, having Outlook use that information while users compose emails can help close a gap between document protection and email protection. It can reduce manual labeling, support compliance objectives and make it easier for employees to follow information protection policies — even when they’re working from a mobile device.
In short, Microsoft’s latest Outlook mobile update is less about adding another feature for the sake of convenience and more about making security classification a natural part of the email experience.
As organizations continue to depend on mobile work, that kind of behind-the-scenes automation could become increasingly important.



