Skip to content
All articlesSharePoint

Purview Auto-Labeling Failure Codes for SharePoint Files: What Each Means

All 23 failure codes Purview reports when auto-labeling a SharePoint file fails: which retry on their own, which need action, and where to find the code.

3 Oct 20268 min read
Purview Auto-Labeling Failure Codes for SharePoint Files: What Each Means

Auto-labeling failed on a SharePoint file: what the failure codes mean

When a Microsoft Purview auto-labeling policy matches a file in SharePoint or OneDrive but cannot apply the label, Purview records a failure code against that file. Microsoft documents 23 of them. Eleven retry on their own, six describe something that is by design and need nothing from you, and six need you to change something before the file can be labeled.

That split is the useful part. Most of the codes you will see are the first two groups, and the instinct to investigate every one wastes time. This page sorts them, shows where to find the code for a given file, and covers the one case, QuotaExceeded, that is really a storage problem.

For the wider picture of how classification works in SharePoint, see SharePoint data classification.

Where to find the failure code for a file

You need one of these roles to see the details: Compliance Administrator, Compliance Data Administrator, Information Protection Admin or Information Protection Analyst.

  1. Sign in to the Microsoft Purview portal.
  2. Go to Information Protection, then Auto-labeling.
  3. Select the policy you want to check.
  4. On the Overview tab, the Labeling failures card shows a snapshot of the failures from the last 30 days and the top three reasons.
  5. Select Review items, or open the Labeling failures tab, to see the files.
  6. Select a file, open the Details tab, and note the code under Failure reason.

What happens to the file when labeling fails

Nothing changes. Microsoft states that when a labeling operation fails, the affected file keeps the label it had before, or has no label if it had not been assigned one already. A failure is a missed label, not a removed one.

Microsoft also separates the causes. Failures caused by SharePoint or OneDrive infrastructure conditions are transient, and the service retries them automatically. Failures caused by the file format, protection on the file or the way the label is configured have to be resolved by hand.

The six codes that need you to act

CodeWhat it meansWhat to do
EncryptedFileNotSupportedThe file is protected by external encryption, such as a password or non-Microsoft encryption, which prevents the label being appliedRemove the external encryption or password protection
UnsupportedFileTypeMicrosoft's description is "PDF Labeling isn't enabled"Enable sensitivity labels for files in SharePoint and OneDrive
DisabledOrUnsupportedLabelThe label is disabled or not supported for the tenantCheck the label is published and active in your labeling policy
InvalidFileNameThe file name is not validRename the file to remove invalid characters, or shorten it
CancelledByEventHandlerAn event handler on the SharePoint site cancelled the operationReview custom event receivers on the affected site, because one is rejecting label-property updates
QuotaExceededThe site's storage quota is exceededFree up storage on the site or increase the quota, then rerun the policy

UnsupportedFileType is the one most often misread. The name suggests a bad file, but Microsoft's description is that PDF labeling has not been switched on, so the fix is a tenant setting and not a change to any file.

The eleven codes that retry on their own

Microsoft's recommended action for each of these is that no action is required and the operation is retried automatically.

CodeWhat it means
FileLockedAnother user or process has the file locked
FileCheckOutA user has the file checked out
GetTagsFailureSharePoint could not read the label metadata already on the file
RmsUnavailableAzure Rights Management was briefly unavailable, which matters when the label also applies encryption
ConflictThe file was being modified at the same moment, causing a version or save conflict
TransientA temporary infrastructure error
UnauthorizedAccessExceptionThe system was denied access while modifying the file
Unknown_SPExceptionAn unclassified SharePoint error. If you see it repeatedly for the same files, contact Microsoft Support
TransientErrorStorageConnectionA temporary storage connectivity error
GenericExceptionAn unexpected error
SqlThrottledSharePoint was throttling requests because of high database load

If many files fail with the same code, Microsoft's advice is to check the SharePoint Online service health dashboard for an active incident in the same time window before investigating further. A spike in SqlThrottled, TransientErrorStorageConnection or Unknown_SPException often corresponds to a known service event.

The six codes that need nothing, by design

CodeWhat it means
FileNotSupportedThe file type does not support sensitivity labels
FileExtensionNotSupportedThe file extension does not support sensitivity labels
CannotOverrideCurrentLabelThe file already has a label of equal or higher priority than the one the policy is applying, so the existing label takes precedence
ZeroByteFileThe file is empty, and label metadata cannot be written to an empty file
DirectoryNotFoundThe folder was deleted after the file was classified
FileNotFoundThe file was deleted or moved after it was classified

FileNotSupported and FileExtensionNotSupported are worth pausing on. For SharePoint and OneDrive, Microsoft lists PDF and the Word (.docx), PowerPoint (.pptx) and Excel (.xlsx) formats as supported for auto-labeling. These two codes describe files whose type cannot carry a sensitivity label, so nothing you change in the policy will label them.

QuotaExceeded is a storage problem

Of the 23 codes, this is the only one where the cause is the size of the site and not the file or the policy. A site over its storage quota cannot be labeled until space is freed or the quota is raised, and then the policy has to be rerun.

If you are over quota anyway, these are the places to start:

Archiving inactive files is one way to release space. Squirrel moves inactive files into your own Azure storage and leaves a pointer page in SharePoint, and a user restores a file in one click. Archiving reduces bytes, not item counts, so it will not help with a limit on the number of items.

A file can be unlabeled without any failure at all

A file with no failure code has not necessarily been evaluated. Microsoft's checklist for files that were expected to be labeled says that auto-labeling only evaluates content that was created or modified after the sensitive information type was created or last modified, and that older unchanged files need an on-demand classification scan.

Content that has been archived out of SharePoint is a separate case. When Squirrel archives a file, SharePoint keeps only a small pointer page in its place, and anything that looks at SharePoint sees the pointer page, not the document. Forage reads the archive copy and, where content classification is enabled, records what it contains. It does not apply Microsoft labels, and it requires Squirrel.

Frequently asked questions

Does a failed auto-labeling attempt remove the label a file already has?

No. The file keeps the label it had before the attempt, or stays unlabeled if it had none.

Does Purview retry failed labeling automatically?

For infrastructure causes, yes. Microsoft treats those failures as transient and the service retries them. Failures caused by the file format, file protection or label configuration have to be resolved manually.

What does UnsupportedFileType mean in Purview auto-labeling?

Microsoft's description is that PDF labeling is not enabled. The fix is to enable sensitivity labels for files in SharePoint and OneDrive, which is a tenant setting and not a problem with the file.

Why is my file not labeled when there is no failure?

Most likely it was never evaluated. Auto-labeling only looks at content created or modified after the sensitive information type was created or last modified, so older unchanged files need an on-demand classification scan.

How far back does the failure list go?

The Labeling failures card on the policy's Overview tab shows a snapshot of the failures from the last 30 days, along with the top three reasons.

Who can see the failure details?

Members of the Compliance Administrator, Compliance Data Administrator, Information Protection Admin or Information Protection Analyst roles.

About the author
Mark Smith - Co-Founder, SmiKar Software

Mark Smith co-founded SmiKar Software in 2015 and has spent the past decade helping organisations solve Microsoft 365 data management challenges. He works with the SmiKar team to build solutions for SharePoint archiving, storage optimisation, governance and compliance, supporting customers from growing businesses through to Fortune 500 enterprises.

More about SmiKar

Ready when you are

Cut your Microsoft 365 storage bill - keep your data in your tenant.