Auto-labeling failed on a SharePoint file: what the failure codes mean
When a Microsoft Purview auto-labeling policy matches a file in SharePoint or OneDrive but cannot apply the label, Purview records a failure code against that file. Microsoft documents 23 of them. Eleven retry on their own, six describe something that is by design and need nothing from you, and six need you to change something before the file can be labeled.
That split is the useful part. Most of the codes you will see are the first two groups, and the instinct to investigate every one wastes time. This page sorts them, shows where to find the code for a given file, and covers the one case, QuotaExceeded, that is really a storage problem.
For the wider picture of how classification works in SharePoint, see SharePoint data classification.
Where to find the failure code for a file
You need one of these roles to see the details: Compliance Administrator, Compliance Data Administrator, Information Protection Admin or Information Protection Analyst.
- Sign in to the Microsoft Purview portal.
- Go to Information Protection, then Auto-labeling.
- Select the policy you want to check.
- On the Overview tab, the Labeling failures card shows a snapshot of the failures from the last 30 days and the top three reasons.
- Select Review items, or open the Labeling failures tab, to see the files.
- Select a file, open the Details tab, and note the code under Failure reason.
What happens to the file when labeling fails
Nothing changes. Microsoft states that when a labeling operation fails, the affected file keeps the label it had before, or has no label if it had not been assigned one already. A failure is a missed label, not a removed one.
Microsoft also separates the causes. Failures caused by SharePoint or OneDrive infrastructure conditions are transient, and the service retries them automatically. Failures caused by the file format, protection on the file or the way the label is configured have to be resolved by hand.
The six codes that need you to act
| Code | What it means | What to do |
|---|---|---|
EncryptedFileNotSupported | The file is protected by external encryption, such as a password or non-Microsoft encryption, which prevents the label being applied | Remove the external encryption or password protection |
UnsupportedFileType | Microsoft's description is "PDF Labeling isn't enabled" | Enable sensitivity labels for files in SharePoint and OneDrive |
DisabledOrUnsupportedLabel | The label is disabled or not supported for the tenant | Check the label is published and active in your labeling policy |
InvalidFileName | The file name is not valid | Rename the file to remove invalid characters, or shorten it |
CancelledByEventHandler | An event handler on the SharePoint site cancelled the operation | Review custom event receivers on the affected site, because one is rejecting label-property updates |
QuotaExceeded | The site's storage quota is exceeded | Free up storage on the site or increase the quota, then rerun the policy |
UnsupportedFileType is the one most often misread. The name suggests a bad file, but Microsoft's description is that PDF labeling has not been switched on, so the fix is a tenant setting and not a change to any file.
The eleven codes that retry on their own
Microsoft's recommended action for each of these is that no action is required and the operation is retried automatically.
| Code | What it means |
|---|---|
FileLocked | Another user or process has the file locked |
FileCheckOut | A user has the file checked out |
GetTagsFailure | SharePoint could not read the label metadata already on the file |
RmsUnavailable | Azure Rights Management was briefly unavailable, which matters when the label also applies encryption |
Conflict | The file was being modified at the same moment, causing a version or save conflict |
Transient | A temporary infrastructure error |
UnauthorizedAccessException | The system was denied access while modifying the file |
Unknown_SPException | An unclassified SharePoint error. If you see it repeatedly for the same files, contact Microsoft Support |
TransientErrorStorageConnection | A temporary storage connectivity error |
GenericException | An unexpected error |
SqlThrottled | SharePoint was throttling requests because of high database load |
If many files fail with the same code, Microsoft's advice is to check the SharePoint Online service health dashboard for an active incident in the same time window before investigating further. A spike in SqlThrottled, TransientErrorStorageConnection or Unknown_SPException often corresponds to a known service event.
The six codes that need nothing, by design
| Code | What it means |
|---|---|
FileNotSupported | The file type does not support sensitivity labels |
FileExtensionNotSupported | The file extension does not support sensitivity labels |
CannotOverrideCurrentLabel | The file already has a label of equal or higher priority than the one the policy is applying, so the existing label takes precedence |
ZeroByteFile | The file is empty, and label metadata cannot be written to an empty file |
DirectoryNotFound | The folder was deleted after the file was classified |
FileNotFound | The file was deleted or moved after it was classified |
FileNotSupported and FileExtensionNotSupported are worth pausing on. For SharePoint and OneDrive, Microsoft lists PDF and the Word (.docx), PowerPoint (.pptx) and Excel (.xlsx) formats as supported for auto-labeling. These two codes describe files whose type cannot carry a sensitivity label, so nothing you change in the policy will label them.
QuotaExceeded is a storage problem
Of the 23 codes, this is the only one where the cause is the size of the site and not the file or the policy. A site over its storage quota cannot be labeled until space is freed or the quota is raised, and then the policy has to be rerun.
If you are over quota anyway, these are the places to start:
- SharePoint storage full or almost full: how to free up space covers why deleting files does not always release space, and what to do instead.
- Find over-quota OneDrives and SharePoint sites with PowerShell lists the sites that are affected.
- See what is using your SharePoint storage breaks the usage down by site, library and file.
Archiving inactive files is one way to release space. Squirrel moves inactive files into your own Azure storage and leaves a pointer page in SharePoint, and a user restores a file in one click. Archiving reduces bytes, not item counts, so it will not help with a limit on the number of items.
A file can be unlabeled without any failure at all
A file with no failure code has not necessarily been evaluated. Microsoft's checklist for files that were expected to be labeled says that auto-labeling only evaluates content that was created or modified after the sensitive information type was created or last modified, and that older unchanged files need an on-demand classification scan.
Content that has been archived out of SharePoint is a separate case. When Squirrel archives a file, SharePoint keeps only a small pointer page in its place, and anything that looks at SharePoint sees the pointer page, not the document. Forage reads the archive copy and, where content classification is enabled, records what it contains. It does not apply Microsoft labels, and it requires Squirrel.
Frequently asked questions
Does a failed auto-labeling attempt remove the label a file already has?
No. The file keeps the label it had before the attempt, or stays unlabeled if it had none.
Does Purview retry failed labeling automatically?
For infrastructure causes, yes. Microsoft treats those failures as transient and the service retries them. Failures caused by the file format, file protection or label configuration have to be resolved manually.
What does UnsupportedFileType mean in Purview auto-labeling?
Microsoft's description is that PDF labeling is not enabled. The fix is to enable sensitivity labels for files in SharePoint and OneDrive, which is a tenant setting and not a problem with the file.
Why is my file not labeled when there is no failure?
Most likely it was never evaluated. Auto-labeling only looks at content created or modified after the sensitive information type was created or last modified, so older unchanged files need an on-demand classification scan.
How far back does the failure list go?
The Labeling failures card on the policy's Overview tab shows a snapshot of the failures from the last 30 days, along with the top three reasons.
Who can see the failure details?
Members of the Compliance Administrator, Compliance Data Administrator, Information Protection Admin or Information Protection Analyst roles.
Related reading
- SharePoint data classification - the tools, their limits and a path for a whole tenant.
- Sensitivity labels vs retention labels in SharePoint - the two label types admins confuse.
- Microsoft Purview explained - the pieces of Purview and where each fits.
- SharePoint storage full or almost full - the storage side of
QuotaExceeded. - Forage: records management for SharePoint and the Squirrel archive
Mark Smith co-founded SmiKar Software in 2015 and has spent the past decade helping organisations solve Microsoft 365 data management challenges. He works with the SmiKar team to build solutions for SharePoint archiving, storage optimisation, governance and compliance, supporting customers from growing businesses through to Fortune 500 enterprises.
More about SmiKar


