{"id":22681,"date":"2026-05-28T10:30:00","date_gmt":"2026-05-28T17:30:00","guid":{"rendered":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/?p=22681"},"modified":"2026-05-28T10:56:26","modified_gmt":"2026-05-28T17:56:26","slug":"transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra","status":"publish","type":"post","link":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/","title":{"rendered":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Security groups serve as the backbone of our approach to access control across the Microsoft corporate tenant. These groups determine who has access to different resources across our network, including Azure subscriptions, Power BI reports, SharePoint sites, and more.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For years, our security groups operated without consistent, policy\u2011based guardrails. As a result, we couldn\u2019t uniformly control guest access to sensitive resources or apply governance consistently across different group types.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Addressing this required a complex, coordinated effort by our team here in Microsoft Digital, the company\u2019s IT organization, and the Microsoft Entra product team.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/05\/David-Johnson.png\" alt=\"A photo of Johnson.\" class=\"wp-image-20994\" style=\"width:150px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/05\/David-Johnson.png 500w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/05\/David-Johnson-300x300.png 300w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/05\/David-Johnson-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cBecause IT security is our highest priority at Microsoft, we knew we needed a better approach to limiting access to groups within our tenant. And we realized that Microsoft Entra was a powerful in-house solution that represented our best path forward to solve for this challenge.\u201d<\/p>\n<cite>David Johnson, principal product manager architect, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a new approach to sensitivity labels across the organization that strengthens our security posture, which benefits Microsoft and our customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBecause IT security is our highest priority at Microsoft, we knew we needed a better approach to limiting access to groups within our tenant,\u201d says David Johnson, a principal product manager architect in Microsoft Digital. \u201cAnd we realized that Microsoft Entra was a powerful in-house solution that represented our best path forward to solve for this challenge.\u201d<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex has-2-columns\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:65px\">\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"95\" height=\"96\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Learn-how-p-g.png\" alt=\"\" class=\"wp-image-19668\" style=\"width:48px\"\/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><strong>Go deeper<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4);margin-bottom:var(--wp--preset--spacing--spacing-4)\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/users\/groups-assign-sensitivity-labels\" type=\"link\" id=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/users\/groups-assign-sensitivity-labels\" target=\"_blank\" rel=\"noreferrer noopener\">Learn how to assign sensitivity labels to Microsoft Entra security groups.<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Closing the security gap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sensitivity labels for Microsoft 365 groups are labels that govern join and access restrictions for membership and sharing. They have been a product feature since 2020. But sensitivity labels for security groups\u2014labels that enforce rules about who can join a group\u2014had no equivalent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This meant that organizations that wanted to govern who could join a security group or determine if guests are permitted and how group membership is managed had to either lock down the group creation process entirely, or rely on reactive scanning after the fact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Security groups are a key piece of our efforts to secure sensitive resources,&#8221; says Mohit Bhargava, a principal product manager on the Microsoft Entra team, which manages the Entra family of identity and network access products. \u201cWe wanted to apply policies to protect who could be in security groups so that the sensitive resources in those groups would remain secure.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/Basanth-Kakumani.png\" alt=\"A photo of Kakumani.\" class=\"wp-image-22687\" style=\"width:150px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/Basanth-Kakumani.png 500w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/Basanth-Kakumani-300x300.png 300w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/Basanth-Kakumani-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Whoever gets into an Azure security group can have access to all the resources associated with the Azure subscription. That&#8217;s a potential high-severity threat.&#8221;<\/p>\n<cite>Basanth Kakumani, software engineer II, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The security risk is real. If an unauthorized guest account ends up as a member of a security group that governs access to an Azure subscription, that guest gains access to every resource inside that subscription.<\/p>\n\n\n\n<aside class=\"wp-block-group aside-for-guide has-white-200-background-color has-background has-global-padding is-content-justification-right is-layout-constrained wp-container-core-group-is-layout-3f1abf08 wp-block-group-is-layout-constrained\" style=\"border-radius:10px;padding-top:var(--wp--preset--spacing--spacing-12);padding-right:var(--wp--preset--spacing--spacing-12);padding-bottom:var(--wp--preset--spacing--spacing-12);padding-left:var(--wp--preset--spacing--spacing-12)\">\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-298f84b7 wp-block-group-is-layout-flex\" style=\"margin-top:0;margin-bottom:0;padding-top:0;padding-bottom:0\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"132\" height=\"132\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/10\/Engage-with-our-experts_blogs.png\" alt=\"\" class=\"wp-image-20636\" style=\"width:48px\"\/><\/figure>\n\n\n\n<p class=\"has-body-lg-font-size wp-block-paragraph\"><strong>Engage with our experts!<\/strong><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-4)\">Customers or Microsoft account team representatives from Fortune 500 companies are welcome to <a href=\"mailto:msitstaff@microsoft.com\">request a virtual engagement<\/a> on this topic with experts from our Microsoft Digital team.<\/p>\n<\/aside>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Whoever gets into an Azure security group can have access to all the resources associated with the Azure subscription,&#8221; says Basanth Kakumani, a software engineer II in Microsoft Digital. &#8220;That&#8217;s a potential high-severity threat.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another priority was the need for consistency across experiences.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Microsoft 365 groups have supported labeling for a very long time,&#8221; Bhargava says. &#8220;Customers have an expectation that there&#8217;s parity across group types, so that they can govern them uniformly. That was another driving factor for this work.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security groups reuse the same sensitivity labels already configured for Microsoft 365 groups and SharePoint sites in Microsoft Purview\u2014so admins don\u2019t need to create or manage a separate set of labels. This reuse reduces configuration overhead and supports a more consistent governance model across group types.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Security workarounds, and why they fell short<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Without sensitivity label support, we had to make do with alternative solutions. The most common one was simply preventing certain users from creating any security groups at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the Microsoft tenant, this meant that employees who needed a security group had to fill out a form that had custom business logic behind it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We had on-premises, Active Directory, synchronization, tooling, and customization,&#8221; Johnson says. &#8220;This caused latency, from the time you created your group to the time it would show cloud membership. If you wanted to manage your membership, you had to do it on premises, AD, and then wait for it to sync to Entra.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither centralized control nor reactive governance was a satisfying solution to prevent policy violations.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThis is really about making reactive things more proactive. We want to catch problems before they occur.\u201d<\/p>\n<cite>John Begley, principal software engineer, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Typically, IT is going to manage this in one of two ways: Either we turn off self-service and manage everything on behalf of users, or we do reactive governance, which includes scanning groups and looking for policy violations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those aren\u2019t super effective at preempting violations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis is really about making reactive things more proactive,\u201d says John Begley, a principal software engineer in Microsoft Digital. \u201cWe want to catch problems before they occur.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A collaborative solution<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Coming up with a solution to this challenge required a genuine partnership.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We at Microsoft Digital approached the Entra product team and explained the problem we were trying to solve. Rather than simply handling this as a feature request, the two teams agreed to a co-development arrangement.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Having access to a very large customer who cares deeply about security was extremely helpful. If it works for Microsoft, which is so complicated and huge, it&#8217;s going to work for smaller-sized tenants too.&#8221;<\/p>\n<cite>Mohit Bhargava, principal product manager, Microsoft Entra<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft Digital team members would work alongside Entra engineers as the feature was built, serving simultaneously as implementation partner, design critic, and test environment\u2014what we like to call <a href=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/inside-microsoft-being-customer-zero-in-an-ai-powered-world\/\">our Customer Zero role<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bhargava found the partnership equally illuminating from the product side.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Having access to a very large customer who cares deeply about security was extremely helpful,\u201d he says. \u201cIf it works for Microsoft, which is so complicated and huge, it&#8217;s going to work for smaller-sized tenants too.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Begley and his team, working closely with the product team revealed how complex the solution actually was.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Both the product team and Microsoft Digital walked into this thinking a fix was going to be simpler than what it turned out to be,&#8221; Begley says. &#8220;It&#8217;s been eye-opening to see how the product is built, how it runs, what all the moving parts are. We learned early on that there was significant co\u2011development happening within Entra itself, across teams with very different areas of expertise.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That dynamic played out in specific feature decisions. The team&#8217;s original plan did not include support for agent access controls and didn\u2019t include the ability to prevent AI agents from joining sensitive security groups. This is something the product group quickly addressed and resolved after our team in Microsoft Digital raised it as a concern.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;One of the first customers who raised it was Microsoft Digital,&#8221; Bhargava says. &#8220;They said we needed need to start thinking about it ahead of time to get ahead of the problem.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sensitivity labels for Microsoft Entra cloud security groups are now in public preview. The same labels you publish in Microsoft Purview for Microsoft 365 groups and sites now apply to Entra security groups. <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/users\/groups-assign-sensitivity-labels?tabs=microsoft\" target=\"_blank\" rel=\"noreferrer noopener\">Visit Microsoft Learn for scope, supported scenarios, and current preview behaviors.<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Changes afoot for IT admins and employees<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The practical impact of this solution lands on both sides of the relationship between Microsoft Digital and the company\u2019s employees.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Now I can&#8217;t accidentally have guests in an internal-only group, which changes the dynamic. Employees can create their own Entra security groups now, without us having to worry that they&#8217;ll be inviting guests where they shouldn&#8217;t be.&#8221;<\/p>\n<cite>David Johnson, principal product manager architect, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">For IT admins, the shift is from reactive remediation to proactive prevention. For employees, it means self-service action with security groups become viable again, without the security risks that made organizations reluctant to enable it before.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Now I can&#8217;t accidentally have guests in an internal-only group, which changes the dynamic,&#8221; Johnson says. &#8220;Employees can create their own Entra security groups now, without us having to worry that they&#8217;ll be inviting guests where they shouldn&#8217;t be.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Johnson underscores the broader ambition behind the shift, which is to allow employees to create and manage groups directly in Entra.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;A company that can unblock self-service action by its employees with confidence, knowing that there\u2019s an additional level of protection\u2014that&#8217;s very important,&#8221; he says.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Looking ahead: AI and the expanding policy surface<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Labeling support for security groups is already being extended across the organization, with AI governance in mind.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding the ability to block agents from joining sensitive security groups is our next logical step. Guest membership is enforced via allow-to-add guest policy, but agents won&#8217;t join in the same way. Rather, we will set policies in Purview and then use labels to control if an agent can join a group.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The longer-term vision involves extending oversharing prevention beyond Entra itself. This will make it impossible (not just detectable) to accidentally assign a highly confidential resource to an unlabeled or inappropriately scoped security group. The foundation we\u2019ve built with labeling in Entra is what makes this vital step possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We want to get into the preventative aspect,&#8221; Johnson says. &#8220;The goal is to make it so it\u2019s not possible to overshare in the first place.&#8221;<\/p>\n\n\n\n<div class=\"wp-block-group has-global-padding is-content-justification-left is-layout-constrained wp-container-core-group-is-layout-c0392459 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"190\" height=\"190\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Key-takeaways-badge.png\" alt=\"\" class=\"wp-image-19493\" style=\"object-fit:cover;width:75px;height:75px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Key-takeaways-badge.png 190w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Key-takeaways-badge-150x150.png 150w\" sizes=\"auto, (max-width: 190px) 100vw, 190px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-24);margin-bottom:0;padding-top:var(--wp--preset--spacing--spacing-24)\">Key takeaways<\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some tips as you consider ways to address how you manage your own security labeling practices: &nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Reuse existing labels\u2014no extra setup required.<\/strong> Security groups reuse the same sensitivity labels already configured for Microsoft 365 Groups and SharePoint sites in Microsoft Purview, eliminating duplicate configuration and helping admins apply a consistent governance model across group types.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Understand label immutability at launch.<\/strong> Unlike Microsoft 365 Groups, sensitivity labels on security groups are initially immutable\u2014a deliberate design choice to ensure protections are enforced from the moment a group is created. Controlled label mutability will be introduced in a subsequent update.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Know what\u2019s in scope today. <\/strong>Labeling currently applies to static, non\u2013mail-enabled security groups. Dynamic membership groups, mail-enabled security groups, and distribution lists aren\u2019t supported at launch, so admins should plan accordingly.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Shift from reactive cleanup to proactive protection.<\/strong> Label-driven membership controls prevent policy violations\u2014such as unintended guest access\u2014before they occur, reducing the need for post-creation audits and remediation.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Enable safe self-service with guardrails.<\/strong> With labels enforcing access rules automatically, employees can create and manage security groups without increasing risk, restoring self-service without sacrificing control.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Lay the foundation for future governance scenarios.<\/strong> Using sensitivity labels as the backbone of access policy creates a scalable framework that can extend to additional protections over time, including broader enforcement and emerging governance needs.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-content-justification-left is-layout-constrained wp-container-core-group-is-layout-c0392459 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"190\" height=\"190\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Try-it-out-badge.png\" alt=\"\" class=\"wp-image-19492\" style=\"object-fit:cover;width:75px;height:75px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Try-it-out-badge.png 190w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Try-it-out-badge-150x150.png 150w\" sizes=\"auto, (max-width: 190px) 100vw, 190px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-24);margin-bottom:0;padding-top:var(--wp--preset--spacing--spacing-24)\">Try it out<\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/users\/groups-sensitivity-labels?OCID=InsideTrack_Product_10822\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about configuring security with Microsoft Entra.<\/a><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-content-justification-left is-layout-constrained wp-container-core-group-is-layout-c0392459 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"190\" height=\"190\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Related-links-badge.png\" alt=\"\" class=\"wp-image-19491\" style=\"object-fit:cover;width:75px;height:75px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Related-links-badge.png 190w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Related-links-badge-150x150.png 150w\" sizes=\"auto, (max-width: 190px) 100vw, 190px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-24);margin-bottom:0;padding-top:var(--wp--preset--spacing--spacing-24)\">Related links<\/p>\n<\/div>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--spacing-20)\" class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/empowering-employee-self-service-with-guardrails-how-were-using-sensitivity-labels-to-make-microsoft-more-secure\/\">Learn how we\u2019re using sensitivity labels to make Microsoft more secure.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/fundamentals\/\" target=\"_blank\" rel=\"noreferrer noopener\">Get an overview of Microsoft Entra fundamentals documentation.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/microsoft-creates-self-service-sensitivity-labels-in-microsoft-365\/\">Find out how self-service sensitivity labels to help our employees stay productive without exposing sensitive information.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/implementing-a-zero-trust-security-model-at-microsoft\/\">See what it took to transition our company to a Zero Trust security model.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"\/insidetrack\/blog\/boosting-our-secure-future-initiative-at-microsoft-with-a-transformed-approach-to-wired-network-security\/\">Explore how we\u2019re boosting our Secure Future Initiative with a new approach to wired network security.<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-group has-global-padding is-content-justification-left is-layout-constrained wp-container-core-group-is-layout-c0392459 wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<div class=\"wp-block-group has-global-padding is-layout-constrained wp-container-core-group-is-layout-7db9d80f wp-block-group-is-layout-constrained\" style=\"padding-right:0;padding-left:0\">\n<figure class=\"wp-block-image alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"190\" height=\"190\" src=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Wed-like-to-hear-from-you-badge.png\" alt=\"\" class=\"wp-image-19490\" style=\"object-fit:cover;width:75px;height:75px\" srcset=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Wed-like-to-hear-from-you-badge.png 190w, https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/07\/Wed-like-to-hear-from-you-badge-150x150.png 150w\" sizes=\"auto, (max-width: 190px) 100vw, 190px\" \/><\/figure>\n\n\n\n<p class=\"has-body-xl-font-size wp-block-paragraph\" style=\"margin-top:var(--wp--preset--spacing--spacing-24);margin-bottom:0;padding-top:var(--wp--preset--spacing--spacing-24)\">We&#8217;d like to hear from you!<\/p>\n<\/div>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--spacing-20)\" class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"mailto:msitstaff@microsoft.com\">Want more information? Email us and include a link to this story and we\u2019ll get back to you.<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security groups serve as the backbone of our approach to access control across the Microsoft corporate tenant. These groups determine who has access to different resources across our network, including Azure subscriptions, Power BI reports, SharePoint sites, and more. For years, our security groups operated without consistent, policy\u2011based guardrails. As a result, we couldn\u2019t uniformly [&hellip;]<\/p>\n","protected":false},"author":227,"featured_media":22683,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[199,868,827,115,689,848,851],"coauthors":[894],"class_list":["post-22681","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-ai","tag-ai-deployment-and-adoption","tag-microsoft-365-copilot","tag-microsoft-azure","tag-network-security","tag-security-and-risk-management","tag-tenant-management","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-28T17:30:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-28T17:56:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Stephanie Parry\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Stephanie Parry\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/\"},\"author\":{\"name\":\"Stephanie Parry\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/0a6fa3d0bb1a1e4813142232ee874c0c\"},\"headline\":\"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra\",\"datePublished\":\"2026-05-28T17:30:00+00:00\",\"dateModified\":\"2026-05-28T17:56:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/\"},\"wordCount\":1936,\"image\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/03\\\/10822-Hero_image.jpg\",\"keywords\":[\"AI\",\"AI deployment and adoption\",\"Microsoft 365 Copilot\",\"Microsoft Azure\",\"Network Security\",\"Security and risk management\",\"Tenant management\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/\",\"url\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/\",\"name\":\"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/03\\\/10822-Hero_image.jpg\",\"datePublished\":\"2026-05-28T17:30:00+00:00\",\"dateModified\":\"2026-05-28T17:56:26+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/0a6fa3d0bb1a1e4813142232ee874c0c\"},\"description\":\"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#primaryimage\",\"url\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/03\\\/10822-Hero_image.jpg\",\"contentUrl\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/03\\\/10822-Hero_image.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"We\u2019re now extending sensitivity labels to Entra security groups at Microsoft, allowing us to prevent oversharing and enable secure self-service at scale.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/0a6fa3d0bb1a1e4813142232ee874c0c\",\"name\":\"Stephanie Parry\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g18dc39db377ce7c1a5ad1725bdaf8597\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g\",\"caption\":\"Stephanie Parry\"},\"url\":\"https:\\\/\\\/new-cm-edgedigital.pages.dev\\\/insidetrack\\\/blog\\\/author\\\/sparry\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog","description":"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/","og_locale":"en_US","og_type":"article","og_title":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog","og_description":"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.","og_url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/","og_site_name":"Inside Track Blog","article_published_time":"2026-05-28T17:30:00+00:00","article_modified_time":"2026-05-28T17:56:26+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","type":"image\/jpeg"}],"author":"Stephanie Parry","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Stephanie Parry","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#article","isPartOf":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/"},"author":{"name":"Stephanie Parry","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/#\/schema\/person\/0a6fa3d0bb1a1e4813142232ee874c0c"},"headline":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra","datePublished":"2026-05-28T17:30:00+00:00","dateModified":"2026-05-28T17:56:26+00:00","mainEntityOfPage":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/"},"wordCount":1936,"image":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#primaryimage"},"thumbnailUrl":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","keywords":["AI","AI deployment and adoption","Microsoft 365 Copilot","Microsoft Azure","Network Security","Security and risk management","Tenant management"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/","url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/","name":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra - Inside Track Blog","isPartOf":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#primaryimage"},"image":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#primaryimage"},"thumbnailUrl":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","datePublished":"2026-05-28T17:30:00+00:00","dateModified":"2026-05-28T17:56:26+00:00","author":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/#\/schema\/person\/0a6fa3d0bb1a1e4813142232ee874c0c"},"description":"Learn how we extend sensitivity labels to our Microsoft Entra security groups using labels policy to prevent oversharing and enable secure self-service.","breadcrumb":{"@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#primaryimage","url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","contentUrl":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","width":2300,"height":1293,"caption":"We\u2019re now extending sensitivity labels to Entra security groups at Microsoft, allowing us to prevent oversharing and enable secure self-service at scale."},{"@type":"BreadcrumbList","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/transforming-our-approach-to-sensitivity-labels-at-microsoft-with-microsoft-entra\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Transforming our approach to sensitivity labels at Microsoft with Microsoft Entra"}]},{"@type":"WebSite","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/#website","url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/#\/schema\/person\/0a6fa3d0bb1a1e4813142232ee874c0c","name":"Stephanie Parry","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g18dc39db377ce7c1a5ad1725bdaf8597","url":"https:\/\/secure.gravatar.com\/avatar\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1673d453a91c9842992879dd94fbd75bd4ad918eb85dba05b6b89913006489fa?s=96&d=mm&r=g","caption":"Stephanie Parry"},"url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/author\/sparry\/"}]}},"jetpack_featured_media_url":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/uploads\/prod\/2026\/03\/10822-Hero_image.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-5TP","_links":{"self":[{"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/22681","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/227"}],"replies":[{"embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=22681"}],"version-history":[{"count":24,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/22681\/revisions"}],"predecessor-version":[{"id":23929,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/22681\/revisions\/23929"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/22683"}],"wp:attachment":[{"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=22681"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=22681"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=22681"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/new-cm-edgedigital.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=22681"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}