Once data asset policies are created to apply labels, Data Security will regularly scan assets (of the right file types) that
match the policy’s criterion and attempt to apply the label. Labels are only
applied if the policy driven label has a higher priority than the label
currently on the asset.
For example, if an asset has the Top Secret (the highest
priority) label and a matching policy needs to apply the Confidential
(which has lower priority than Top Secret) label, the policy will not
attempt to apply the label. This will also apply when multiple policies match
the asset. Eventually, the rule with the highest priority label will get
applied.
Data Security applies labels by invoking
Microsoft Graph API. This applies the label asynchronously on the asset. So,
there might be a lag between the moment Data Security
applying the label and the label actually reflecting
on the file in Office 365.