Insights

Two Microsoft pages, two different file limits

Braintree Insights | 28 August 2026

Two Microsoft pages, two different file limits

Microsoft’s security round-up published on 27 August 2026 states that Purview auto-labelling now processes up to 500,000 SharePoint and OneDrive files per day, up from 100,000. The Microsoft Learn documentation, last updated on 13 August 2026, states a maximum of 100,000 files per day in five places, including the guidance that tells administrators to use that figure when planning a policy.

What changed

Microsoft’s What’s new in Microsoft Security post of 27 August 2026 states that auto-labelling policies in Microsoft Purview now process up to 500,000 SharePoint and OneDrive files per day, up from 100,000, and presents this under the heading of speeding up Microsoft Copilot readiness. The Microsoft Learn article on applying a sensitivity label automatically, with an ms.date of 10 August 2026 and last updated on 13 August 2026, states a maximum of 100,000 automatically labelled files per tenant per day, repeats the figure in its troubleshooting guidance and in its explanation of labelling progress, and instructs administrators to use the main Auto-labelling page to see how all policies are tracking against the 100,000 files-per-day throughput limit when planning a new policy.

The risk here is not a breach or an outage. It is a plan built on a number that has changed, or a plan abandoned because of a number that no longer applies. Throughput limits are the sort of constraint that gets recorded once in a design document and then quietly governs decisions for years, and a labelling programme that was shelved as too slow is unlikely to be revisited unless somebody deliberately re-tests the assumption behind it.

What the term means in plain language

Auto-labelling in Microsoft Purview applies sensitivity labels to files in SharePoint and OneDrive without a user choosing the label. A policy defines which content qualifies, usually by matching sensitive information types, and the service labels matching files as it scans them. The label is not decorative: encryption, data loss prevention rules and access restrictions are attached to it, so labelling coverage determines how much content is actually protected. Microsoft ties this directly to Microsoft 365 Copilot, on the basis that labels are the mechanism that stops an assistant surfacing content a user should not see.

This distinction matters because product status is not the same as business readiness. Availability, support and compatibility are separate questions. A service can be available but unsupported, supported but capacity-constrained, or technically updated while a customer-specific process has stopped working.

Why this matters to a South African organisation

South African teams often operate with tight specialist capacity, rand-sensitive budgets and business processes that cannot be paused while a replacement is sourced. Localisation, regional cloud capacity and long procurement lead times can narrow the recovery options. The practical response is to use the available test window before it becomes an emergency window.

The consequence belongs to the business process, not only the technology team. Finance month-end, customer transactions, data pipelines and ERP extensions all cross technical and operational ownership. A change should therefore be accepted only when the service owner and the business owner can see the same evidence.

The hidden exposure

Microsoft’s security round-up published on 27 August 2026 states that Purview auto-labelling now processes up to 500,000 SharePoint and OneDrive files per day, up from 100,000. The Microsoft Learn documentation, last updated on 13 August 2026, states a maximum of 100,000 files per day in five places, including the guidance that tells administrators to use that figure when planning a policy.

Normal operation is weak evidence. It proves only that yesterday’s combination of platform, configuration and workload completed. It does not prove that the next capacity allocation, lifecycle enforcement or major release will preserve the same result. An owner needs an inventory, a representative test and a dated decision.

Decision path

This article does not adjudicate between the two figures, and it is worth being explicit about why. Both pages are Microsoft’s, the documentation was updated two weeks before the blog post rather than years before it, and nothing consulted for this article states which figure applies to which tenant or from what date. What can be stated is the shape of the problem: the older number is the one giving instructions. The documentation does not merely mention 100,000, it tells an administrator to plan against it, which makes the discrepancy operational rather than cosmetic. Whether the gap changes a decision depends on the size of the estate, and the arithmetic is Braintree’s rather than Microsoft’s: a backlog of one million files takes ten working days to label at 100,000 a day and two at 500,000. That is the difference between a scheduled project with a change window and an afternoon’s work, and it is exactly the sort of difference that determines whether a labelling programme gets sequenced before a Copilot rollout or after it. The safe course is neither to trust the blog nor to trust the documentation, but to read the number the tenant itself reports.

Record the alternatives that were rejected and why. That prevents the next reviewer from reopening the entire question without context. Where the preferred path cannot be completed inside seven days, approve a time-bound exception with a responsible owner, expiry date and compensating control.

Technical test plan

The reading that settles it is inside the tenant. In the Microsoft Purview portal, open the main Auto-labelling page: Microsoft’s own documentation states that the total daily files labelled across all policies is displayed at the top of that page, and that this is the number to use when planning a new policy or troubleshooting whether the tenant is approaching its labelling limit. Read it on a day when policies are actively running rather than on a quiet weekend, because a total well below any limit tells you nothing about the ceiling. Per-policy labelling progress is available alongside it, showing the files still to be labelled, the files affected over the last seven days and the total affected, which is the figure that lets you project how long a backlog will take at the rate the tenant is actually achieving. Two adjacent limits are worth carrying into the same planning conversation, because throughput is rarely the only constraint that bites. Microsoft’s documentation lists a limit of 100 auto-labelling policies and 100 locations per policy, and a simulation scan limit of 4,000,000 items. Where more than 100 SharePoint sites need to be in scope, Microsoft directs administrators to associate a SharePoint adaptive scope with the policy using the SharePointAdaptiveScopes parameter on New-AutoSensitivityLabelPolicy, and is explicit that this does not increase the portal limit but replaces static site enumeration with dynamic adaptive-scope membership. If a rollout stalled, it is worth confirming which of these limits it actually stalled against before concluding that throughput was the problem.

Use production-representative conditions without exposing production data unnecessarily. Capture the starting configuration, exact version, time of test and expected result. A pass requires evidence from the real workflow, not only a successful login or an unchanged dashboard.

Primary owner

Primary owner: Whoever owns Microsoft Purview and the sensitivity labelling programme, usually the compliance or information protection lead, with the Microsoft 365 administrator who runs the auto-labelling policies.

The named owner coordinates platform, application, commercial and business-process decisions. Contributors may perform the work, but accountability cannot be distributed across a meeting invite. The owner closes the test, exception and evidence record.

Action within seven days

Action within seven days: Open the main Auto-labelling page in the Purview portal and read the total daily files labelled across all policies, which is displayed at the top of the page. That figure is your tenant, measured today, and it is the number to plan against rather than either published figure. If a labelling rollout was deferred or descoped because the throughput would not carry it, put the assumption back on the table and re-test it against what the page now reports.

Start with the highest-consequence workload. Assign the people, date and pass criteria before the test begins. If the first test fails, record the failure as evidence and open remediation with a deadline rather than hiding it behind a general project status.

Evidence to retain

Evidence to retain: A dated screenshot or export of the main Auto-labelling page showing the total daily files labelled across all policies, together with the labelling progress figures for each active policy. Where a rollout decision was previously made on throughput grounds, retain the original design note alongside the new reading so the change in the constraint is documented rather than assumed.

Store the evidence with the platform or change record. Include source exports and machine-readable results where possible. The next reviewer should be able to reproduce the conclusion without rebuilding it from email, chat or memory.

Frequently asked questions

Which number is correct for our tenant?

This article does not say, because no consulted source states it. The number to act on is the one your own tenant reports at the top of the main Auto-labelling page in the Purview portal, which Microsoft’s documentation identifies as the figure to use when planning.

Is the documentation simply out of date?

That is a reasonable reading and it is Braintree’s, not Microsoft’s. What is verifiable is that the documentation page was last updated on 13 August 2026 and the blog post published on 27 August 2026, and that the two carry different figures.

Why does auto-labelling throughput matter for Copilot?

Microsoft makes the connection itself, presenting the change under the heading of speeding up Microsoft Copilot readiness. Sensitivity labels carry the encryption and data loss prevention controls that govern what an assistant can surface, so labelling coverage is a gate in front of a Copilot rollout rather than a parallel workstream.

How long would our backlog take?

At the documented 100,000 files a day, one million files is ten working days. At the figure in the blog post it is two. That arithmetic is ours, on Microsoft’s own two numbers, and the honest input is the rate your tenant is currently achieving rather than either published ceiling.

Are there other limits we should check at the same time?

Yes. Microsoft documents a limit of 100 auto-labelling policies, 100 locations per policy and a 4,000,000-item simulation scan limit. Where more than 100 SharePoint sites are needed, Microsoft directs you to a SharePoint adaptive scope, which replaces static site enumeration rather than raising the portal limit.

The Braintree view

Microsoft’s announcement supplies the platform fact. The customer control begins after that fact: identify the exposed process, name the owner, test the real dependency and retain a decision that can survive audit or staff turnover. Braintree can help structure the inventory, build the representative test and translate the result into a controlled implementation plan.

Use the seven-day action as the entry point. Do not wait for a renewal, support refusal or enforced update to reveal work that can be measured now.

Primary Microsoft sources

AI-use disclosure: AI supported research and drafting. Every factual claim was checked against the Microsoft sources listed here.

Related Posts

Microsoft Entra Tenant Governance brings multiple Microsoft tenants...
Microsoft's lifecycle table lists the Azure AI Document...

The cost of delay is rising as AI...