How to Remove Encryption from SharePoint Sensitivity-Labeled Files
Question details
The user needs to remove encryption or sensitivity labels from a file stored in SharePoint or OneDrive without using the Microsoft Information Protection client.
- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Managing document security and decrypting files using PowerShell cmdlets in a Microsoft 365 environment.
- Observed behavior
- The user wants to successfully execute a PowerShell cmdlet to unlabel and decrypt a specified SharePoint document.
Ensure you have the SharePoint Online Management Shell module installed and possess the necessary administrator permissions to execute cmdlets on your tenant's files.
Use the Unlock-SPOSensitivityLabelEncryptedFile Cmdlet
Run this PowerShell cmdlet to remove encryption or sensitivity labels from your SharePoint or OneDrive documents.
This method does not require the Microsoft Information Protection (MIP) client. It is effective for both encrypted files and files that are labeled but not encrypted.
Launch PowerShell on your computer as an Administrator.
Ensure the SharePoint Online Management Shell module is installed and connect to your SharePoint admin center.
Execute the following command, replacing the URL and justification with your specific details: Unlock-SPOSensitivityLabelEncryptedFile -FileUrl "https://contoso.com/sites/Marketing/Shared Documents/Doc1.docx" -JustificationText "Need to decrypt this file"
Try WPS Office for Seamless Document Management
While managing advanced SharePoint encryption requires Microsoft's PowerShell tools, WPS Office offers a lightweight, completely free alternative for handling your everyday document needs with native compatibility for Microsoft Office formats.
- 1. Download WPS Office: Visit the official WPS website to download the free installer.
- 2. Install the Suite: Run the lightweight installer and follow the quick setup wizard.
- 3. Open your Documents: Instantly open and edit your existing Microsoft Office files without formatting loss.

Frequently Asked Questions
Does the Unlock-SPOSensitivityLabelEncryptedFile cmdlet require the MIP client?
No, it does not require the Microsoft Information Protection (MIP) client, but it does require you to have the SharePoint Online Management Shell module installed.
Will this cmdlet work on SharePoint files that are labeled but not encrypted?
Yes, testing confirms that the cmdlet can successfully remove the sensitivity label even if the file itself is not currently encrypted.
What information is needed to run the decryption command?
You will need the exact file URL within your SharePoint or OneDrive environment and a justification text string explaining why you are removing the encryption or label.




