logo
search
Data Protection Issues

How to Remove a Microsoft 365 Group Sensitivity Label with PowerShell

Elise WilliamsElise Williams Sep 30, 2026 869 views

Question details

The user needs to remove an existing sensitivity label from a Microsoft 365 Unified Group using PowerShell, but encounters an error when trying to clear it.

How to Remove a Microsoft 365 Group Sensitivity Label with PowerShell
Product
Microsoft 365 / PowerShell
Device & OS
not provided
Scenario
An administrator is managing Microsoft 365 Group configurations and attempting to clear data protection labels via command line.
Observed behavior
The Set-UnifiedGroup cmdlet fails and throws an error when the SensitivityLabelId is set to "None" or an empty string, as the parameter cannot convert these strings into a valid GUID.
Before you start

Ensure you have the Exchange Online PowerShell module installed, and that you are connected to your tenant with an account holding Exchange Administrator or Global Administrator privileges.

Solution 1Recommended

Use the PowerShell $null Variable to Clear the Label

Pass the native PowerShell null variable to the Set-UnifiedGroup cmdlet to bypass the strict GUID validation and successfully clear the sensitivity label.

The SensitivityLabelId parameter on the Set-UnifiedGroup cmdlet is strictly typed. It expects either a valid Global Unique Identifier (GUID) pointing to an existing label, or a true null value. When you provide text like "None" or an empty string (""), PowerShell attempts to convert that text into a GUID, which fails and causes a syntax error. Passing $null explicitly tells the system to empty the property.

1
Connect to Exchange Online

Open PowerShell as an administrator and execute 'Connect-ExchangeOnline' to authenticate with your Microsoft 365 tenant.

2
Define the target group

Identify the Microsoft 365 Group you want to modify. You can store its identity (such as the email address) in a variable by running: $Group = "yourgroup@domain.com"

3
Execute the Set-UnifiedGroup command

Run the following command to remove the label: Set-UnifiedGroup -Identity $Group -SensitivityLabelId $null

Use the PowerShell $null Variable to Clear the Label
Verification: To verify the label has been removed, run 'Get-UnifiedGroup -Identity $Group | Format-List SensitivityLabelId' and ensure the output is blank.
Free Microsoft Office alternative

Looking for a Simpler Way to Manage Documents? Try WPS Office

While Microsoft 365 offers advanced administrative controls via PowerShell, managing it can sometimes be complex and time-consuming. If you are looking for a lightweight, straightforward, and highly compatible office suite for daily document creation and sharing, WPS Office is an excellent free alternative.

  1. 1. Download the software: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Install WPS Office: Run the downloaded setup file and follow the simple on-screen prompts to complete the installation.
  3. 3. Start creating immediately: Open WPS Office and start editing your documents, spreadsheets, and presentations with full Microsoft format compatibility.
Free to use with a familiar, intuitive user interface that requires no learning curve.Fully compatible with Microsoft Office formats, ensuring seamless sharing of Word, Excel, and PowerPoint files.Lightweight installation with blazing-fast launch speeds.Built-in robust PDF editing, conversion, and signature tools.Ideal for users who want straightforward document management without complex admin configurations.
microsoft office alternative - wps office

Frequently Asked Questions

Why do I get an error when setting SensitivityLabelId to an empty string?

The SensitivityLabelId parameter strictly requires a valid Global Unique Identifier (GUID) format. An empty string ("") is treated as text, which fails the system's GUID validation checks. Only a valid GUID or a $null object is accepted.

Can I remove sensitivity labels from multiple Microsoft 365 groups at once?

Yes. You can use the Get-UnifiedGroup cmdlet to retrieve a list of groups based on your criteria, and then pipe those results into a Foreach-Object loop that runs the Set-UnifiedGroup command with the -SensitivityLabelId $null parameter.

Do I need special permissions to run the Set-UnifiedGroup cmdlet?

Yes, you must be assigned appropriate administrative roles within your Microsoft 365 tenant, such as the Exchange Administrator role or Global Administrator role, to modify Unified Group properties via PowerShell.