How to Remove a Microsoft 365 Group Sensitivity Label with PowerShell
Question details
The user needs to remove an existing sensitivity label from a Microsoft 365 Unified Group using PowerShell, but encounters an error when trying to clear it.

- Product
- Microsoft 365 / PowerShell
- Device & OS
- not provided
- Scenario
- An administrator is managing Microsoft 365 Group configurations and attempting to clear data protection labels via command line.
- Observed behavior
- The Set-UnifiedGroup cmdlet fails and throws an error when the SensitivityLabelId is set to "None" or an empty string, as the parameter cannot convert these strings into a valid GUID.
Ensure you have the Exchange Online PowerShell module installed, and that you are connected to your tenant with an account holding Exchange Administrator or Global Administrator privileges.
Use the PowerShell $null Variable to Clear the Label
Pass the native PowerShell null variable to the Set-UnifiedGroup cmdlet to bypass the strict GUID validation and successfully clear the sensitivity label.
The SensitivityLabelId parameter on the Set-UnifiedGroup cmdlet is strictly typed. It expects either a valid Global Unique Identifier (GUID) pointing to an existing label, or a true null value. When you provide text like "None" or an empty string (""), PowerShell attempts to convert that text into a GUID, which fails and causes a syntax error. Passing $null explicitly tells the system to empty the property.
Open PowerShell as an administrator and execute 'Connect-ExchangeOnline' to authenticate with your Microsoft 365 tenant.
Identify the Microsoft 365 Group you want to modify. You can store its identity (such as the email address) in a variable by running: $Group = "yourgroup@domain.com"
Run the following command to remove the label: Set-UnifiedGroup -Identity $Group -SensitivityLabelId $null

Looking for a Simpler Way to Manage Documents? Try WPS Office
While Microsoft 365 offers advanced administrative controls via PowerShell, managing it can sometimes be complex and time-consuming. If you are looking for a lightweight, straightforward, and highly compatible office suite for daily document creation and sharing, WPS Office is an excellent free alternative.
- 1. Download the software: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install WPS Office: Run the downloaded setup file and follow the simple on-screen prompts to complete the installation.
- 3. Start creating immediately: Open WPS Office and start editing your documents, spreadsheets, and presentations with full Microsoft format compatibility.

Frequently Asked Questions
Why do I get an error when setting SensitivityLabelId to an empty string?
The SensitivityLabelId parameter strictly requires a valid Global Unique Identifier (GUID) format. An empty string ("") is treated as text, which fails the system's GUID validation checks. Only a valid GUID or a $null object is accepted.
Can I remove sensitivity labels from multiple Microsoft 365 groups at once?
Yes. You can use the Get-UnifiedGroup cmdlet to retrieve a list of groups based on your criteria, and then pipe those results into a Foreach-Object loop that runs the Set-UnifiedGroup command with the -SensitivityLabelId $null parameter.
Do I need special permissions to run the Set-UnifiedGroup cmdlet?
Yes, you must be assigned appropriate administrative roles within your Microsoft 365 tenant, such as the Exchange Administrator role or Global Administrator role, to modify Unified Group properties via PowerShell.




