FAQs for Azure Information Protection (AIP) (2024)

  • Article

Note

Are you looking for Microsoft Purview Information Protection, formerly Microsoft Information Protection (MIP)?

The Azure Information Protection add-in is retired and replaced with labels that are built in to your Microsoft 365 apps and services. Learn more about the support status of other Azure Information Protection components.

The Microsoft Purview Information Protection client (without the add-in) is generally available.

Have a question about Azure Information Protection (AIP), or about the Azure Rights Management service (Azure RMS)?

See if it's answered below or on the subsequent, more specific, FAQ pages.

What's the difference between Azure Information Protection and Microsoft Purview Information Protection?

Unlike Azure Information Protection, Microsoft Purview Information Protection isn't a subscription or product that you can buy. Instead, it's a framework for products and integrated capabilities that help you protect your organization's sensitive information.

Microsoft Purview Information Protection products include:

  • Azure Information Protection
  • Microsoft 365 Information Protection, such as Microsoft 365 DLP
  • Windows Information Protection
  • Microsoft Defender for Cloud Apps

Microsoft Purview Information Protection capabilities include:

  • Unified label management
  • End-user labeling experiences built into Office apps
  • The ability for Windows to understand unified labels and apply protection to data
  • The Microsoft Information Protection SDK
  • Functionality in Adobe Acrobat Reader to view labeled and protected PDFs

For more information, see Information protection capabilities to help protect your sensitive data.

What's the difference between Azure Information Protection and Azure Rights Management?

Azure Information Protection (AIP) provides classification, labeling, and protection for an organization's documents and emails.

Content is protected using the Azure Rights Management service, which is now a component of AIP.

For more information, see How AIP protects your data and What is Azure Rights Management?.

What subscription do I need for Azure Information Protection and what features are included?

To understand more about AIP subscriptions, see:

  • Modern Work Plan Comparison (PDF download)

Do you need to be a global admin to configure Azure Information Protection, or can I delegate to other administrators?

Global administrators for a Microsoft 365 tenant or Microsoft Entra tenant can obviously run all administrative tasks for Azure Information Protection.

However, if you want to assign administrative permissions to other users, do so using the following roles:

  • Azure Information Protection administrator
  • Compliance administrator or Compliance data administrator
  • Security administrator
  • Azure Rights Management Global Administrator and Connector Administrator

Additionally, note the following when managing administrative tasks and roles:

IssueDetails
Supported account typesMicrosoft accounts are not supported for delegated administration of Azure Information Protection, even if these accounts are assigned to one of the administrative roles listed.
Onboarding controlsIf you have configured onboarding controls, this configuration does not affect the ability to administer Azure Information Protection, except the RMS connector.

For example, if you have configured onboarding controls so that the ability to protect content is restricted to the IT department group, the account used to install and configure the RMS connector must be a member of that group.

Removing protectionAdministrators cannot automatically remove protection from documents or emails that were protected by Azure Information Protection.

Only users who are assigned as super users can remove protection, and only when the super user feature is enabled.

Any user with administrative permissions to Azure Information Protection can enable the super user feature, and assign users as super users, including their own account.

These actions are recorded in an administrator log.

For more information, see the security best practices section in Configuring super users for Azure Information Protection and discovery services or data recovery.

Tip: If your content is stored in SharePoint or OneDrive, admins can run the Unlock-SensitivityLabelEncryptedFile cmdlet to remove both the sensitivity label and the encryption. For more information, see the Microsoft 365 documentation.

Migrating to the unified labeling storeIf you are migrating your Azure Information Protection labels to the unified labeling store, be sure to read the following section from the label migration documentation:
Administrative roles that support the unified labeling platform.

Azure Information Protection administrator

This Microsoft Entra administrator role lets an administrator configure Azure Information Protection but not other services.

Administrators with this role can:

  • Activate and deactivate the Azure Rights Management protection service
  • Configure protection settings and labels
  • Configure the Azure Information Protection policy
  • Run all the PowerShell cmdlets for the Azure Information Protection client and from the AIPService module

To assign a user to this administrative role, see Assign a user to administrator roles in Microsoft Entra ID.

Compliance administrator or Compliance data administrator

These Microsoft Entra administrator roles enable administrators to:

  • Configure Azure Information Protection, including activating and deactivating the Azure Rights Management protection service
  • Configure protection settings and labels
  • Configure the Azure Information Protection policy
  • Run all the PowerShell cmdlets for the Azure Information Protection client and from the AIPService module.

To assign a user to this administrative role, see Assign a user to administrator roles in Microsoft Entra ID.

To see what other permissions a user with these roles have, see the Available roles section from the Microsoft Entra documentation.

Note

These roles don't support tracking and revoking documents for users.

Security administrator

This Microsoft Entra administrator role enables administrators to configure Azure Information Protection in the Azure portal and some aspects of other Azure services.

Administrators with this role cannot run any of the PowerShell cmdlets from the AIPService module, or track and revoke documents for users.

To assign a user to this administrative role, see Assign a user to administrator roles in Microsoft Entra ID.

To see what other permissions a user with this role has, see the Available roles section from the Microsoft Entra documentation.

Azure Rights Management Global Administrator and Connector Administrator

The Global Administrator role enables users to run all PowerShell cmdlets from the AIPService module without making them a global administrator for other cloud services.

The Connector Administrator role enables users to run only the Rights Management (RMS) connector.

These administrative roles don't grant permissions to management consoles. The Connector Administrator role also does not support tracking and revoking documents for users.

To assign either of these administrative roles, use the AIPService PowerShell cmdlet, Add-AipServiceRoleBasedAdministrator.

Does Azure Information Protection support on-premises and hybrid scenarios?

Yes. Although Azure Information Protection is a cloud-based solution, it can classify, label, and protect documents and emails that are stored on-premises, as well as in the cloud.

If you have Exchange Server, SharePoint Server, and Windows file servers, use one or both of the following methods:

  • Deploy the Rights Management connector so that these on-premises servers can use the Azure Rights Management service to protect your emails and documents
  • Synchronize and federate your Active Directory domain controllers with Microsoft Entra ID for a more seamless authentication experience for users. For example, use Microsoft Entra Connect.

The Azure Rights Management service automatically generates and manages XrML certificates as required, so it doesn't use an on-premises PKI.

For more information about how Azure Rights Management uses certificates, see the Walkthrough of how Azure RMS works: First use, content protection, content consumption.

What types of data can Azure Information Protection classify and protect?

Azure Information Protection can classify and protect email messages and documents, whether they are located on-premises or in the cloud. These documents include Word documents, Excel spreadsheets, PowerPoint presentations, PDF documents, text-based files, and image files.

For more information, see the full list file types supported.

Note

Azure Information Protection cannot classify and protect structured data such as database files, calendar items, Yammer posts, Sway content, and OneNote notebooks.

Tip

Power BI supports classification by using sensitivity labels and can apply protection from those labels to data that is exported to the following file formats: .pdf, .xls, and .ppt. For more information, see Data protection in Power BI.

I see Azure Information Protection is listed as an available cloud app for conditional access—how does this work?

Yes, you can configure Microsoft Entra Conditional Access for Azure Information Protection.

When a user opens a document that is protected by Azure Information Protection, administrators can now block or grant access to users in their tenant, based on the standard conditional access controls. Requiring multi-factor authentication (MFA) is one of the most commonly requested conditions. Another one is that devices must be compliant with your Intune policies so that, for example, mobile devices meet your password requirements and a minimum operating system version, and computers must be domain-joined.

For more information, see Conditional Access policies and encrypted documents.

Additional information:

TopicDetails
Evaluation frequencyFor Windows computers, and the current preview release, the conditional access policies for Azure Information Protection are evaluated when the user environment is initialized (this process is also known as bootstrapping), and then every 30 days.

To fine-tune how often your conditional access policies get evaluated, configure the token lifetime.

Administrator accountsWe recommend that you do not add administrator accounts to your conditional access policies because these accounts will not be able to access the Azure Information Protection pane in the Azure portal.
MFA and B2B collaborationIf you use MFA in your conditional access policies for collaborating with other organizations (B2B), you must use Microsoft Entra B2B collaboration and create guest accounts for the users you want to share with in the other organization.
Terms of Use promptsWith the Microsoft Entra December 2018 preview release, you can now prompt users to accept a terms of use before they open a protected document for the first time.
Cloud appsIf you use many cloud apps for conditional access, you might not see Microsoft Information Protection Sync Service and Microsoft Rights Management Service displayed in the list to select.

In this case, use the search box at the top of the list. Start typing "Microsoft Information Protection Sync Service" and "Microsoft Rights Management Service" to filter the available apps. Providing you have a supported subscription; you'll then see these option and will be able to select them.

Note

The Azure Information Protection support for conditional access is currently in PREVIEW. The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.

Is Azure Information Protection suitable for my country?

Different countries have different requirements and regulations. To help you answer this question for your organization, see Suitability for different countries.

How can Azure Information Protection help with GDPR?

Note

If you’re interested in viewing or deleting personal data, please review Microsoft's guidance in the Microsoft Purview Compliance Manager and in the GDPR section of the Microsoft 365 Enterprise Compliance site. If you’re looking for general information about GDPR, see the GDPR section of the Service Trust portal.

Where can I find supporting information for Azure Information Protection—such as legal, compliance, and SLAs?

See Compliance and supporting information for Azure Information Protection.

How can I report a problem or send feedback for Azure Information Protection?

For technical support, use your standard support channels or contact Microsoft Support.

We also invite you to engage with our engineering team, on their Azure Information Protection Yammer site.

What do I do if my question isn't here?

First, review the frequently asked questions listed below, which are specific to classification and labeling, or specific to data protection. The Azure Rights Management service (Azure RMS) provides the data protection technology for Azure Information Protection. Azure RMS can be used with classification and labeling, or by itself.

  • FAQs for classification and labeling

  • FAQs for data protection

FAQs for Azure Information Protection (AIP) (2024)

FAQs

Is Azure Information Protection going away? ›

The Azure Information Protection add-in is retired and replaced with labels that are built in to your Microsoft 365 apps and services. Learn more about the support status of other Azure Information Protection components. The Microsoft Purview Information Protection client (without the add-in) is generally available.

What is the difference between AIP 1 and AIP 2? ›

There are two business AIP plans to choose from – Plan 1 and Plan 2. The difference between the two is that AIP Plan 2 has Automatic and Recommended Labelling.

What is the most suitable MS Azure Information Protection AIP label? ›

Question: What is the most suitable MS Azure Information Protection (AIP) label while sharing a presentation with project details with your manager? a. Use AIP (Azure Information Protection) label 'Confidential' and select appropriate permissions by opting for a suitable sub levelb.

What is the difference between Microsoft Information Protection and AIP? ›

Microsoft Information Protection (MIP) vs. AIP—are they the same? AIP is one of the building blocks of Microsoft Information Protection (MIP), extending the labeling and classification functions of the latter. AIP is more advanced with additional capabilities, making it more suitable for hybrid work environments.

Is AIP going away? ›

Azure Information Protection Unified Labeling Add-in for Office to officially retire on April 11, 2024.

What is the new name for Azure Information Protection? ›

Microsoft Azure Information Protection to Microsoft Purview Information Protection. Flexera will migrate all releases/mappings from the old product name “Azure Information Protection” to “Purview Information Protection”.

Why use AIP? ›

AIP ensures that only specific people can open documents even when these files are accidentally forwarded as buried attachments in email.

How does AIP encryption work? ›

Unlike traditional file encryption software, AIP allows you to restrict access to files by email account. This means no more pesky passwords to remember, and managing access is as simple as typing an email account.

What is AIP sensitivity? ›

Microsoft 365 Sensitivity Labels are a part of the Azure Information Protection (AIP) tool set. They are a data-protection solution from Microsoft that helps an organization classify and protect its sensitive files and emails.

What are the benefits of Azure AIP? ›

Azure Information Protection (AIP) provides the encryption service, Azure Rights Management, that's used by Microsoft Purview Information Protection and the following capabilities:
  • Sensitivity labels.
  • Microsoft Purview Information Protection client.
  • Microsoft Purview Information Protection scanner.
May 13, 2024

What is the difference between DLP and AIP in Azure? ›

The key difference between Microsoft DLP and AIP is the scope of the data that they protect. Microsoft DLP is designed to protect data stored on-premises and in the cloud, while AIP is designed to protect data stored in the cloud.

What is the most secure AIP label? ›

Confidential is the most suitable MS Azure Information Protection (AIP) label while sharing a presentation with client names and future project details with your Manager.

What is the alternative to Microsoft AIP? ›

The best overall Microsoft Purview Information Protection alternative is Varonis Data Security Platform. Other similar apps like Microsoft Purview Information Protection are Egnyte, Cisco Duo, Acronis Cyber Protect Cloud, and Druva Data Resiliency Cloud.

How does AIP work? ›

The AIP diet aims to support the gut lining and ease autoimmune symptoms by having you avoid foods tied to inflammation. A small study suggested that the diet might improve quality of life in people with inflammatory bowel disease, but the researchers cautioned that larger and more rigorous studies are needed.

What is the main function of Azure Information Protection? ›

Azure Information Protection (AIP) is a subscription-based cloud product from Microsoft that assists organizations by applying labels to documents and emails to help with categorizing, discovering, classifying, and protecting those electronic records.

Is Azure Information Protection add in for Office retiring? ›

Microsoft is retiring the Azure Information Protection (AIP) Unified Labeling add-in for Office on April 11th, 2024. When this will happen: The AIP Add-in for Office will be permanently disabled in Office after May 1st, 2024.

Is Azure being discontinued? ›

In August 2021, we announced Azure Cloud Services (classic) will be retiring on 31 August 2024. As App Service Environment v1 and v2 run on Azure Cloud Services (classic), we will retire App Service Environment v1 and v2 on the same date. Before that date, you must migrate to App Service Environment v3.

What is the new name for Azure Threat protection? ›

Product Name Changes
Previous nameNew name
Azure Advanced Threat ProtectionMicrosoft Defender for Identity
Microsoft Defender Advanced Threat ProtectionMicrosoft Defender for Endpoint
Microsoft Threat ProtectionMicrosoft 365 Defender
Office 365 Advanced Threat ProtectionMicrosoft Defender for Office 365
56 more rows

What happened to Azure Information Protection Premium P1? ›

The AIP P1 standalone offer is no longer available for new customers as of January 2024. Microsoft Azure Information Protection (AIP) is part of Microsoft Purview Information Protection (MIP) and helps organizations discover, classify, protect, and govern sensitive information wherever it lives or travels.

Top Articles
Jak skontaktować się z Instagramem, aby uzyskać pomoc dotyczącą konta lub zgłosić inne konta
Wieże
Nybe Business Id
Fat Hog Prices Today
Uca Cheerleading Nationals 2023
Visitor Information | Medical Center
Is Csl Plasma Open On 4Th Of July
Computer Repair Tryon North Carolina
Calamity Hallowed Ore
Otr Cross Reference
อพาร์ทเมนต์ 2 ห้องนอนในเกาะโคเปนเฮเกน
Morocco Forum Tripadvisor
Gas Station Drive Thru Car Wash Near Me
Troy Athens Cheer Weebly
Dump Trucks in Netherlands for sale - used and new - TrucksNL
Labor Gigs On Craigslist
Conan Exiles Thrall Master Build: Best Attributes, Armor, Skills, More
Gon Deer Forum
Spectrum Field Tech Salary
The Exorcist: Believer (2023) Showtimes
Zoe Mintz Adam Duritz
Horn Rank
Il Speedtest Rcn Net
11526 Lake Ave Cleveland Oh 44102
UCLA Study Abroad | International Education Office
Sensual Massage Grand Rapids
Craigslist Northern Minnesota
2004 Honda Odyssey Firing Order
Craigslist Sf Garage Sales
Parent Management Training (PMT) Worksheet | HappierTHERAPY
3473372961
Colin Donnell Lpsg
Hair Love Salon Bradley Beach
Ny Post Front Page Cover Today
Best Workers Compensation Lawyer Hill & Moin
Games R Us Dallas
Instafeet Login
19 Best Seafood Restaurants in San Antonio - The Texas Tasty
craigslist | michigan
Kerry Cassidy Portal
Download Diablo 2 From Blizzard
Www.craigslist.com Waco
2132815089
How I Passed the AZ-900 Microsoft Azure Fundamentals Exam
Silicone Spray Advance Auto
Tìm x , y , z :a, \(\frac{x+z+1}{x}=\frac{z+x+2}{y}=\frac{x+y-3}{z}=\)\(\frac{1}{x+y+z}\)b, 10x = 6y và \(2x^2\)\(-\) \(...
Kidcheck Login
The Goshen News Obituary
Asisn Massage Near Me
San Pedro Sula To Miami Google Flights
Emmi-Sellers
Pauline Frommer's Paris 2007 (Pauline Frommer Guides) - SILO.PUB
Latest Posts
Article information

Author: Cheryll Lueilwitz

Last Updated:

Views: 5664

Rating: 4.3 / 5 (54 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Cheryll Lueilwitz

Birthday: 1997-12-23

Address: 4653 O'Kon Hill, Lake Juanstad, AR 65469

Phone: +494124489301

Job: Marketing Representative

Hobby: Reading, Ice skating, Foraging, BASE jumping, Hiking, Skateboarding, Kayaking

Introduction: My name is Cheryll Lueilwitz, I am a sparkling, clean, super, lucky, joyous, outstanding, lucky person who loves writing and wants to share my knowledge and understanding with you.