<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Azure-information-protection Archives - Erjen Rijnders</title>
	<atom:link href="https://erjenrijnders.nl/tag/azure-information-protection/feed/" rel="self" type="application/rss+xml" />
	<link>https://erjenrijnders.nl/tag/azure-information-protection/</link>
	<description>Microsoft Azure/EMS blog</description>
	<lastBuildDate>Thu, 04 Apr 2019 09:44:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>
	<item>
		<title>Microsoft Ignite day 5</title>
		<link>https://erjenrijnders.nl/2018/09/28/microsoft-ignite-day-5/</link>
					<comments>https://erjenrijnders.nl/2018/09/28/microsoft-ignite-day-5/#respond</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Fri, 28 Sep 2018 18:13:13 +0000</pubDate>
				<category><![CDATA[Ignite 2018]]></category>
		<category><![CDATA[Azure-information-protection]]></category>
		<category><![CDATA[Security and Compliance center]]></category>
		<category><![CDATA[BYOK]]></category>
		<category><![CDATA[HYOK]]></category>
		<category><![CDATA[Windows 10 Virtual Desktop]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=75852</guid>

					<description><![CDATA[<p>As you know by now (by reading my previous blog posts), I focus mostly on Information Protection and compliance from [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/28/microsoft-ignite-day-5/">Microsoft Ignite day 5</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As you know by now (by reading my previous blog posts), I focus mostly on Information Protection and compliance from a technical point of view and this blog post will cover a lot regarding that. Today, I wasn’t able to visit as many sessions as the last four days because I need a plane to catch in a few hours, but I still got a few interesting things to share.</p>
<h1>Index:</h1>
<ol>
<li><a href="#security-and-compliance-center">Security and Compliance center</a></li>
<li><a href="#service-encryption">Service Encryption</a></li>
<li><a href="#advanced-e-discovery">Advanced E-Discovery</a></li>
<li><a href="#windows-virtual-desktop">Windows Virtual Desktop, RDMI &amp; Windows 10 Multi-User</a></li>
</ol>
<h1><a id="security-and-compliance-center"></a>Security and Compliance center</h1>
<p>Microsoft covers a big part protecting us from malicious tools and attackers, but there is still a part that we must do. And I can tell you that it is the most important part, like activating MFA, encrypting sensitive data etc. This slides covers what Microsoft does and what you have to do.</p>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-75853" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection.png" alt="" width="683" height="385" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection.png 1657w, https://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection-300x169.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection-768x432.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection-1024x577.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/1-Microsoft-us-responsibilities-data-protection-600x338.png 600w" sizes="(max-width: 683px) 100vw, 683px" /></p>
<p>So about the part that we are responsible of, Microsoft provides us multiple tools. How do AIP and OME help with compliance? Check this slide.</p>
<p><img decoding="async" class="alignnone wp-image-75854" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4.png" alt="" width="550" height="317" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4.png 1628w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4-300x172.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4-768x442.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4-1024x589.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/Screenshot_4-600x345.png 600w" sizes="(max-width: 550px) 100vw, 550px" /></p>
<p>There are certain scenario’s that you don’t want that Microsoft manages your key. Some regulatory reasons might require you to manage your key so the security is end-to-end. BYOK might be sufficient since you can store your own key in Azure Key Vault. If that isn’t even good enough you have the HYOK where you store it on-premises. Keep in mind that this option is much less flexible. You only have access to your secured documents as long as you can reach the on-premises key for decryption. Here is an overview of licensing.</p>
<p><img decoding="async" class="alignnone wp-image-75858" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK.png" alt="" width="625" height="351" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK.png 1577w, https://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK-300x169.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK-768x431.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK-1024x575.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/SKUs-BYOK-HYOK-600x337.png 600w" sizes="(max-width: 625px) 100vw, 625px" /></p>
<p>Here is a great overview of BYOK. It makes clear that it is as flexible as the Microsoft-managed keys, but it does give you more overhead since you need to manage the key now.</p>
<p><img decoding="async" class="alignnone wp-image-75857" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology.png" alt="BYOK-technology" width="611" height="335" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology.png 1646w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology-300x165.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology-768x421.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology-1024x562.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-technology-600x329.png 600w" sizes="(max-width: 611px) 100vw, 611px" /></p>
<p>Some good insights when using BYOK.</p>
<p><img decoding="async" class="alignnone wp-image-75859" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points.png" alt="" width="595" height="319" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points.png 1563w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points-300x161.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points-768x412.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points-1024x549.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/BYOK-important-points-600x322.png 600w" sizes="(max-width: 595px) 100vw, 595px" /></p>
<h1><a id="service-encryption"></a>Service Encryption</h1>
<p>Some good news, if we use the Microsoft-managed keys or BYOK, we will have service encryption in Exchange Online, starting to rollout in January 2019 (already available in SharePoint). Once we create a Data Encryption Policy (DEP), It will encrypt our data at storage level. This is required if you want to meet compliance.</p>
<p><img decoding="async" class="alignnone wp-image-75860" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow.png" alt="" width="542" height="320" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow.png 1456w, https://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow-300x177.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow-768x453.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow-1024x604.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/EXchange-Online-Access-Flow-600x354.png 600w" sizes="(max-width: 542px) 100vw, 542px" /></p>
<p>&nbsp;</p>
<h1><a id="advanced-e-discovery"></a>Advanced E-Discovery</h1>
<p>With the advanced E-Discovery set in Office 365 by using the analytics, we can further minimize the data. It will deduplicate data for example and only present us with relevant data. We are also presented now with a much better E-Discovery dashboard. We see what kind of data the hold holds, but we are also able to communicate with the persons in a specific hold, make searches in it etc. Great improvement!</p>
<p><img decoding="async" class="alignnone wp-image-75861" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard.png" alt="legal-hold-dashboard" width="655" height="369" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard.png 1696w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard-300x169.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard-768x432.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard-1024x577.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-dashboard-600x338.png 600w" sizes="(max-width: 655px) 100vw, 655px" /></p>
<p>Now creating a Legal Hold is doable, but not that easy. But it will be! Here is a great overview of how it is now and how it will be very soon.</p>
<p><img decoding="async" class="alignnone wp-image-75862" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process.png" alt="" width="624" height="346" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process.png 1552w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process-300x166.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process-768x425.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process-1024x567.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/legal-hold-process-600x332.png 600w" sizes="(max-width: 624px) 100vw, 624px" /></p>
<p>So these are some great new features! For sure you will see a more in-depth bog when it’s available.</p>
<p>&nbsp;</p>
<h1><a id="windows-virtual-desktop"></a>Windows Virtual Desktop, RDMI &amp; Windows 10 Multi-User</h1>
<p>Now also a little bit of info about Windows Virtual Desktop, as I can imagine you want to see some updates about this as well. One of the bigger announcements is Windows 10 Multi-User within Windows Virtual Desktop, so you will connect to shared hardware. If you spin up a Windows Virtual Desktop, you can decide how many users you want to connect to that VM which makes it a lot cheaper. There will be a Windows Desktop Calculator soon which gives some recommendations of this, based on the chosen size.</p>
<p>Automatic scaling will be available as well. You can auto scale based on two methods: Breath Mode and Depth Mode. The Breath Mode needs reserved instances so turning off a Virtual Desktop doesn’t help you. However, this can still be cheaper, that’s something you need to calculate. The Depth Mode is based on activity. If no users are logged in anymore in a Virtual Desktop, it will automatically turn off the VM and it will save you money. On the other hand if it’s too busy, it will spin up some new VM’s.</p>
<p>Windows Virtual Desktop will be available through the Azure Marketplace.</p>
<p>&nbsp;</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/28/microsoft-ignite-day-5/">Microsoft Ignite day 5</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/09/28/microsoft-ignite-day-5/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Microsoft Information Protection: Unified labeling!</title>
		<link>https://erjenrijnders.nl/2018/09/25/microsoft-information-protection-unified-labeling/</link>
					<comments>https://erjenrijnders.nl/2018/09/25/microsoft-information-protection-unified-labeling/#respond</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Tue, 25 Sep 2018 22:02:08 +0000</pubDate>
				<category><![CDATA[Azure Information Protection]]></category>
		<category><![CDATA[Ignite 2018]]></category>
		<category><![CDATA[Azure-information-protection]]></category>
		<category><![CDATA[aip]]></category>
		<category><![CDATA[microsoft-information-protection]]></category>
		<category><![CDATA[unified labeling]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[office information protection]]></category>
		<category><![CDATA[windows information protection]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=75742</guid>

					<description><![CDATA[<p>Unified labeling with Microsoft Information Protection Because this is such a great feature (within Microsoft Information Protection), I will dedicate a [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/25/microsoft-information-protection-unified-labeling/">Microsoft Information Protection: Unified labeling!</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><a id="unified-labeling"></a>Unified labeling with Microsoft Information Protection</h1>
<p>Because this is such a great feature (within Microsoft Information Protection), I will dedicate a seperate blogpost about this, instead of processing this in the <a href="https://erjenrijnders.nl/2018/09/25/microsoft-ignite-day-2/">Ignite Day 2</a> blogpost (which you should still read by the way for an overview of selected updates).</p>
<p>All the labeling and encryption technologies throughout the Microsoft stack (currently Windows Information Protection, Office Information Protection and Azure Information Protection), will be manageable from one interface: <a href="https://admin.microsoft.com" target="_blank" rel="noopener">https://admin.microsoft.com</a> and will be called Microsoft Information Protection. At the end of this year, we should have it all. But not only that, we will also have native labeling and encryption with all Microsoft Office apps! So also on Mac, Android and iOS. That’s very cool right? Notice that if you want this native encryption without installing the AIP client, you should use Microsoft Information Protection. Those labels are cross-application compatible. Microsoft will bring out some sort of migration possibility from AIP to WIP by the way.</p>
<h2>Index:</h2>
<ol>
<li><a href="#unified-labeling">Unified labeling</a></li>
<li><a href="#sensitivity-labels">Sensitivity Labels</a></li>
<li><a href="#retention-labels">Retention Labels</a></li>
<li><a href="#conclusion">Conclusion</a></li>
</ol>
<h1><a id="sensitivity-labels"></a>Sensitivity Labels</h1>
<p>Microsoft is now using one unified way for labeling: Sensitivity label. This label is customizable as you are used to with Azure Information Protection. So let’s try it out how this new unified way of labeling works.</p>
<p>Go to <a href="https://protection.microsoft.com" target="_blank" rel="noopener">https://protection.microsoft.com</a> &gt; Classification &gt; Labels &gt; Sensitivity &gt; Create a label.</p>
<p><img decoding="async" class="alignnone wp-image-75744" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels.png" alt="microsoft-information-protection-sensitivity-labels" width="504" height="370" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels.png 1349w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-300x220.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-768x564.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-1024x751.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-600x440.png 600w" sizes="(max-width: 504px) 100vw, 504px" /></p>
<p>Name your label.</p>
<p><img decoding="async" class="alignnone wp-image-75745" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1.png" alt="microsoft-information-protection-sensitivity-labels-page-1" width="581" height="296" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1.png 2348w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1-300x153.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1-768x391.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1-1024x521.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-1-600x305.png 600w" sizes="(max-width: 581px) 100vw, 581px" /></p>
<p>Here you have basically the same options as with Azure Information Protection in the Azure Portal.</p>
<p><img decoding="async" class="alignnone wp-image-75746" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2.png" alt="microsoft-information-protection-sensitivity-labels-page-2" width="625" height="318" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2.png 2369w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2-300x153.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2-768x391.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2-1024x521.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-2-600x305.png 600w" sizes="(max-width: 625px) 100vw, 625px" /></p>
<p>Here starts a great unified feature, enable Windows Information Protection!</p>
<p><img decoding="async" class="alignnone wp-image-75747" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3.png" alt="microsoft-information-protection-sensitivity-labels-page-3" width="589" height="265" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3.png 2735w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3-300x135.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3-768x345.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3-1024x461.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-3-600x270.png 600w" sizes="(max-width: 589px) 100vw, 589px" /></p>
<p>Again, a great unified feature, enable Office Information Protection.</p>
<p><img decoding="async" class="alignnone wp-image-75749" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5.png" alt="microsoft-information-protection-sensitivity-labels-page-4" width="648" height="362" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5.png 2353w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5-300x167.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5-768x429.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5-1024x571.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-5-600x335.png 600w" sizes="(max-width: 648px) 100vw, 648px" /></p>
<p>Last but not least, enable auto labeling as you are used to configure with AIP in the Azure Portal.</p>
<p><img decoding="async" class="alignnone wp-image-75750" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6.png" alt="microsoft-information-protection-sensitivity-labels-page-5" width="673" height="366" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6.png 2373w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6-300x163.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6-768x418.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6-1024x557.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-6-600x326.png 600w" sizes="(max-width: 673px) 100vw, 673px" /></p>
<p>After this, you should publish your label.</p>
<p><img decoding="async" class="alignnone wp-image-75751" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7.png" alt="microsoft-information-protection-sensitivity-labels-page-6" width="349" height="418" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7.png 1192w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7-250x300.png 250w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7-768x921.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7-854x1024.png 854w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-sensitivity-labels-page-7-600x719.png 600w" sizes="(max-width: 349px) 100vw, 349px" /></p>
<p>To me, this is really a step up. Now we still have some highly requested items, like add dynamic permissions in WIP but that will come for sure (since it&#8217;s already available in Office Message Encryption).</p>
<p>One caveat for now, this label is not synced yet to Exchange Online so you cannot use it with Exchange rules. Hopefully they will solve this very soon since they only made these new functionalities available yesterday.</p>
<p>&nbsp;</p>
<h1><a id="retention-labels"></a>Retention labels</h1>
<p>But that is not all, we also have retention labels now which have some very cool features. Let&#8217;s check it out. Click on retention labels and click Create a label. You will be presented with some groundbreaking features: Trigger a disposition review!</p>
<p><img decoding="async" class="alignnone wp-image-75753" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1.png" alt="microsoft-information-protection-retention-labels" width="546" height="382" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1.png 1785w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1-300x210.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1-768x538.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1-1024x717.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-1-600x420.png 600w" sizes="(max-width: 546px) 100vw, 546px" /></p>
<p>If you select this option, you give the choice to an admin, he or she can decide if that specific document must be deleted or kept. Like if job interviews are still open, you might want to hold the CV&#8217;s a little longer. Really great feature. But wait, there is even a more great feature! We can delete content based on an event. That is exactly what we need.</p>
<p><img decoding="async" class="alignnone wp-image-75754" src="http://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2.png" alt="microsoft-information-protection-retention-labels-page-1" width="582" height="371" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2.png 1971w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2-300x191.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2-768x489.png 768w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2-1024x652.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2018/09/microsoft-information-protection-retention-labels-page-2-600x382.png 600w" sizes="(max-width: 582px) 100vw, 582px" /></p>
<p>You can customize your events by going to &#8220;Data Governance &gt; Events&#8221;. For extensive documentation, I recommend you to should the <a href="https://docs.microsoft.com/en-us/office365/securitycompliance/event-driven-retention?redirectSourcePath=%252fen-us%252farticle%252fOverview-of-event-driven-retention-dd851332-747b-45b9-82de-e3cd7d01c8a7" target="_blank" rel="noopener">Microsoft Docs</a> which is a really good document.</p>
<h1><a id="conclusion"></a>Conclusion</h1>
<p>Microsoft&#8217;s products are getting better and better. The tight integration is getting phenomenal. In this document we have seen the possibilities of Sensitivity Labels and Retention Labels. Both serve different purposes which you should check out for sure, especially regarding sensitive content.</p>
<p>The post <a href="https://erjenrijnders.nl/2018/09/25/microsoft-information-protection-unified-labeling/">Microsoft Information Protection: Unified labeling!</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/09/25/microsoft-information-protection-unified-labeling/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Protect PDF-files with Azure Information Protection!</title>
		<link>https://erjenrijnders.nl/2018/08/29/protect-pdf-files-with-azure-information-protection/</link>
					<comments>https://erjenrijnders.nl/2018/08/29/protect-pdf-files-with-azure-information-protection/#comments</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Wed, 29 Aug 2018 10:00:16 +0000</pubDate>
				<category><![CDATA[Azure Information Protection]]></category>
		<category><![CDATA[aip]]></category>
		<category><![CDATA[Azure-information-protection]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=73883</guid>

					<description><![CDATA[<p>Exciting news! it&#8217;s now possible (since 2018/08/28) to encrypt PDF-files with Azure Information Protection, without the need for file encapsulation, [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/08/29/protect-pdf-files-with-azure-information-protection/">Protect PDF-files with Azure Information Protection!</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Exciting news! it&#8217;s now possible (since 2018/08/28) to encrypt PDF-files with Azure Information Protection, without the need for file encapsulation, so you will get native protection. PDF-files don&#8217;t turn into .ppdf files anymore, just .pdf files.</p>
<p>All PDF-readers that use ISO standard will understand the encrypted PDF-file, however, it&#8217;s not possible yet to open the PDF with those readers. It&#8217;s only possible to open an encrypted PDF-file with the Azure Information Protection Viewer. I expect that this will be possible in the near future.<br />
Encrypting the PDF-file directly from the Adobe Reader will also be possible soon, Microsoft is currently working with Adobe to get this feature completed.</p>
<p>To activate the encryption, right click a PDF-file and click &#8220;Classify and protect&#8221;.</p>
<p><img decoding="async" class="alignnone size-full wp-image-73870" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/azure-information-protection-classify-and-protect.png" alt="" width="274" height="93" /></p>
<p>Choose your label on which encryption is enabled.</p>
<p><img decoding="async" class="alignnone wp-image-73886" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-encrypt.jpg" alt="" width="666" height="498" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-encrypt.jpg 912w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-encrypt-300x224.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-encrypt-768x574.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-encrypt-600x449.jpg 600w" sizes="(max-width: 666px) 100vw, 666px" /></p>
<p><img decoding="async" class="alignnone wp-image-73887" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-work-finished.jpg" alt="" width="485" height="365" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-work-finished.jpg 912w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-work-finished-300x226.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-work-finished-768x578.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-work-finished-600x451.jpg 600w" sizes="(max-width: 485px) 100vw, 485px" /></p>
<p>As you can see we still have the .pdf file extension after protecting.</p>
<p><img decoding="async" class="alignnone size-full wp-image-73888" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-still-pdf.jpg" alt="" width="83" height="22" /></p>
<p>Now opening the protected file with Adobe gives you this message.</p>
<p><img decoding="async" class="alignnone wp-image-73890" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-adobe.jpg" alt="" width="498" height="479" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-adobe.jpg 1009w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-adobe-300x288.jpg 300w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-adobe-768x738.jpg 768w, https://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-adobe-600x577.jpg 600w" sizes="(max-width: 498px) 100vw, 498px" /></p>
<p>In my opinion this is user friendly, but still eagerly waiting for the possibility to open protected PDF-files integrated in Adobe.</p>
<p>&nbsp;</p>
<p>To get the new features, you need to update your Azure Information Protection client to version 1.36.18.0 (currently in preview).</p>
<p>&nbsp;</p>
<h2>More great features coming with this version!</h2>
<p>This version added more sensitive information types:</p>
<p>EU Phone Number<br />
EU Mobile Phone Number<br />
EU Passport Number<br />
EU Driver&#8217;s License Number<br />
EU GPS Coordinates<br />
EU National Identification Number<br />
EU Social Security Number (SSN) or Equivalent ID<br />
EU Tax Identification Number (TIN)<br />
Thai Population Identification Code<br />
Turkish National Identification number<br />
Japanese Residence Card Number</p>
<p>The &#8220;Send Us Feedback&#8221; button is now replaced with &#8220;Report an issue&#8221; and is fully customizable, even the email address used behind that button doesn&#8217;t have to be Microsoft anymore. It can be a company email now.</p>
<p>The post <a href="https://erjenrijnders.nl/2018/08/29/protect-pdf-files-with-azure-information-protection/">Protect PDF-files with Azure Information Protection!</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/08/29/protect-pdf-files-with-azure-information-protection/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title>GDPR: how to automatically delete sensitive content</title>
		<link>https://erjenrijnders.nl/2018/08/21/gdpr-how-to-automatically-delete-sensitive-content/</link>
					<comments>https://erjenrijnders.nl/2018/08/21/gdpr-how-to-automatically-delete-sensitive-content/#comments</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Tue, 21 Aug 2018 17:41:31 +0000</pubDate>
				<category><![CDATA[Azure Information Protection]]></category>
		<category><![CDATA[Office 365]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud App Security]]></category>
		<category><![CDATA[Azure-information-protection]]></category>
		<category><![CDATA[aip]]></category>
		<category><![CDATA[azure]]></category>
		<category><![CDATA[office 365]]></category>
		<category><![CDATA[cloud app security]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=73835</guid>

					<description><![CDATA[<p>These days, I get a lot of questions from customers how to make sure that for example a resumé is [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/08/21/gdpr-how-to-automatically-delete-sensitive-content/">GDPR: how to automatically delete sensitive content</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>These days, I get a lot of questions from customers how to make sure that for example a resumé is automatically deleted after a predefined timeframe. I receive this question a lot because of the GDPR legislation. To accomplish this, you have multiple options. Keep in mind that this blog is not covering in-depth knowledge of the products itself, nor how to configure regex (let me know if you’re interested how to do this in these scenario’s, I might make a blogpost about it), but rather giving you a good idea which tool you should use in which scenario.</p>
<p>So, in case when you have an applicant on a job offer, the person sends you its resumé somehow (by e-mail, sharing through OneDrive etc.) and you download it to the company share (SharePoint Online or locally). In all scenario’s you need to make sure that, whatever way the resumé is received, you catch it and set an expiration date.</p>
<p>Note: Every product to accomplish this have its caveats. You need to make sure that you align the job applications with the way you handle your sensitive data.</p>
<p>Depending on the license you have, you can use these products for achieving above:</p>
<ol>
<li style="list-style-type: none;">
<ol>
<li><a href="#azure-information-protection"><strong>Azure Information Protection;</strong></a></li>
<li><a href="#cloud-app-security"><strong>Cloud App Security;</strong></a></li>
<li><a href="#aip-scanner"><strong>AIP Scanner;</strong></a></li>
<li><a href="#data-loss-prevention"><strong>Data Loss Prevention;</strong></a></li>
<li><a href="#exchange-online-retention-policies"><strong>Exchange Online Retention Policies</strong></a></li>
<li><a href="#conclusion"><strong>Conclusion</strong></a></li>
</ol>
</li>
</ol>
<p>Let’s see how these products can achieve this.</p>
<h2><a id="azure-information-protection"></a>1. Azure Information Protection</h2>
<p>First you need to configure a label with content expiration. Go to the “Azure Portal &gt; Azure Information Protection &gt; Labels &gt; Protect”. Under “Content expiration”, set the content to expire “By days” or “By date”. When the content expires, you can no longer decrypt the content which makes it unreadable:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/azure-information-protection-content-expiration.png" alt="" width="903" height="510" /></h2>
<p>Now classify the document You can easily do this by right clicking a PDF or Word document and click “Classify and protect”:</p>
<p><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-classify-and-protect.png" alt="" width="274" height="93" /></p>
<p>Click the label you configured with “Content expiration”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/azure-information-protection-sensititvy.png" alt="" width="905" height="169" /></h2>
<p>If you view the custom properties of the document, you can see it’s now classified as “Confidential”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/azure-information-protection-advanced-properties.png" alt="" width="1012" height="495" /></h2>
<p>In my opinion, the problem with this approach is the chance on forgetting classifying a document. So, if you choose Azure Information Protection for achieving this, make sure no documents get through without classification and give your users clear instructions.</p>
<p>Another way with Azure Information Protection is the automatic labeling function. You can do this, based on document content. With PDF-files however (and any filetype other than docx, pptx, xlsx), you can only achieve this with the AIP scanner (check point 3). To configure automatic labeling, take the same steps as before but also configure a condition and create a regex policy or fill in predefined keywords:</p>
<p><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/azure-information-protection-conditions-300x120.png" alt="" width="300" height="120" /></p>
<h2><a id="cloud-app-security">2. Cloud App Security</a></h2>
<p>Using Cloud App Security, you can automatically classify documents when they reside in a specific folder or when the document contains sensitive information. Personally, I would love the last one, but it’s currently not possible to scan PDF files with Cloud App Security so the first option is the only working option at the moment.</p>
<p>We will discuss both options however. First let’s see how it works when sensitive files are stored in a specific folder. Go to <a href="https://portal.cloudappsecurity.com/" target="_blank" rel="noopener">https://portal.cloudappsecurity.com/</a>, click “Control &gt; Policies &gt; Create policy &gt; File policy”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/cloud-app-security-create-policy.png" alt="" width="1324" height="501" /></h2>
<p>Select as condition “Parent folder” and select the folder:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/cloud-app-security-conditions.png" alt="" width="816" height="161" /></h2>
<p>Apply a classification label beneath “Microsoft OneDrive for Business” and “Microsoft SharePoint Online”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/cloud-app-security-rule.png" alt="" width="448" height="398" /></h2>
<p>Create the policy, now all content in that folder will have automatically the content expiration activated. Of course, you need to configure content expiration for the label set. See step 1 for more details.</p>
<p>Let’s see how automatic labeling with Cloud App Security works. Create a File policy again and scroll down till the “Inspection method” part. We skip the conditions for now since we did that just before and it’s straight forward as well.</p>
<p>Select “Data Classification Service &gt; Match if Any of the following occur &gt; Choose inspection type… &gt; Select a sensitive information type”:</p>
<p><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/cloud-app-security-apply-classification-label-300x300.png" alt="" width="300" height="300" /></p>
<p>Here you can select a sensitive information type, or you can add a custom information type. You need to know regular expressions, but it’s not too hard.</p>
<p>For adding a custom information type, click the + button on the right:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/cloud-app-security-custom-rule.png" alt="" width="1832" height="512" /></h2>
<p>Once added, click “Done” and navigate to the bottom. Now again select the classification label you want to apply for “Microsoft OneDrive for Business” and “Microsoft SharePoint Online”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/cloud-app-security-rule.png" alt="" width="431" height="383" /></h2>
<p>All matched files are now automatically classified with “Confidential” (make sure you configure the content expiration again in Azure Information Protection).</p>
<p>Remember, it’s not working yet with PDF-files but will be available in future versions.</p>
<h2><a id="aip-scanner">3. AIP Scanner</a></h2>
<p>This is more or less the same as step 2, only the tool is different and it’s possible to scan PDF files. You still need to know regular expressions (or you need to choose predefined templates like “Credit Card Number”). the scanner uses the Office 365 data loss prevention (DLP) service. For configuration of the filetypes in DLP, see point 4.</p>
<p>The actual configuration of the AIP scanner is not covered in this post, since there are already many great posts how to do this.</p>
<h2><a id="data-loss-prevention">4. Data Loss Prevention</a></h2>
<p>DLP has great potential for achieving this task, especially because you can connect with Exchange Online which means you can scan e-mail attachments and restrict or encrypt the content when a condition matches.</p>
<p>However, one big flaw is that DLP cannot scan PDF files (yet), same goes for Cloud App Security. They both use the same core functionality, but I expect this possibility the coming months. Till then, we cannot use this functionality for scanning PDF files.</p>
<p>To create a custom classification type to use within a DLP policy, go to “<a href="https://protection.office.com" target="_blank" rel="noopener">https://protection.office.com</a> &gt; Classifications &gt; Custom sensitive information types”:</p>
<p><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/data-loss-prevention-custom-policies-157x300.png" alt="" width="157" height="300" /></p>
<p>Now click “Create” and add a Regular expression:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/data-loss-prevention-regular-expressions.png" alt="" width="1237" height="758" /></h2>
<p>At this point, click “Finish” and add a DLP policy. Click on “Data loss prevention &gt; Policy &gt; Create a policy”. Walk through the steps, at the “Policy settings” tab click “Use advanced settings”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/data-loss-prevention-advanced-settings.png" alt="" width="1204" height="539" /></h2>
<p>Click “New rule” and within the “Conditions” tab, click “Content contains &gt; Sensitive info types”:</p>
<p><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/08/data-loss-prevention-conditions-300x264.png" alt="" width="300" height="264" /></p>
<p>Now select your just created custom policy. On the “Actions” tab, select “Block people from sharing and restrict access to shared content” and “Everyone. Only the content owner, the last modifier, and the site admin will continue to have access”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/data-loss-prevention-actions.png" alt="" width="964" height="332" /></h2>
<p>Fill in the other desired settings and save the policy.</p>
<h2><a id="exchange-online-retention-policies">5. Exchange Online retention policies</a></h2>
<p>With Exchange Online retention policies, you can achieve best of all worlds. You can just delete content matching a custom information type that you created with regex. So, it’s possible to apply this to Exchange, SharePoint and OneDrive!</p>
<p>Go to “<a href="https://protection.office.com" target="_blank" rel="noopener">https://protection.office.com</a> &gt; Data governance &gt; Retention &gt; Create”. Create a custom retention policy and add a “Sensitive info types”:</p>
<h2><img decoding="async" src="http://erjenrijnders.nl/wp-content/uploads/2018/04/exchange-online-retention-policy.png" alt="" width="900" height="815" /></h2>
<p>Make sure you delete the content after the period you define, from the data when it was labeled.</p>
<p>One caveat with this option is that you don’t have much conditions. You can only choose to which location you want to apply it (SharePoint Online, OneDrive or Exchange Online).</p>
<p><strong> </strong></p>
<p><strong><a id="conclusion">Conclusion</a></strong></p>
<p>As you figured out by now, it’s impossible to use one tool for scanning your complete environment (if you both use on-premises file server and cloud-based file servers). Also, scanning PDF-files is apparently hard and even impossible to scan Exchange Online PDF files with a tool like Azure Information Protection, Data Loss Prevention or Cloud App Security. Fortunately, it’s possible with retention policies.</p>
<p>In the scenario where you only use SharePoint, OneDrive and Exchange Online and you also want to scan PDF-files, the best option would be using retention policies. Keep in mind that you do not have much options in conditions. In case you need more freedom in conditions and still need to scan PDF-files, you have to wait for this functionality to become available in AIP, DLP and MCAS.</p>
<p>You might have an on-premises file server as well, where you want to apply labels automatically, you need the AIP-scanner since it can scan PDF files.</p>
<p>If you have any questions, feel free to contact me or place a comment below.</p>
<p>The post <a href="https://erjenrijnders.nl/2018/08/21/gdpr-how-to-automatically-delete-sensitive-content/">GDPR: how to automatically delete sensitive content</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/08/21/gdpr-how-to-automatically-delete-sensitive-content/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>AIP label-based encryption</title>
		<link>https://erjenrijnders.nl/2018/07/03/aip-label-based-encryption/</link>
					<comments>https://erjenrijnders.nl/2018/07/03/aip-label-based-encryption/#respond</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Tue, 03 Jul 2018 19:12:04 +0000</pubDate>
				<category><![CDATA[Azure Information Protection]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure-information-protection]]></category>
		<category><![CDATA[aip]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=73792</guid>

					<description><![CDATA[<p>If you visited my session @Experts Live 2018, you saw the possibility to integrate Azure Information Protection with Office Message Encryption. [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2018/07/03/aip-label-based-encryption/">AIP label-based encryption</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you visited my session @Experts Live 2018, you saw the possibility to integrate Azure Information Protection with Office Message Encryption. Basically, this means that you can encrypt e-mails based on a chosen AIP label.</p>
<p>At first, this is officially not supported but it’s working flawlessly and since you make use of the e-mail header, it’ll always work.</p>
<p>Lets pick a label in Word, for example “Confidential”. I have configured that Outlook automatically takes over the label from the document as you can see in below screenshots:</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73827" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-label-300x85.png" alt="" width="300" height="85" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-label-300x85.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-label.png 596w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>&nbsp;</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73828" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-automatic-label-300x145.png" alt="" width="300" height="145" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-automatic-label-300x145.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-automatic-label.png 469w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>&nbsp;</p>
<p>Now we want to make sure that this e-mail is encrypted, without the need for the user to select the “Do Not Forward” button (which is also only available with the AIP client) and without the need for the AIP client to be installed.</p>
<p>Go to “Exchange admin center &gt; mail flow &gt; new rule &gt; select Apply Office 365 Message Encryption and rights protection to messages…”</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73831" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-OME-300x226.png" alt="" width="300" height="226" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-OME-300x226.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-OME-600x453.png 600w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-OME.png 680w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>If you check the e-mail header from an e-mail where you selected “Confidential”, you will see that the sensitivity is set to “Confidential”:</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73832" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-sensitivity-300x39.png" alt="" width="300" height="39" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-sensitivity-300x39.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-sensitivity-600x78.png 600w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-sensitivity.png 632w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>So we have to make sure that OME is applied when an e-mail header matches “Confidential”.</p>
<p>the header name is called “msip_labels”</p>
<p>Configure it like this (make sure you configure multiple if you use multiple languages with AIP):</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73830" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-exchange-rule-300x232.png" alt="" width="300" height="232" srcset="https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-exchange-rule-300x232.png 300w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-exchange-rule-600x464.png 600w, https://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-exchange-rule.png 724w" sizes="(max-width: 300px) 100vw, 300px" /></p>
<p>Now wait a few minutes (can take up to one hour before your changes are synced through the 220 thousand Exchange servers) and try it out! You should you receive the e-mail now as a protected e-mail:</p>
<p><img decoding="async" class="alignnone size-medium wp-image-73829" src="http://erjenrijnders.nl/wp-content/uploads/2018/05/azure-information-protection-encrypted-email.png" alt="" width="259" height="59" /></p>
<p><strong>Note that if you encrypt the e-mail, by default it will also encrypt Office documents. And because they are encrypted by OME, you cannot track the document (yet).</strong></p>
<p>The post <a href="https://erjenrijnders.nl/2018/07/03/aip-label-based-encryption/">AIP label-based encryption</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2018/07/03/aip-label-based-encryption/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
