Azure Information Protection

Azure Information Protection (AIP, formerly known as Azure Rights Management Services or Azure RMS) is an online service for information security provided as part of the Microsoft Azure family of services. It combines data classification, encryption, access controls, usage rights enforcement and access tracking and reporting for controlling access to unstructured content such as corporate e-mails, Microsoft Word documents, and PDFs, and the operations authorized users can perform on them. Companies can use this technology to protect information stored in such document formats, and through policies embedded in the documents PReVENT the protected content from being accessed except by specified people or groups, in certain environments, under certain conditions, and for certain periods of time. Specific operations like printing, copying, editing, forwarding, and deleting can be allowed or disallowed by content authors for individual pieces of content, and AIP administrators can define Classification Labels with associated rights which users or automated services can then apply to content.

Azure Information Protection is the successor to both AD RMS and Secure Islands, which Microsoft acquired in 2015.

In addition, using this same technique, a user that has been granted rights to view a protected document can manipulate the content of the document without leaving traces of the manipulation. Since Azure RMS is not a non-repudiation solution and, unlike document signing solutions, does not claim to provide anti-tampering capabilities, and since the changes can only be made by users that are granted rights to the document, Microsoft does not consider the later issue to be an actual attack against the claimed capabilities of RMS. The researchers provide a proof of concept tool, to allow evaluation of the results, via GitHub.

Software support

Azure Information Protection is supported by the following products:

  • Microsoft Office 2010 and later: Word, Excel, PowerPoint, Outlook, InfoPath
  • Visio 2016
  • Microsoft Office for Mac 2016 and later: Word, Excel, PowerPoint, Outlook
  • SharePoint 2010 and later and SharePoint Online
  • Exchange Server 2010 and later and Exchange Online
  • The Azure Information Protection app
  • Multiple third party PDF readers including Foxit and 9Folders
  • AutoCAD and other third party applications through third-party extensions