إشعار
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تسجيل الدخول أو تغيير الدلائل.
يتطلب الوصول إلى هذه الصفحة تخويلاً. يمكنك محاولة تغيير الدلائل.
The MIP SDK uses two backend Azure services for labeling and protection. In the Microsoft Entra app permissions blade, these services are:
- Azure Rights Management Service
- Microsoft Purview Information Protection Sync Service
Grant application permissions to one or more APIs when you use the MIP SDK for labeling and protection. Different application authentication scenarios might require different application permissions. For application authentication scenarios, see Authentication scenarios.
Grant tenant-wide admin consent for application permissions when those permissions require administrator consent. For more information, see the Microsoft Entra documentation.
Application permissions
Application permissions allow an application in Microsoft Entra ID to act as its own entity, rather than on behalf of a specific user.
| Service | Permission name | Description | Admin consent required |
|---|---|---|---|
| Azure Rights Management Service | Content.SuperUser | Read all protected content for this tenant | Yes |
| Azure Rights Management Service | Content.DelegatedReader | Read protected content on behalf of a user | Yes |
| Azure Rights Management Service | Content.DelegatedWriter | Create protected content on behalf of a user | Yes |
| Azure Rights Management Service | Content.Writer | Create protected content | Yes |
| Azure Rights Management Service | Application.Read.All | Permission not required for MIP SDK use | Not applicable |
| MIP Sync Service | UnifiedPolicy.Tenant.Read | Read all unified policies of the tenant | Yes |
Content.SuperUser
Use this permission when an application needs to decrypt all content protected for the specific tenant. Examples of services that require Content.SuperUser rights are data loss prevention or cloud access security broker services that must view all content in plaintext to make policy decisions about where that data might flow or be stored.
Content.DelegatedWriter
Use this permission when an application needs to encrypt content protected by a specific user. Examples of services that require Content.DelegatedWriter rights are line-of-business applications that need to encrypt content based on a user's label policies, apply labels, or encrypt content natively. This permission allows the application to encrypt content in the context of the user.
Content.DelegatedReader
Use this permission when an application needs to decrypt all content protected for a specific user. Examples of services that require Content.DelegatedReader rights are line-of-business applications that need to decrypt content based on a user's label policies and display the content natively. This permission allows the application to decrypt and read content in the context of the user.
Content.Writer
Use this permission when an application needs to list templates and encrypt content. A service that attempts to list templates without this permission receives a token rejected message from the service. Examples of services that require Content.Writer are line-of-business applications that apply classification labels to files on export. Content.Writer encrypts the content as the service principal identity, so the owner of the protected files is the service principal identity.
UnifiedPolicy.Tenant.Read
Use this permission when an application needs to download unified labeling policies for the tenant. Examples of services that require UnifiedPolicy.Tenant.Read are applications that need to work with labels as a service principal identity.
Delegated permissions
Delegated permissions allow an application in Microsoft Entra ID to perform actions on behalf of a particular user.
| Service | Permission name | Description | Admin consent required |
|---|---|---|---|
| Azure Rights Management Service | user_impersonation | Create and access protected content for the user | No |
| MIP Sync Service | UnifiedPolicy.User.Read | Read all unified policies a user has access to | No |
user_impersonation
Use this permission when an application needs to use Azure Rights Management Services on behalf of the user. Examples of services that require user_impersonation rights are applications that need to encrypt or access content based on a user's label policies to apply labels or encrypt content natively.
UnifiedPolicy.User.Read
Use this permission when an application needs to read unified labeling policies related to a user. Examples of services that require UnifiedPolicy.User.Read permissions are applications that need to encrypt and decrypt content based on a user's label policies.