API permissions for the Microsoft Information Protection SDK

The MIP SDK uses two backend Azure services for labeling and protection. In the Microsoft Entra app permissions blade, these services are:

  • Azure Rights Management Service
  • Microsoft Purview Information Protection Sync Service

Grant application permissions to one or more APIs when you use the MIP SDK for labeling and protection. Different application authentication scenarios might require different application permissions. For application authentication scenarios, see Authentication scenarios.

Grant tenant-wide admin consent for application permissions when those permissions require administrator consent. For more information, see the Microsoft Entra documentation.

Application permissions

Application permissions allow an application in Microsoft Entra ID to act as its own entity, rather than on behalf of a specific user.

Service Permission name Description Admin consent required
Azure Rights Management Service Content.SuperUser Read all protected content for this tenant Yes
Azure Rights Management Service Content.DelegatedReader Read protected content on behalf of a user Yes
Azure Rights Management Service Content.DelegatedWriter Create protected content on behalf of a user Yes
Azure Rights Management Service Content.Writer Create protected content Yes
Azure Rights Management Service Application.Read.All Permission not required for MIP SDK use Not applicable
MIP Sync Service UnifiedPolicy.Tenant.Read Read all unified policies of the tenant Yes

Content.SuperUser

Use this permission when an application needs to decrypt all content protected for the specific tenant. Examples of services that require Content.SuperUser rights are data loss prevention or cloud access security broker services that must view all content in plaintext to make policy decisions about where that data might flow or be stored.

Content.DelegatedWriter

Use this permission when an application needs to encrypt content protected by a specific user. Examples of services that require Content.DelegatedWriter rights are line-of-business applications that need to encrypt content based on a user's label policies, apply labels, or encrypt content natively. This permission allows the application to encrypt content in the context of the user.

Content.DelegatedReader

Use this permission when an application needs to decrypt all content protected for a specific user. Examples of services that require Content.DelegatedReader rights are line-of-business applications that need to decrypt content based on a user's label policies and display the content natively. This permission allows the application to decrypt and read content in the context of the user.

Content.Writer

Use this permission when an application needs to list templates and encrypt content. A service that attempts to list templates without this permission receives a token rejected message from the service. Examples of services that require Content.Writer are line-of-business applications that apply classification labels to files on export. Content.Writer encrypts the content as the service principal identity, so the owner of the protected files is the service principal identity.

UnifiedPolicy.Tenant.Read

Use this permission when an application needs to download unified labeling policies for the tenant. Examples of services that require UnifiedPolicy.Tenant.Read are applications that need to work with labels as a service principal identity.

Delegated permissions

Delegated permissions allow an application in Microsoft Entra ID to perform actions on behalf of a particular user.

Service Permission name Description Admin consent required
Azure Rights Management Service user_impersonation Create and access protected content for the user No
MIP Sync Service UnifiedPolicy.User.Read Read all unified policies a user has access to No

user_impersonation

Use this permission when an application needs to use Azure Rights Management Services on behalf of the user. Examples of services that require user_impersonation rights are applications that need to encrypt or access content based on a user's label policies to apply labels or encrypt content natively.

UnifiedPolicy.User.Read

Use this permission when an application needs to read unified labeling policies related to a user. Examples of services that require UnifiedPolicy.User.Read permissions are applications that need to encrypt and decrypt content based on a user's label policies.