How to view external access of AIP protected documents?

96797374 0 Reputation points
2023-02-06T15:49:03.34+00:00

We are using sensitivity labels (AIP) to protect documents, some of which are used for sharing files with users outside of our tenant. I am using the Microsoft Purview Information Protection connector in Sentinel to view the activity of the labeled files. Access logs are created when a user within our tenant accesses AIP protected files, but not when an external user accesses the documents. The end goal is to be able to view all access to AIP protected documents, not just internal access (within the tenant).

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
560 questions
Microsoft Security Microsoft Sentinel
Microsoft Security Microsoft Purview
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 35,621 Reputation points Microsoft Employee Moderator
    2023-02-10T07:57:46.6833333+00:00

    Apologies for the delay in my response, was checking with the team internally on your ask, Below is the update I have

    Access to any protected content will go though the AADRM part of AIP. Currently you may export the AIP Service User Logs with PowerShell to see this.

    This logging is scheduled to be added to the Activity Explorer data, its in the roadmap - can be tracked here whenever they are new changes to Azure Information Protection - https://www.microsoft.com/en-in/microsoft-365/roadmap?=&filters=&searchterms=azure%2Cinformation%2Cprotection

    Reference:

    https://learn.microsoft.com/en-us/powershell/module/aipservice/get-aipserviceuserlog?view=azureipps

    https://learn.microsoft.com/en-us/azure/information-protection/log-analyze-usage

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.