MIP: AipServiceMaxUseLicenseValidityTime and predefined offline access in labels

BenHV 21 Reputation points
2021-01-26T09:47:18.913+00:00

Hello everyone! Following issue with MIP on a quite common use case:

  • We would like to provide a Microsoft Information Protection label "Confidential" with an offline access on the file of 30 days. Only predefined user groups can open the document.
  • Additionally, we would like to provide a Microsoft Information Protection label "Highly confidential" where we let the user assign permissions when they apply the label. In order to be able to revoke access for these highly confidential documents, we'd like to set offline access to 0 days (authentification required whenever a user tries to open a file).

Unfortunately, offline access can't be configured for a MIP label where users can assign permissions as they are not saved as AIPServiceTemplates. However, I can set the AipServiceMaxUseLicenseValidityTime which then is globally valid for all labels and overwrites specific offline access values from other labels, as it is more restrictive.

Is there a way that allows me to set offline access individually for labels with predefined permissions and labels where the user can apply permissions?

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
523 questions
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,496 Reputation points Microsoft Employee
    2021-01-29T17:58:09.077+00:00

    @BenHV
    Thank you for your time and patience throughout this issue! I received a response from our AIP team and will post their update below.

    Update:
    If you use user defined permissions, it gives the user control and therefore you don't have the option to set that setting. I would rather have the lower classification have user defined permissions and the more restrictive be defined by a label, that should circumvent the issue.

    I hope this helps! If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


0 additional answers

Sort by: Most helpful