使用 PowerShell 管理 Azure 權利管理服務

Microsoft Purview 服務描述

手動啟用 Azure 權利管理加密服務需要 PowerShell,有些進階設定也需要 PowerShell。 部分設定可以從 Microsoft Purview 入口網站完成,不過你可能偏好使用 PowerShell,以提升命令列控制和腳本的效率。

下表列出了一些使用 PowerShell 的進階設定情境。 當設定也能在不使用 PowerShell 的情況下完成時,這些資訊也會包含在表格中。

欲了解本模組可用指令匣的完整清單及每個指令匣的更多資訊,請參見 AIPService

要安裝此 PowerShell 模組,請參見 Install the AIPService PowerShell module for the Azure Right Management service

提示

除了這個服務端的 PowerShell 模組外,Microsoft Purview 資訊保護用戶端還安裝了一個補充的 PowerShell 模組 PurviewInformationProtection

此用戶端模組支援標註與加密多個檔案,例如你可以對資料夾中的所有檔案進行批量保護。 欲了解更多資訊,請參閱 使用 PowerShell 設定資訊保護用戶端

按管理任務分組的指令小子

下表依照執行指令碼(cmdlet)將常見管理任務分類。

如果您需要… …請使用以下指令匣
從本地的 Rights Management (AD RMS 或 Windows RMS) 遷移到 Microsoft Purview 資訊保護 的 Azure Rights Management 服務。 Import-AipServiceTpd

Set-AipServiceKeyProperties
連接或斷開貴組織的權利管理服務。 Connect-AipService

Disconnect-AipServiceService
為Azure權利管理服務產生並管理您自己的根金鑰—— (自帶金鑰) BYOK 情境。 Set-AipServiceKeyProperties

Use-aipServiceKeyVaultKey

Get-AipServiceKeys
為您的組織啟用或停用 Azure 權利管理服務。 啟用-AIPService

Disable-AIPService
為分階段部署 Azure 權利管理服務配置入職控制。 Get-AipServiceOnboardingControlPolicy

Set-AipServiceOnboardingControlPolicy
為您的組織建立並管理權利管理範本。 Add-AipServiceTemplate

Export-AipServiceTemplate

Get-AipServiceTemplate

Get-AipServiceTemplateProperty

Import-AipServiceTemplate

New-aipServiceRightsDefinition

Remove-AipServiceTemplate

Set-AipServiceTemplateProperty
設定您組織加密內容在使用授權有效期) (可無網路連線存取的最大天數。 Get-AipServiceMaxUseLicenseValidityTime

Set-AipServiceMaxUseLicenseValidityTime
管理貴組織 Azure 權利管理服務的超級使用者功能。 Enable-aipServiceSuperUserFeature

Disable-AipServiceSuperUserFeature

Add-AipServiceSuperUser

Get-AipServiceSuperUser

Remove-AipServiceSuperUser

Set-AAipServiceSuperUserGroup

Get-AipServiceSuperUserGroup

Clear-AipServiceSuperUserGroup
管理有權管理貴組織 Azure 權利管理服務的使用者與群組。 Add-AIP-ServiceRoleBasedAdministrator

Get-aip-ServiceRoleBasedAdministrator

Remove-AIP-ServiceRoleBasedAdministrator
取得您組織 Azure 權利管理服務管理任務的日誌。 Get-AipServiceAdminLog
記錄並分析 Azure 權利管理服務的使用日誌。 Get-AipServiceUserLog
顯示您組織目前 Azure 權利管理服務的設定。 Get-AipServiceConfiguration
將您的組織從 Azure 權利管理服務遷移到本地部署的 AD RMS 部署。 Set-AipServiceMigrationUrl

Get-AipServiceMigrationUrl
管理權利保護文件的舊有文件追蹤網站 Disable-AipServiceDocumentTrackingFeature

Enable-aipServiceDocumentTrackingFeature

Get-AipServiceDocumentTrackingFeature

Set-AipServiceDoNotTrackUserGroup

Clear-AIPServiceDoNotTrackUserGroup

Get-AipServiceDoNotTrackUserGroup

Get-AipServiceTrackingLog

Get-AipServiceDocumentLog