Forum Discussion
Force AIP labelling/protection
- Nov 01, 2018
Soon enough the Azure Information Protection client will be build into the Office Pro Plus clients, effectively solving one of your issues. Until then I think your best bet is to utilize Azure Information Protection in conjunction with Data Loss Prevention for sensitive data types.
In AIP you could enforce that all documents must have a label and ensure that all documents starts with a default label. It won't solve all you headaches, but It's a start I guess.
Also you can enforce transport rules through the Exchange Admin center, that will add protection to content that is being sent externally, even if that content is sent from devices or applications that does not support adding labels or protection to content.
https://docs.microsoft.com/en-us/azure/information-protection/configure-exo-rules
You can also enforce Information Rights Management in selected or all SharePoint/OneDrive document library locations, to ensure protection for files located there.
https://docs.microsoft.com/en-us/office365/securitycompliance/set-up-irm-in-sp-admin-center
To allow automatic label you must configure the relevant settings but not all services work with the label, for example in Exchange you must to create Exchange Transport Rule to allow label, but there are some conditions when applying labels with AIP and Exchange.
But before starting with AIP label and Exchange take a quick look with the following URL's: https://docs.microsoft.com/en-us/azure/information-protection/faqs-infoprotect
https://docs.microsoft.com/en-us/azure/information-protection/configure-policy-protection
For other protection such as RMS, you can apply Secure Email (OMEv2) and protect all content that go externally.
Eli.
Eli, thank you for taking the time to respond to my email and to gather those links; I really appreciate it. Let's set aside emails for the time being. I am chiefly concerned with documents being labeled and protected by default. If no emails at all were protected, but every document was, I would be content with that.
What are these relevant settings you mentioned in your first sentence?
I have set a policy and assigned my test user to it. There is a default label, but it only gets automatically applied if the AIP client is installed, which means a malicious user could just uninstall it to get around the labeling requirement.