Super user

%3CLINGO-SUB%20id%3D%22lingo-sub-85427%22%20slang%3D%22en-US%22%3ESuper%20user%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-85427%22%20slang%3D%22en-US%22%3E%3CP%3E%C2%BFWhat%20do%20you%20do%20when%20the%20employee%20who%20protected%20the%20file%20left%20the%20company%3F%20%C2%BFOr%20if%20you%20want%20to%20remove%20the%20current%20protection%20policy%20and%20apply%20a%20new%20one%3F%20The%20answer%20is%20%3CSTRONG%3ESuper%20User%3C%2FSTRONG%3E.%3C%2FP%3E%3CP%3EAs%20an%20admin%2C%20you%20can%20configure%2C%20publish%20and%20update%20policies%20and%20labels%2C%20but%20you%20cannot%20override%20permissions.%20That%20task%20can%20only%20be%20performed%20by%20a%20Super%20User.%3C%2FP%3E%3CP%3ESuper%20Users%20are%20not%20enabled%20by%20default%2C%20but%20you%20can%20do%20so%20by%20following%20a%20couple%20of%20simple%20steps%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EInstall%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Finformation-protection%2Fdeploy-use%2Finstall-powershell%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAADRM%20Powershell%20module%3C%2FA%3E%3C%2FLI%3E%3CLI%3ERun%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Faadrm%2Fvlatest%2Fenable-aadrmsuperuserfeature%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EEnable-AadrmSuperUserFeature%3C%2FA%3E%26nbsp%3Bcmdlet%20followed%20by%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fpowershell%2Faadrm%2Fvlatest%2Fadd-aadrmsuperuser%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAdd-AadrmSuperUser%3C%2FA%3E%26nbsp%3Bproviding%20the%20email%20of%20the%20new%20super%20user.%3C%2FLI%3E%3C%2FOL%3E%3CP%3EThat's%20it.%20The%20super%20suer%20is%20now%20able%20to%20override%20permissions%20on%20any%20protected%20file%20(handle%20with%20care!)%3C%2FP%3E%3CP%3EMore%20information%20here.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-85427%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EInformation%20Protection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERights%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Pablo Ortiz Baiardo
New Contributor

¿What do you do when the employee who protected the file left the company? ¿Or if you want to remove the current protection policy and apply a new one? The answer is Super User.

As an admin, you can configure, publish and update policies and labels, but you cannot override permissions. That task can only be performed by a Super User.

Super Users are not enabled by default, but you can do so by following a couple of simple steps:

 

  1. Install AADRM Powershell module
  2. Run Enable-AadrmSuperUserFeature cmdlet followed by Add-AadrmSuperUser providing the email of the new super user.

That's it. The super suer is now able to override permissions on any protected file (handle with care!)

More information here.

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies