Outlook Encryption and AIP UL

%3CLINGO-SUB%20id%3D%22lingo-sub-1586574%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586574%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F716659%22%20target%3D%22_blank%22%3E%40pradeepg290%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20would%20you%20be%20able%20to%20post%20some%20screen%20shots%20of%20the%20Label%20and%20Label%20policy%20settings%20please%20-%20specifically%20in%20regards%20to%20assigning%20permissions%20to%20users%20and%20groups%3F%26nbsp%3B%20This%20would%20be%20helpful%20to%20see.%26nbsp%3B%20Thank%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586763%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586763%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20very%20much%20much%20appreciate%20your%20help%2C%20please%20see%20the%20screen%20shot%20of%20the%20label%20settings%20and%20policy.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22policy.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212220i6ABC249F4743CA70%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22policy.png%22%20alt%3D%22policy.png%22%20%2F%3E%3C%2FSPAN%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586783%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586783%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThank%20you%20very%20much%2C%20much%20appreciate%20your%20help%2C%20please%20see%20the%20screen%20shot%20of%20the%20label%20settings%20and%20policy.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22policy.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212223i417277FBE973EFC6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22policy.png%22%20alt%3D%22policy.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586874%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586874%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F716659%22%20target%3D%22_blank%22%3E%40pradeepg290%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHmm%2C%20that%20all%20looks%20in%20order%20to%20me.%26nbsp%3B%20The%20only%20thing%20I%20can%20think%20of%20is%20to%20check%20that%20there%20are%20no%20conflicting%20labels%20or%20policies%20which%20may%20be%20assigning%20permissions%20for%20the%20Secret%20label%20to%20the%20user%20who%20should%20not%20have%20it%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586881%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586881%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20m%20also%20confuse%2C%20no%20conflict%20policy%20as%20we%20are%20testing%20this%20only%20with%20POC%20user%20group%20and%20all%20policies%20has%20been%20assigned%20to%20this%20group%20only.%20I%20have%20cheek%20it%20multiple%20times.%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20there%20any%20way%20to%20find%20a%20specific%20label%20is%20public%20using%20powershell%2C%20so%20I%20can%20run%20and%20see%20is%20this%20Label%20is%20public%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586902%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586902%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F716659%22%20target%3D%22_blank%22%3E%40pradeepg290%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20think%20PowerShell%20will%20be%20much%20help%20here%20as%20you%20only%20have%20the%20option%20with%20Unified%20Labelling%20to%20Set-AIPFilelabel%2C%20you%20don't%20have%20the%20option%20to%20Get-AIPFileLabel.%26nbsp%3B%20%26nbsp%3BYou%20can%20Get-AIPFileStatus%20but%20this%20is%20not%20going%20to%20help%20you%20here.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'd%20recommend%20opening%20a%20ticket%20with%20Microsoft%20as%20the%20next%20step%20and%20ask%20them%20to%20check%20into%20this%20for%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586916%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586916%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20Peter.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1586399%22%20slang%3D%22en-US%22%3EOutlook%20Encryption%20and%20AIP%20UL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1586399%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3EI%20have%20created%20a%20AIP%20UL%20label%20called%20%22Secret%22%20and%20published%20the%20label%20policy%20for%20a%20scoped%2Ftargeted%20users%20(%20group%20of%20users)%20%2C%20but%20when%20a%20user%20(who%20is%20not%20on%20the%20scoped%20group)%20goes%20to%20the%20outlook%20under%20the%20%22Encrypt%20this%20item%22%20she%20can%20see%20this%20scoped%20label.%3C%2FP%3E%3CP%3E%3CSTRONG%3ECan%20someone%20tell%20me%20why%20is%20that%2C%20I%20was%20under%20the%20impression%20only%20the%20scope%20users%20will%20be%20able%20to%20see%20this%20label.%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22outlook.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212193iA0CE08EE6B023A07%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22outlook.png%22%20alt%3D%22outlook.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EThe%20set%20of%20labels%20are%20as%20follows-%3C%2FP%3E%3CP%3ESecret%20label%20-%20has%20encryption%3C%2FP%3E%3CP%3EInternal%20-%20Dont%20have%20any%20encryption%20%26lt%3B-%20why%20this%20label%20is%20not%20display%20under%20this%20Encrypt%26nbsp%3B%3C%2FP%3E%3CP%3EClassified%20-%26nbsp%3BDont%20have%20any%20encryption%26nbsp%3B%26lt%3B-%20why%20this%20label%20is%20not%20display%20under%20this%20Encrypt%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20when%20I%20go%20to%20Outlook%20sensitivity%20on%20the%20outlook%20ribbon%2C%20user%20s%20can%20see%20the%20labels%20as%20expected.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22sensitivity.png%22%20style%3D%22width%3A%20163px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212195i1458E6D0B3B9543F%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22sensitivity.png%22%20alt%3D%22sensitivity.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1586399%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EInformation%20Protection%20%26amp%3B%20Governance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Information%20Protection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERights%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hi All,

I have created a AIP UL label called "Secret" and published the label policy for a scoped/targeted users ( group of users) , but when a user (who is not on the scoped group) goes to the outlook under the "Encrypt this item" she can see this scoped label.

Can someone tell me why is that, I was under the impression only the scope users will be able to see this label. 

 

outlook.png

The set of labels are as follows-

Secret label - has encryption

Internal - Dont have any encryption <- why this label is not display under this Encrypt 

Classified - Dont have any encryption <- why this label is not display under this Encrypt 

 

But when I go to Outlook sensitivity on the outlook ribbon, user s can see the labels as expected. 

sensitivity.png

 

Thanks. 

6 Replies

@pradeepg290 

 

Hi, would you be able to post some screen shots of the Label and Label policy settings please - specifically in regards to assigning permissions to users and groups?  This would be helpful to see.  Thank you.

@PeterRising 

 

Thank you very much, much appreciate your help, please see the screen shot of the label settings and policy.

policy.png

@pradeepg290 

 

Hmm, that all looks in order to me.  The only thing I can think of is to check that there are no conflicting labels or policies which may be assigning permissions for the Secret label to the user who should not have it?

@PeterRising 

I m also confuse, no conflict policy as we are testing this only with POC user group and all policies has been assigned to this group only. I have cheek it multiple times. 

Are there any way to find a specific label is public using powershell, so I can run and see is this Label is public?

 

Thanks. 

@pradeepg290 

 

I don't think PowerShell will be much help here as you only have the option with Unified Labelling to Set-AIPFilelabel, you don't have the option to Get-AIPFileLabel.   You can Get-AIPFileStatus but this is not going to help you here.

 

I'd recommend opening a ticket with Microsoft as the next step and ask them to check into this for you.

@PeterRising 

Thanks Peter.