Azure Information Protection

All ideas that relate to Azure Information Protection (AIP)

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. AIP support in Adobe Reader Mobile App

    It is great that AIP is now supported to be opened on Adobe Reader after installing the Addin.

    However equally it is sad that this functionality is not yet supported on Adobe Reader Mobile App. Having this capability only on PC is half the functionality.
    In these days of mobility when users access and annotate the PDF files more on mobile devices than PCs, this functionality should be available in mobile apps as well.

    Any timeline or roadmap when Microsoft and Adobe are planning to release this on mobile apps?

    3 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  2. Allow policies not to automatically grant full control to document creators

    While document creators have by definition unrestricted access to the data they add to the document, having owner rights would allow them to later extract data others have added to the documents they created. Owner rights also allow creators to downgrade classification on documents that have already been classified.
    The suggestion is for AIP to have a setting on each policy that when enabled does not automatically grant the creator of a document full control rights or the ability to reclassify once the document is closed.

    12 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  3. Allow modification to Do Not Forward template

    The DNF template has restrictions on copy, print and export. Some customers would like to modify this template for example to allow print.

    Maybe also a possibility to add a company wide scope of users to this dynamic rule like the request in
    https://msip.uservoice.com/forums/600097-azure-information-protection/suggestions/19602400-dynamic-protection-templates

    And the possibility for the sending user to add more users to the permission list with BCC and without BCC

    for example if Sara@contoso.com send DNF to Anna@contoso.com and Lisa@adatum.com but wants Anna@contoso.com to be co-owner.

    if Sara@contoso.com send DNF to Lisa@adatum.com but wants her team to be co-owner.

    29 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    3 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  4. Shared Mailbox and ticketingsystem support

    This is really a grooving problem right now with GDPR.
    I can see a big increase in incoming OME/DNF to all my customers tenants. Many use shared mailboxes or ticketing systems and cannot open these mails and attached documents.

    For example a customer with AIP implemented, they work with both partners and customers. Many of their services use Shared mailboxes. Multiple users handle these requests.
    Now multiple partners has started to use OME and DNF encryption. When they send sensitive information to these shared mailboxes, no one can read.

    Same situation with the opposite, If they send OME DNF to…

    26 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  5. Enable Watermarking of Adobe PDF documents using Classify and Protect

    Hi, We are looking for the Watermarking feature Adobe PDF documents while performing Classify and Protect option in AIP.

    Thanks

    27 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  6. Limit custom permission (Select users, groups, or organizations) to not allow domain

    Currently AIP custom permission allow users to type the recipients full email address, a group email address, or a domain name from the organization for all users in that organization.

    It would be great if organizations can control to NOT allow domain name as recipient. as this could be a security concern. since anyone in the target organization domain name can access the content (although the tracking is available but risk of information sharing is increased).

    1 vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  7. AIP Scanner - identify PxI and redact sensative data elements

    Speech to text transcription services may output text that contains sensitive information such as credit card (PCI) numbers. It would be very useful to leverage pre-defined AIP Scanner policies to identify PCI data elements in the text files and also redact or overwrite the PCI data instead of just applying a label or protecting the file. Ideally this would be an Azure API service call or cmdlet.

    1 vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  8. AIP Protection with Set user-defined permissions should allow hybrid settings. e.g setting Allow Offline Access which is not set by Office

    When setting an AIP Protection policy with Set User Defined Permissions, AIP Admin should be able to include settings like Allow Offline Access within the Protection policy. This would then act the same as a protection policy with no users defined except for the Allow Offline Access setting, and the Office user selecting users and permissions.

    3 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  9. Allow the end user to view or edit specific section of the file content

    Azure Information Protection, to allow to the end user to view or edit specific section of the file content (word) (Example: section 2.5).
    AIP will work on sections inside the file not only on the file

    2 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  10. Enable co-authoring of Protected Documents

    Currently, documents that are labelled can be co-authored in Office, but any document that is encrypted can only be opened by one person at a time. This prevents most of the business scenarios folks use today with two three or more folks editing a document at the same time. Instead - it forces businesses to email copies of a document around after setting AIP policies to allow folks to all edit it. A huge blocker for most of our customers.

    137 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    We're working on it!  ·  6 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  11. Allow "Everyone" or Wildcard to assign rights to a document

    It would be handy for some documents if you could define a wildcard scope or everyone to view a document (with or without an expiration date) while you give for example co-author rights to all tenant users.
    This could be usefull for some types of information for example safety sheets that you want everyone to be able to read but to make sure the latest version is used.

    12 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  12. Enforce access only to users with correct domain name

    Both in the AIP Portal (for admins to create labels) and in the GUI (for users defining own permissions on documents), you can choose to type in a domain - eg contoso.com - which we thougth would give access to users with primary SMTP set to contoso.com - it seems we were wrong!
    What actually happens is everybody on the tenant which contoso.com belongs to gets access. A user which belongs to a different company/entity (adatum.com) or a sub company (foodtruck.contoso.com), but is on the same tenant also gets access to the file with permissions only for contoso.com users.

    This…

    3 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  13. Add support for Intune MAM to AIP iOS App

    Allow Intune to configure and apply MAM policies on the AIP viewer mobile app for iOS

    18 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  14. Allow mailbox delegates to access protected content on behalf of managers

    If a user is a designated delegate of a mailbox of another user, allow them to access content protected to that user

    69 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Under Review  ·  11 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  15. Add one time pin via sms for OME

    Would be good to add one time pin via SMS for OME. presently users gets an email to decrypt and encrypted email or document however if mailbox has been compromised, one can access encrypted mail as one time is sent via email.

    5 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. Conditional Access policies for highly sensitive information types based on label

    Add new policy options to integrate and enforce Conditional Access policies (such as user, device, location etc) when accessing sensitive information depending on the label, including MFA

    82 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    8 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  17. Increase the number of file types that automatically get protected when attached to a protected email, starting with PDF.

    Currently, when you attach an unprotected Office document to an email, and then protect the email, the attachment inherits the protection. This should be expanded to include other file types, importantly PDF files.

    44 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Proposed  ·  1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  18. aip scanner support for exchange online

    need a way for scanning email at-rest for identifying GDPR and similar data compliance requirements. today only DLP while in transit is available to identify sensitive email content due to lacking index of this data.

    17 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    Under Review  ·  1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  19. An easy way to request and be granted additional rights to already protected documents

    Make it easy for document owners to receive requests for additional rights to protected documents and have that update all copies of that document i.e. maintain a central rights catalog

    61 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
  20. AIP and external services (e.g. DocuSign)

    Allow for external services to be invoked using AIP files, by giving appropriate permissions to the external service or removing and reapplying protection as part of the transaction.

    Specific use cases around DocuSign

    6 votes
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3
  • Don't see your idea?

Feedback and Knowledge Base