Azure Information Protection

All ideas that relate to Azure Information Protection (AIP)

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Allow policies not to automatically grant full control to document creators

    While document creators have by definition unrestricted access to the data they add to the document, having owner rights would allow them to later extract data others have added to the documents they created. Owner rights also allow creators to downgrade classification on documents that have already been classified.
    The suggestion is for AIP to have a setting on each policy that when enabled does not automatically grant the creator of a document full control rights or the ability to reclassify once the document is closed.

    7 votes
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)

      We’ll send you updates on this idea

      1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
    • Shared Mailbox and ticketingsystem support

      This is really a grooving problem right now with GDPR.
      I can see a big increase in incoming OME/DNF to all my customers tenants. Many use shared mailboxes or ticketing systems and cannot open these mails and attached documents.

      For example a customer with AIP implemented, they work with both partners and customers. Many of their services use Shared mailboxes. Multiple users handle these requests.
      Now multiple partners has started to use OME and DNF encryption. When they send sensitive information to these shared mailboxes, no one can read.

      Same situation with the opposite, If they send OME DNF to…

      17 votes
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)

        We’ll send you updates on this idea

        4 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
      • AIP Protection with Set user-defined permissions should allow hybrid settings. e.g setting Allow Offline Access which is not set by Office

        When setting an AIP Protection policy with Set User Defined Permissions, AIP Admin should be able to include settings like Allow Offline Access within the Protection policy. This would then act the same as a protection policy with no users defined except for the Allow Offline Access setting, and the Office user selecting users and permissions.

        2 votes
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)

          We’ll send you updates on this idea

          0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
        • Allow the end user to view or edit specific section of the file content

          Azure Information Protection, to allow to the end user to view or edit specific section of the file content (word) (Example: section 2.5).
          AIP will work on sections inside the file not only on the file

          1 vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)

            We’ll send you updates on this idea

            0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
          • Enable co-authoring of Protected Documents

            Currently, documents that are labelled can be co-authored in Office, but any document that is encrypted can only be opened by one person at a time. This prevents most of the business scenarios folks use today with two three or more folks editing a document at the same time. Instead - it forces businesses to email copies of a document around after setting AIP policies to allow folks to all edit it. A huge blocker for most of our customers.

            102 votes
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)

              We’ll send you updates on this idea

              Yes, Committed  ·  5 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
            • Add support for Intune MAM to AIP iOS App

              Allow Intune to configure and apply MAM policies on the AIP viewer mobile app for iOS

              17 votes
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)

                We’ll send you updates on this idea

                0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
              • Add one time pin via sms for OME

                Would be good to add one time pin via SMS for OME. presently users gets an email to decrypt and encrypted email or document however if mailbox has been compromised, one can access encrypted mail as one time is sent via email.

                5 votes
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  4 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                • Allow mailbox delegates to access protected content on behalf of managers

                  If a user is a designated delegate of a mailbox of another user, allow them to access content protected to that user

                  59 votes
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    Under Review  ·  9 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                  • Conditional Access policies for highly sensitive information types based on label

                    Add new policy options to integrate and enforce Conditional Access policies (such as user, device, location etc) when accessing sensitive information depending on the label, including MFA

                    63 votes
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      7 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                    • Allow Office 365 Business Premium users to have OME functionality in their desktop Outlook app

                      At this time, Office 365 Business Premium users may purchase licenses for Azure Information Protection, however the OME protection only extends to the online activity, in particular email. They must adjust their licensing in order to have the functions of this license extended to their desktop software. This is generally unexpected for the customer as I have worked with major distributor Microsoft licensing desks who did not get this right when I requested the specific licensing solution for the functionality I am describing. Please change policy so that the click-to-run version of Office available to Business Premium subscribers will inherit…

                      4 votes
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                      • AIP and external services (e.g. DocuSign)

                        Allow for external services to be invoked using AIP files, by giving appropriate permissions to the external service or removing and reapplying protection as part of the transaction.

                        Specific use cases around DocuSign

                        5 votes
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                        • Add the ability to grant access to protected content via OTP

                          We are finding that many external parties do not want to or have the ability to install AIP software, or are prevented from signing up to a Microsoft account. Some form of OTP code or ability to get one time access to the document (or for X number of days) would be very helpful

                          17 votes
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            Proposed  ·  0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                          • Automatically add first time Sign up instructions for external users

                            There should be automatic instructions added in an email (with a protected attachment) being sent to external users.

                            in Azure RMS early days Share-Protect feature used to add an automated sign-up instruction for external users. so that when a recipient who does not have AIP viewer or client, knows what to do to open the protected document or email.

                            Unfortunately this feature is no more. It would be great if such instructions can be added automatically in the email if AIP policy (or custom permissions) contains any external recipient.

                            This is a big ask by one of our customer we…

                            3 votes
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              Proposed  ·  0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                            • Check if the receiver (domain?) is likely to be able to receive aip protected messages

                              If I send protected emails to an external party it would be cool if o365 could hint me if it thinks the receiver can decode it or not.

                              Shute this is not a 100% hint.

                              1 vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                              • Enforce access only to users with correct domain name

                                Both in the AIP Portal (for admins to create labels) and in the GUI (for users defining own permissions on documents), you can choose to type in a domain - eg contoso.com - which we thougth would give access to users with primary SMTP set to contoso.com - it seems we were wrong!
                                What actually happens is everybody on the tenant which contoso.com belongs to gets access. A user which belongs to a different company/entity (adatum.com) or a sub company (foodtruck.contoso.com), but is on the same tenant also gets access to the file with permissions only for contoso.com users.

                                This…

                                1 vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                • Allow modification to Do Not Forward template

                                  The DNF template has restrictions on copy, print and export. Some customers would like to modify this template for example to allow print.

                                  Maybe also a possibility to add a company wide scope of users to this dynamic rule like the request in
                                  https://msip.uservoice.com/forums/600097-azure-information-protection/suggestions/19602400-dynamic-protection-templates

                                  And the possibility for the sending user to add more users to the permission list with BCC and without BCC

                                  for example if Sara@contoso.com send DNF to Anna@contoso.com and Lisa@adatum.com but wants Anna@contoso.com to be co-owner.

                                  if Sara@contoso.com send DNF to Lisa@adatum.com but wants her team to be co-owner.

                                  21 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    3 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                  • excel filtering should not be disabled!

                                    when document is protected, users having read-only cannot use filters. if you have couple rows it's not a problem.. but we are having report files with thousands rows - so either you have edit permissions, or you can't do any reporting. file is pretty much unusable without filters /: true bummer

                                    3 votes
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      0 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Enable Watermarking of Adobe PDF documents using Classify and Protect

                                      Hi, We are looking for the Watermarking feature Adobe PDF documents while performing Classify and Protect option in AIP.

                                      Thanks

                                      16 votes
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        3 comments  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                      • AIP viewer application on mobile does not block out sceenshot capabilities

                                        AIP viewer application on mobile does no block out mobile screenshot capabilities, this provides a by-pass to extract (copy) information from a view only document.
                                        In this case, users can just open the view only protected file on the mobile AIP viewer instead of the desktop application.

                                        5 votes
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Screenshot not disabled for Outlook live

                                          By sending a protected mail to non-outlook accounts, upon opening the mail, I will be prompt to view the message using outlook live.
                                          I noticed that when I open an email using outlook live (web) I can still screenshot the contents of the email.
                                          Is this a bug?

                                          2 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            1 comment  ·  Protection  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3
                                          • Don't see your idea?

                                          Feedback and Knowledge Base