{"id":2440,"date":"2017-01-09T16:21:43","date_gmt":"2017-01-09T14:21:43","guid":{"rendered":"http:\/\/blog.hosebei.ch\/?p=2440"},"modified":"2017-01-09T16:21:43","modified_gmt":"2017-01-09T14:21:43","slug":"azure-information-protection-if-os-7-8-10-and-office-2010-2013-2016-365-which-clients-do-i-need-for-aip","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=2440","title":{"rendered":"Azure Information Protection: If OS {7, 8, 10} and Office {2010, 2013, 2016, 365} which Clients do I need for AIP?"},"content":{"rendered":"<p>Currently many customers are looking for a solution to protect their content, and finding themself within the Microsoft Office 365 and Azure Ecosystem, and realizing, that they might already been able to use a solution for Information Protection. But this leads often to the Question, how can I, and more important, how can my users take advantage of Azure Information Protection (AIP)?<br \/>\nI will try to answer those questions within this Blog Post.<br \/>\n<!--more--><br \/>\nSo the first question might be:<br \/>\n<strong>Which Windows Version do I need, to be able to use AIP?<\/strong><br \/>\nThis first one is quite easy, currently all Supported Microsoft Client Operating Systems do not support Azure Information Protection. Starting with Windows Vista (or Windows Server 2008), all operating Systems bring the Rights Management Services (RMS) Client (also called as MSIPC), which is required for using Azure RMS or also the Active Directory RMS (which is the On-Premise Service). Any Application that has implemented the RMS Features can then use the protection options of a connected RMS source.<br \/>\nBut in fact, not the current Version of the RMS Client is included within the operating system, and you may not get it through Windows Updates. From the FAQ of the RMS Client Version 2:<\/p>\n<blockquote><p><strong>Is the RMS client included by default when I install a supported operating system?<\/strong><br \/>\nNo. This version of the RMS client ships as an optional download that can be installed separately on computers running supported versions of the Microsoft Windows operating system.<\/p><\/blockquote>\n<p>So we don&#8217;t have to deploy the RMS Client Version 2 separately, as we can see on the later Topics, it will be included in the other Packages, and for the regular Application purposes the default RMS Client will work.<br \/>\nSee the RMS Client Documentation Deployment Notes for more information: <a href=\"https:\/\/docs.microsoft.com\/en-us\/information-protection\/rms-client\/client-deployment-notes\" target=\"_blank\">docs.microsoft.com<\/a><\/p>\n<p>This brings us to our next question:<br \/>\n<strong>Do I need additional Software to use RMS within Applications?<\/strong><br \/>\nThe answer is simply: No, you don&#8217;t, but for AIP you will.<br \/>\nAnd you might want to, because within the Operating System shipped Version of the RMS Client, you can only use those commands, which a Developer has included in their products. For example within Microsoft Office from Version 2010 (with required Service Pack) until the current Version of Office, you can use the protect command within Word or Excel:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01.png?w=300\" alt=\"RMS in Office Application\" width=\"300\" height=\"171\" class=\"aligncenter size-medium wp-image-2445\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01.png 1087w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01-300x171.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01-1024x584.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip01-768x438.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nThis image show the Integration of the RMS Client within the Office Products out of the Box. The User can select an pre-existent Template to protect a Document, but he\/she will not be able to select only a few Users, or to assign the protection on a simple way.<br \/>\nBut to close the gap to a more user-friendly presentation, there exists two different clients to extend the RMS Client functionality, I will point out those later on.<br \/>\nFor automation purposes, you can also use a connector between your On-Premise Resource and Azure RMS, and automatically protect Files within SharePoint or on a FileServer using the File and Resource Manager Feature.<\/p>\n<p>I have talked about those additions to the RMS Clients, which are available from Microsoft. There are two of them and one is called RMS Sharing Application, where the other one is simply called Microsoft Azure Information Protection. Let me first talk about the new and improved Microsoft Azure Information Protection client, so here it comes, the:<br \/>\n<strong>What can I do with the Microsoft Azure Information Protection?<\/strong><br \/>\nThis client helps you (or your IT) and your End-Users aswell. For the End-User Perspective, he will receive a new bar within Office (and other Products where it is supported, see this List for more Information <a href=\"https:\/\/docs.microsoft.com\/en-us\/information-protection\/get-started\/requirements-applications\" target=\"_blank\">docs.microsoft.com<\/a>), where he can select the purpose of the document:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip02.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip02.png?w=300\" alt=\"Azure Information Protection Office Integration\" width=\"300\" height=\"11\" class=\"aligncenter size-medium wp-image-2447\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip02.png 911w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip02-300x11.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip02-768x28.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAfter a click on a Sensitivity option on which template is assigned (the assignment of a template will be done through the Azure Portal), the Documents gets protected and will show this to the User:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03.png?w=300\" alt=\"AIP Office Permissions\" width=\"300\" height=\"126\" class=\"aligncenter size-medium wp-image-2448\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03.png 1279w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03-300x126.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03-1024x432.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip03-768x324.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAs an author, all the Permissions are granted to my Account.<br \/>\nYou can trigger this protection automatically based on content or other Data of the Document, even Regular Expressions to detect Personal ID-Numbers can be implemented.<br \/>\nThe document itself looks like a regular Word Document:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip04.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip04.png?w=300\" alt=\"Protected Word Document\" width=\"300\" height=\"17\" class=\"aligncenter size-medium wp-image-2450\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip04.png 620w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip04-300x17.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nWhen you open the file again, based on the RMS template you might be asked to authenticate, and you can view or edit the document like before. Co-Workers can open the file aswell, if the template allows them to do so.<br \/>\nYou can find the AIP Client in the Microsoft Download Center: <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=53018\" target=\"_blank\">download link<\/a><\/p>\n<p>Last but not least, the<br \/>\n<strong>What is the Rights Management sharing application?<\/strong><br \/>\nThis application was the first Azure RMS related client, that was introduced to manage protection more easily, and also within the File-Explorer for not natively Supported Document Applications (like Notepad or PDF). But even in the early days, there was only a short amount of time, until the first publishers have implemented RMS in their products, Foxit PDF Reader is one of those examples.<br \/>\nSo how can End-User use the features of the sharing application? The Sharing App adds another Button to the Office Products:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip05.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip05.png\" alt=\"RMS sharing application\" width=\"152\" height=\"130\" class=\"aligncenter size-full wp-image-2451\" \/><\/a><br \/>\nWithin the opened wizard, the user can select, which permission are granted, and to whom.<br \/>\nAnother option is to protect documents, that are not recognized by the sharing application. Just open the File Explorer and navigate to the File, and right-click to open the context menu:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip06.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip06.png?w=300\" alt=\"RMS Sharing Application File Explorer\" width=\"300\" height=\"79\" class=\"aligncenter size-medium wp-image-2453\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip06.png 956w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip06-300x79.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip06-768x202.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nWhen the protection was successful, the file-ending gets a leading p:<br \/>\n<a href=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip07.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/blog.hosebei.ch\/wp-content\/uploads\/2017\/01\/azure_aip07.png\" alt=\"RMS Protected bmp\" width=\"178\" height=\"23\" class=\"aligncenter size-full wp-image-2455\" \/><\/a><br \/>\nThe RMS sharing Application brings for a small set of file types (like txt) a reader, thus a file does not be unprotected to read. Those readers can be triggered by double-click on a protected file, like &#8220;this_is_a_textfile.ptxt&#8221;.<br \/>\nYou can find the RMS sharing application on the Microsoft download Center: <a href=\"https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=40857\" target=\"_blank\">download link<\/a><\/p>\n<p>And I also want to mention, that RMS is not limited to Microsoft Operating Systems, and there are a lot more features than I explained in this blog, which is looking at the client side. It is really worth to check the availability of RMS for your company, and check where protection and tracking (<a href=\"https:\/\/docs.microsoft.com\/en-us\/information-protection\/rms-client\/sharing-app-track-revoke\" target=\"_blank\">See how tracking works<\/a>) is required.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Currently many customers are looking for a solution to protect their content, and finding themself within the Microsoft Office 365 and Azure Ecosystem, and realizing, that they might already been able to use a solution for Information Protection. But this leads often to the Question, how can I, and more important, how can my users [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,7,8],"tags":[],"class_list":["post-2440","post","type-post","status-publish","format-standard","hentry","category-aip","category-azure-ad","category-azure-information-protection"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2440","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2440"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/2440\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2440"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2440"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2440"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}