Activating the protection service from Azure Information Protection (AIP) (2024)

  • Article

This article describes how administrators can activate the Azure Rights Management protection service for Azure Information Protection (AIP). When the protection service is activated for your organization, administrators and users can start to protect important data by using applications and services that support this information protection solution. Administrators can also manage and monitor protected documents and emails that your organization owns.

This configuration information in this article is for administrators who are responsible for a service that applies to all users in an organization. If you are looking for user help and information to use the Rights Management functionality for a specific application or how to open a file or email that is rights-protected, use the help and guidance that accompanies your application.

For technical support and other questions about the service, see the Support options and community resources information.

Automatic activation for Azure Rights Management

When you have a service plan that includes Azure Rights Management, you may not have to activate the service:

If neither of the listed scenarios apply to you, you must manually activate the protection service.

How to activate or confirm the status of the protection service

Important

Do not activate the protection service if you have Active Directory Rights Management Services (AD RMS) deployed for your organization. More information

To activate the protection service, your organization must have a service plan that includes the Azure Rights Management service from Azure Information Protection. For more information, see .

When the protection service is activated, all users in your organization can apply information protection to their documents and emails, and all users can open (consume) documents and emails that have been protected by this service. However, if you prefer, you can restrict who can apply information protection, by using onboarding controls for a phased deployment. For more information, see the Configuring onboarding controls for a phased deployment section in this article.

Activate protection via PowerShell

You must use PowerShell to activate the Rights Management protection service (Azure RMS). You can no longer activate or deactivate this service from the Azure portal.

  1. Install the AIPService module, to configure and manage the protection service. For instructions, see Installing the AIPService PowerShell module.

  2. From a PowerShell session, run Connect-AipService, and when prompted, provide the Global Administrator account details for your Azure Information Protection tenant.

  3. Run Get-AipService to confirm whether the protection service is activated. A status of Enabled confirms activation; Disabled indicates that the service is deactivated.

  4. To activate the service, run Enable-AipService.

Configuring onboarding controls for a phased deployment

If you don’t want all users to be able to protect documents and emails immediately by using Azure Information Protection, you can configure user onboarding controls by using the Set-AipServiceOnboardingControlPolicy PowerShell command. You can run this command before or after you activate the Azure Rights Management service.

For example, if you initially want only administrators in the “IT department” group (that has an object ID of fbb99ded-32a0-45f1-b038-38b519009503) to be able to protect content for testing purposes, use the following command:

Set-AipServiceOnboardingControlPolicy -UseRmsUserLicense $False -SecurityGroupObjectId "fbb99ded-32a0-45f1-b038-38b519009503"

Note that for this configuration option, you must specify a group; you cannot specify individual users. To obtain the object ID for the group, you can use the Microsoft Graph PowerShell—for example, for version 1.0 of the module, use the Get-MgGroup command. Or, you can copy the Object ID value of the group from the Azure portal.

Alternatively, if you want to ensure that only users who are correctly licensed to use Azure Information Protection can protect content:

Set-AipServiceOnboardingControlPolicy -UseRmsUserLicense $True

When you no longer need to use onboarding controls, whether you used the group or licensing option, run:

Set-AipServiceOnboardingControlPolicy -UseRmsUserLicense $False

For more information about this cmdlet and additional examples, see the Set-AipServiceOnboardingControlPolicy help.

When you use these onboarding controls, all users in the organization can always consume protected content that has been protected by your subset of users, but they won’t be able to apply information protection themselves from client applications. Server-side applications, such as Exchange, can implement their own per-user controls to achieve the same result. For example, to prevent users from protecting emails in Outlook on the web, use Set-OwaMailboxPolicy to set the IRMEnabled parameter to $false.

Next steps

Now that the protection service is activated for your organization, apps and services can apply encryption to help protect your data. One of the easiest ways to apply encryption, is by using sensitivity labels from Microsoft Purview Information Protection.

Activating the protection service from Azure Information Protection (AIP) (2024)

FAQs

How do I enable Azure AIP? ›

Perform the following steps:
  1. Confirm your subscription and assign user licenses.
  2. Prepare your tenant to use Azure Information Protection.
  3. Configure and deploy classification and labeling.
  4. Prepare for data protection.
  5. Configure labels and settings, applications, and services for data protection.
Mar 29, 2024

How to connect to AIP service? ›

To connect to Azure Information Protection, use an account that is one of the following: A global admin for your Office 365 tenant. A global administrator for your Azure AD tenant. However, this account cannot be a Microsoft account (MSA) or from another Azure tenant.

What is AIP Azure Information Protection? ›

Azure Information Protection (AIP) is a cloud-based solution that enables organizations to classify and protect documents and emails by applying labels. For example, your administrator might configure a label with rules that detect sensitive data, such as credit card information.

How to activate the rights management service RMS? ›

Activating Azure Rights Management Using the New/Next O365 Admin Interface
  1. Log into your O365 account and access the Admin section.
  2. Navigate to Settings and select Services & add-ins.
  3. Select Microsoft Azure Rights Management.
  4. Select Manage Microsoft Azure Rights Management settings. ...
  5. Select Activate.
  6. Select Activate.

How do I know if my Azure information protection is enabled? ›

Run Get-AipService to confirm whether the protection service is activated. A status of Enabled confirms activation; Disabled indicates that the service is deactivated. To activate the service, run Enable-AipService.

How do you know if Azure Information Protection has been installed? ›

Protect Within Office:

Once you have installed Azure Information Protection, you will see the AIP Classification menu below the Office Ribbon menu.

How to enable information rights management in Office 365? ›

Log into Office 365 as an administrator at https://portal.office.com.
  1. If you're not already taken to the Office 365 Admin center, click the App Launcher on the top left, then click the Admin tile.
  2. Under Service Settings, click Rights Management.
  3. Click Manage, under Protect your information.

What is the AIP scanner command? ›

The Start-AIPScan cmdlet instructs the Azure Information Protection scanner to immediately start a one-time scan cycle. The scanner service must be started already and the scanner schedule must be configured for a manual schedule. To configure the schedule, use the Azure portal to configure the scanner.

How do I connect to Azure App Service? ›

Securely connect to Azure services and databases from Azure App Service
  1. Connect using secrets.
  2. Connect using the app identity.
  3. Connect as the authenticated user.
  4. Next steps.
Jan 24, 2024

What is AIP and how does it work? ›

Air-independent propulsion (AIP), or air-independent power, is any marine propulsion technology that allows a non-nuclear submarine to operate without access to atmospheric oxygen (by surfacing or using a snorkel).

What is the difference between Microsoft information protection and AIP? ›

Microsoft Information Protection (MIP) vs. AIP—are they the same? AIP is one of the building blocks of Microsoft Information Protection (MIP), extending the labeling and classification functions of the latter. AIP is more advanced with additional capabilities, making it more suitable for hybrid work environments.

Is Azure Information Protection no longer available? ›

The Azure Information Protection add-in is retired and replaced with labels that are built in to your Microsoft 365 apps and services. Learn more about the support status of other Azure Information Protection components.

How to use Azure Information Protection Viewer? ›

Using Azure Information Protection Viewer to open protected and encrypted files or folders
  1. Click the "Start" icon and then "Azure Information Protection Viewer".
  2. Click "Open".
  3. Locate the file and click "Open".

How do I access RMS? ›

Go to Accounting > Quick Account Access in the Side Menu of RMS.
  1. Select an Action to Take.
  2. Select the Search Option and enter the Search Criteria.
  3. Select the 'Go to Account' icon or press 'Enter' on the keyboard.

How does Microsoft RMS work? ›

Azure RMS simply makes the data in a document unreadable to anyone other than authorized users and services: The data is encrypted at the application level and includes a policy that defines the authorized use for that document.

How do I enable Azure DDoS protection standard? ›

Enable DDoS IP Protection on a public IP address
  1. Select Create a resource in the upper left corner of the Azure portal.
  2. Select Networking, and then select Public IP address.
  3. Select Create.
  4. Enter or select the following values. Expand table. Setting. Value. Subscription. Select your subscription. ...
  5. Select Create.
Mar 1, 2024

How do I enable application gateway in Azure? ›

Step 1: Visit the Azure portal and search for “Application gateways” and then click “Add”. Step 2: After this, fill in all the basic details such as the resource group, autoscaling details, and virtual network. Also create a new VNet, if it does not exist before, and then click on “Frontends”.

How do I enable AIP o365? ›

Navigate to the Office 365 Admin Center. From the left menu, choose Settings > Services & add-ins. In the list of apps on the right, choose Microsoft Azure Information Protection. (Formerly it was Microsoft Azure Rights Management).

Top Articles
Latest Posts
Article information

Author: Dan Stracke

Last Updated:

Views: 6059

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Dan Stracke

Birthday: 1992-08-25

Address: 2253 Brown Springs, East Alla, OH 38634-0309

Phone: +398735162064

Job: Investor Government Associate

Hobby: Shopping, LARPing, Scrapbooking, Surfing, Slacklining, Dance, Glassblowing

Introduction: My name is Dan Stracke, I am a homely, gleaming, glamorous, inquisitive, homely, gorgeous, light person who loves writing and wants to share my knowledge and understanding with you.