Azure Information Protection- part 4: the AIP Viewer-client

In part 3, I discussed the end user side of Azure Information Protection: How can users classify and label document by using the Microsoft Office apps. To get the ribbon inside the office apps, as mentioned before, you need to install the AIP client on your Windows device. Besides the ribbon, the client also is a full client app to label content and share it with externals. It also is a viewer for other (than Office) supported formats, like a protected .pdf file (which will be a .ppdf file). You can check here which file formats are supported with the AIP client-viewer, for protection and classification.

So, what is the flow of sharing a classified and protected document with an external (or internals who weren’t part of the users in the RMS template)? Remember, a classified and protected (with RMS) document can only be shared with internal users, within your organisation, out of the box- set in the RMS template. Sometimes you want to share a document with someone outside your org. The AIP Viewer/client has shell integration, so the only thing you need to do is to right-click on your document and clic
k on “Classify and protect”.

 

The AIP Viewer/client will open you you will see the same labels as in the ribbons of your Office apps. Here you can change the classification of a document (when setting a lower classification, optionally with a justification) and you can check “Protect with custom permissions” . Then it will be possible to select permissions: like Viewer- View Only, Reviewer- View/Edit, Co-Author and Co-Owner. You set these permissions for groups of user, which you can add manually. Optionally, you can set an expiration date. After applying the settings, you can send the document to new internal users and external users, you have added.

From that moment on, you will be able to track the document. At the top of the Viewer, you see “Track and Revoke”. When you click on that button, your browser will open and you will see an overview of your document: when was it shared with others, the list of users it was shared with, who viewed, denied access, expiration date etc. There also is a timeline of activities and a map with geo locations of your viewers. At the button, in black, you see the Revoke Access button. This way, you can monitor the usage of your document and take action when needed.

 

 

There are no ribbons in, for example Adobe Reader. However, you can still label and protect .pdf files if you want. Again, the AIP Viewer/client supports several file formats. Just right-click on a .pdf file and click on “Classify and protect”.  You can now label your .pdf file or label + protect it. Meta data and optionally protection is being added to the file. With pdf files, you can see the AIP logo being added in the icon, as shown in the picture.

With the Azure Information Protection Viewer/client, users can now easily share content with others, but in a very controlled way. They intentionally need to take steps to do so. Even if a person you have shared a document with shouldn’t be allowed to view that document anymore, the user can quickly revoke access to the document.