MIP integration workflow for protecting co-authored or auto-save enabled document with Labelinfo

Prev Next

. You can use Labelinfo in MSIP labeled classifications to support reading MIP label information or metadata in co-authored or auto-save enabled documents.

  1. Register the client application in Azure Active Directory. After registering the new application, obtain the Application (client) ID and Directory (tenant) ID from the overview menu option generated during provisioning Enterprise Application for Trellix DLP usage. Also, obtain the Client Secret Code that is created during application registration on the Azure portal. You will need these values for configuring the registered servers from ePO - On-prem later. For more information, see KB91833.

    These credentials have an expiration date and must be renewed.

  2. Preconfigure the Application permissions required for MIP service rights. Also, configure the permissions for these services in the Azure portal:

    • Azure Rights Management Service

    • Microsoft Purview Information Protection Sync Service

  3. Configure sensitivity labels and label actions in Microsoft Purview compliance portal. For information about sensitivity labels and how they can help you protect your organization's data, see https://learn.microsoft.com/en-us/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide.

  4. Obtain the Label IDs of sensitivity labels needed to create MSIP labels (Labelinfo stream). Trellix DLP is provisioned to read metadata of the protected or unprotected Word, PowerPoint, Excel, and Outlook documents and identifies the MIP tagged Microsoft 365 files through the label ID included in the classifications. For more information about getting label IDs, see https://learn.microsoft.com/en-us/powershell/module/exchange/get-label?view=exchange-ps.

  5. In ePO - On-prem, configure the registered Azure server to connect and use AIP services. Trellix DLP Network uses MIP credentials for decryption and these credentials are verified during configuration. Information protection is applicable to both Email Protection and Web Protection rules. Trellix DLP Network identifies the AIP encrypted content and decrypt both documents and emails protected by the configured MIP tenant for content inspection. If a protected email also contains protected documents, both the email and documents are decrypted. Both MS Office documents and files protected manually via the Configure the registered Azure server in ePO - On-prem for Microsoft Information Protection with Trellix DLP NetworkMIP classify and protect plugin are supported. For more information, see .

  6. .Create and apply MSIP labeled classifications mapped to LabelInfo stream using Custom Property (Trellix DLP Network)

  7. Any data violation is shown in the Incident Manager.