Skip to main content

Mip Document Control

warning

Please be informed that there are some restrictions on data access.
Detailed information about MIP document control features isnextYou can check it at.

Output Print Marking

Overview

  • Apply document security print marking when outputting MIP documents.

Applying Print Marking When Outputting MIP Documents

DS_MIP_INITItem Settings

{
"aipDoc":{
"marking":"use"
}
}

Constraints

  • In MIP Label (RMS/intune), output permissions must be granted in advance.
  • Marking Restrictions When Viewing MIP Documents in Teams or Web App

Right-click release

Overview

  • Users can use the right-click menu to release the MIP document and convert it to a regular document.
    • Right-click menu related links
info

In previous versions of the related module below, MIP release was possible regardless of the ztcap policy, but the MIP release function has been changed to be released according to the ZTCAP policy as a standard feature.

danger

To release the Mip document, the ztcap policy is required.

  • Please refer to the explanation of the ztcap policy settings below and add any necessary information.
    • The explanation of the basic ztcap policy is omitted.
  • If there is no policy, the Mip document release will fail.
  1. Select Mip document from the target document
  • All Mip document release policy - Select all Mip documents
  • When releasing a specific MIP document - After selecting the designated MIP document -> Assign label -> Select specific MIP label (multiple selection possible)\
    img
  1. Document Events
  • Right-click the mouse and click the [Release Mip Document] menu.
    img
  1. Execution Policy
  • Mip document release selection
    img

After selecting a policy, you can click the corresponding icon to view and edit (modify) the policy in JSON code format.

{
"name": "[개발]Mip해제정책",
"description": "모든 Mip문서 해제하는 정책",
....
"enforcementAttributes": [
{
"order": 0,
"category": "MIPRemove" // category에 MIPRemove로 추가
}
],
"decisionFactors": [
{
"category": "document",
"targets": [
{
"type": "mip",
"use": true,
"operation": "AND"
}
]
},
{
"category": "storage",
"targets": [
{
"type": "local",
"use": true,
"operation": "OR",
"info": {
"folder": [
"*"
]
}
}
]
},
{
"category": "fileEvent",
"targets": [
{
"type": "local",
"use": true,
"operation": "OR",
"info": {
"event": [
- "RButtonClickLabelRemove" // event를 RButtonClickLabelRemove로 지정
]
}
}
]
}
]
}


MIP icon display policy on/off

Overview

  • This is a custom policy that allows you to turn the display of the MIP icon on/off as a policy.
IDDSICON_NOT_USE_AIP_ICON
TYPECheck On/Off
Policy Value FormatCheck On/Off
DescriptionMIP icon display usage (1: not in use, 0: in use)
Policy Value1 (or Check)
scscDSICON_NOT_USE_AIP_ICON.scsc

Application Method

  1. Module Patch
  2. Custom Policy Settings and Fetching Policies

Notification window call when viewing a read-only document

info

Notification appears when viewing read-only Mip documents

When a read-only document is accessed, display a popup after viewing to inform that this document is read-only (ex, This document is read-only. Please edit the document by saving it under a different name.)

Overview

  • Read-only MIP documents inform users that they are non-editable documents and encourage them to save under a different name before editing.

Description

  • When opening the Mip document, if it opens as a read-only document, the following notification message appears.
    img

Policy

  1. The Mip Init policy must have the option value (NotifyReadOnlyDoc key) added as below to function. DS_MIP_INIT policy link
{
"s365_url": "https://devlogin.softcamp.co.kr/",
...(생략)...
"custom": {
...
"NotifyReadOnlyDoc": "use"
},
...(생략)...
}

Constraints

  • For documents opened through onedrive, sharepoint, and teams, the file path is generated as a URL, so it is not possible to determine whether it is a Mip document through the Mip SDK, and therefore no notification window appears.Therefore, a feature that operates only on local files.
  • This feature works when opening attached documents that are downloaded locally from Outlook, but it is not supported when opening directly from cloud links such as SharePoint. (For the same reason as above.)

Notification Message

img


Third-party Tenant MIP Document Viewing Confirmation Guide

Overview

A user logged in with a company accountDocuments protected by MIP (Microsoft Information Protection) labels from other companies' tenantswhen opening,**"Documents protected by other companies may have restricted access. Do you still want to proceed?"**This is a feature that first displays a confirmation dialog to allow the user to directly choose whether to open or block.

Reason for Needing This Feature

MIP label protects the document**Company (Tenant)**Permissions are grouped by unit. Therefore, company employees are associated with clients and partners, etc.MIP document protected by third-party tenantIf you receive it and open it, you will not be able to normally view the document as it cannot pass the protection policy with your company account.

The problem is**In the existing operation, the user could not identify the cause of this situation.**is the point.

  • When opening third-party MIP documents, MIP authentication fails.Blank Screen · Unknown ErrorIt has ended.
  • In some paths,"The validity period has expired"sameInaccurate messagewas displayed, leading the user to misunderstand the cause.
  • As a result, inquiries (VOC) such as "The document is corrupted / The product malfunctions" have been repeatedly received.

This feature is designed to eliminate this confusion at the time of opening the document.**"This document is identified in advance as a document protected by another company."**to provide accurate guidance, and still allows the user to choose whether to open it.

Operation Method — "Confirm and Select" Instead of Forced Blocking

This feature does not block third-party documents under any circumstances.Yes / No confirmation dialogIt leaves the judgment to the user.

  • YesSelect → Proceed with document viewing as before (actual viewing may be restricted due to third-party protection).
  • No / Close Window (X) / No Response→ Document viewingBlockdoes.
info

Summary: If an employee of our company opens a document protected by MIP from another company's tenant, a confirmation window will first appear stating, "This document is protected by another company, and access may be restricted. Do you still want to proceed?" The access will either continue or be blocked based on the user's yes/no selection.

Application Entry Point

This feature allows the user to open the document.Two PassagesIt is applied.

#Entry PointUser Action
1Explorer double-clickWhen double-clicking an Office document in Windows Explorer to open it
2Office 'Open' dialog boxWhen selecting and opening a document in the [File → Open → Browse] dialog box of Word / Excel / PowerPoint
warning

Opening methods other than the two paths above —Drag & Drop · Select from Recent Documents in Office · Acrobat (PDF)— is excluded from the scope of this feature (see the limitations below).

User Screen (Notification Confirmation Window)

If judged as a third-party tenant MIP document, the following will apply:Yes / No confirmation dialogThis will be displayed.

┌─────────────────────────────────────────────┐
│ Document Security │
│ │
│ '<File Name>' is protected by MIP labels of │
│ another tenant. Do you still want to open it?│
│ │
│ [ No(N) ] [ Yes(Y) ] │
└─────────────────────────────────────────────┘

The button is on the screenNo / YesIt will be arranged in order (same as the existing product message window UI).

User Selectionresult
No (N)Access to the document is blocked.
Yes (Y)Proceeding with document viewing (actual viewing may be restricted due to third-party protection).
Close Window (X) / Unresponsive (Auto Close)Safe BlockingProcessing. (To ensure that 'Yes' is not automatically selected, it defaults to 'No' in case of no response.)
  • The text does not contain the full path.File name onlyThe displayed path information is not exposed.

The guidance text is provided in six languages: Korean, English, Japanese, Chinese, German, and Russian, and is displayed according to the system locale (if the language resource is not available, it will be displayed in English).

Action Scenario Summary Table

#situationOperation Result
1Third-party Tenant MIP DocumentOpen in Explorer/Office + User**'Yes'**Display confirmation window → Proceed to view (Actual viewing may be restricted due to third-party protection)
2Third-party Tenant MIP Document+ User**'No' / X / No response**Display confirmation window →Access Blocked
3Our MIP Document(No company authorization)Do not intervene in this function →Fallback to the original message(Issued GUID = Company GUID, not Third Party)
4General Document / Company Authorization Normal Document / Non-MIP DocumentDo not intervene in this function → View normally as usual
5Products Excluding Third-Party Identification CoreIdentification Core Absence →No Operation, all documents open the same as before
6Drag and Drop / Recent Documents List / Open with Acrobat (PDF)Apart from the application of this feature — Display app errors and login windows as before without a notification window (see limitations)

This feature isOnly when it is a third-party tenant MIP documentIntervenes (Scenario 1·2). Other than that (company documents·general documents) are not blocked or guided at all, so there is no impact on existing operations.

Support Document Types

This feature isOffice 'Open' dialog entry point for Office documentsIt operates on the following: Supported Office versions/types are Word, Excel, and PowerPoint of 2016 / 202X.

  • Explorer Double Click Entry PointThis product operates on the document extensions it supports.
  • PDF is not supportedis (see the restrictions below).

Constraints

Unsupported document opening paths (Drag and drop · Recent documents · Acrobat PDF)

There are four main ways to open a document, and this feature is one of them.**Only two paths with 'blocking point before opening'**I apply.

Open Pathsupport
a. Double-click in the explorersupport
b. Select in the Office 'Open' dialog boxsupport
c. Open in Office by Drag & DropUnsupported
d. Open by selecting from the recent documents list in OfficeUnsupported
(Open with Acrobat (PDF))Unsupported

There are two supported paths (Explorer double-click · Office 'Open' dialog) where a confirmation dialog can be displayed before the document is opened, but there are no such pre-blocking points in the drag-and-drop, recent documents, and Acrobat (PDF) paths, making it currently difficult to support safely.

User Impact: c·d·Acrobat path opens third-party MIP documents, the guidance window for this feature does not appear, and the error/login window of the respective app (Office/Acrobat) appears as before. It is a third-party document.**Detection (Recognition)**It is possible to do it itself, but for the above reason, "safely stopping before opening" is currently not possible.

Other Constraints

  • Products Excluding Third-Party Identification Core: Since there is no third-party identification core, guidance and blocking do not operate, and all documents open as they did before (intended no action).
  • Multilingual Notification Message Distribution Dependency: Guide Message Resource(ResUI*.rc6 types, 6.0.0.33) must be distributed together as an SDK installation package. In non-distributed environments, it will be displayed with the default English phrases.
  • Safety Lockout on Identification Failure: In uncertain situations such as unresponsive pop-ups or display failures,Safely to the blocking sideProcessing.
  • DS365 Certification Status Dependency: Since the tenant GUID of our company is needed for the judgment of our company/other company, the DS365 agent must be in a normal login and MIP authenticated state to be accurately judged.