Skip to main content

Microsoft 365

This screen isMicrosoft 365 Dedicatedis. The menu is only displayed to customers using Microsoft 365. Policies targeting Google Drive areGoogle WorkspaceSet it on the screen.

SHIELD DRM conditional policy is a feature that allows you to set and manage security policies for documents stored in OneDrive, SharePoint, and Teams.

It is possible to convert general documents to MIP documents or DRM documents, or to convert between MIP documents and DRM documents.

This guide explains the components and configuration methods of conditional policies for Cloud Storage in the Microsoft 365 environment.


Notice of Termination of Existing Add-In Method and Transition to Event Receiver​

Microsoft has discontinued ACS (Azure Access Control) and the Add-In method as of April 2, 2026.
The Microsoft365 (Add-In) menu of the SHIELD DRM management page isReplaced with Event Receiver menuIt has been done.
→ Policies registered with the existing Add-In method are now through the Event Receiver method.Data MigrationIt has been done.
→ After April 2, 2026, Policies set in Add-In mode will no longer function.

Existing Add-In Method:

  • .appInstall the file on each SharePoint site to receive events
  • Installation and management are required for each site.
  • Authentication and Authorization Control through ACS (Azure Access Control)

Event Receiver Method:

  • Structure for Directly Receiving Events in a Cloud Environment
  • Central management without a separate add-in installation process
  • Receive file events (creation, modification, movement, etc.) from SharePoint and OneDrive in real-time.

Terminology整理​

  • ACS (Azure Access Control Service): It is a legacy app, and currently, PowerShell scripts have been registered for each tenant during the SHIELD DRM setup.
    • Multi GEO sites require the registration of PowerShell scripts for each domain (a domain is added when a GEO is added).
  • Add-In : .appIt is provided as a file, and if registered in the tenant's add-in catalog, the add-in can be installed on the tenant's site.
    • To receive events, installation is required on each site.
  • RER(Remote Event Receiver) : Currently running as an Azure Service and implemented in .NET using the SharePoint CSOM (Client-Side Object Model) library.

Cloud Storage Conditional Policy Components​

SHIELD DRM Admin Page조건부 정책 > Cloud Storage > Microsoft 365Click on the menu to access.

Policy List Table Structure​

  • **Priority:**Indicates the order of policy implementation.
  • **Policy Name:**This is the unique name of the policy.
  • **Description:**The purpose of the policy or a brief description.
  • **Members:**Specify the users, groups, or policy groups to which the policy applies.
  • **Target document:**Document types to which the policy applies (General Document, DRM Document, MIP Document). If security level (C/S/O) conditions are set, those conditions will also be displayed.
  • **Document Path:**Specify the file path where the policy is applied.
  • **Document Event:**Event types in which policies are executed (file creation/modification/upload, file movement, etc.)
  • **Document House Policy:**Document encryption methods to which the policy will be applied (encrypted with MIP, document deletion, document decryption)
  • **Revised date:**This is the date when the policy was last modified.

How to Register Conditional Policies for Cloud Storage​

1. Policy Registration​

Click the [Policy Registration] button to enter the policy creation screen.

2. Enter Basic Policy Information​

  • Policy Name (required): Enter the unique name of the policy.
  • Policy Description: You can enter the purpose of the policy or a brief description.
  • Designating Members (required) :
    • Select the user or group to which the policy will be applied.
    • [All users], specific users, groups, or policy groups can be specified.
  • Specify Document Type (required) :
    • Select the document type to which the conditional policy will be applied (General Document / DRM Document / MIP Document).Multiple selections availabledoes.
    • Each document type is displayed with a selectable extension area ("box") divided according to the applicable execution policy as follows.
Target Document TypeExposed Extension BoxAttachable Execution Policy in the Box
General DocumentMIP Supported ExtensionsEncryption with MIP / Document Deletion
General DocumentRemovable Extensions (New)Document Deletion
DRM DocumentDRM Exclusive Extension (New)Document Decryption / Document Deletion
DRM DocumentSupported extensions for both DRM and MIPEncrypt with MIP / Decrypt document / Delete document
MIP DocumentMIP Supported ExtensionsDocument Decryption / Document Deletion

Please check the exact supported extension list for each box in the extension specification area of the policy registration/editing screen in real-time. (The list may be added or adjusted based on the SHIELD DRM client verification results.)

  • By specifying the scope as "All General/DRM/MIP Documents," the extensions of all boxes exposed for that document type are applied together.
  • Some execution policies cannot be attached to specific box extensions (e.g., encryption with MIP is removable and does not apply to DRM-only boxes). If you attempt to save with such a combination, a notification popup will inform you of the excluded extensions before saving. The policy itself will save and execute normally, and only the extensions that cannot be attached will be automatically excluded.
  • Document Security Level Conditions (C/S/O) :
    • You can additionally specify the C/S/O security level (label) conditions below the document type selection.Multiple selection availabledoes.
    • If no grade is selected, the entire grade will be subject to the same as before (backward compatibility).
    • The grade ID and label ID are mapped as a pair and are judged together — the grade and label information of the target document must match completely for the policy to be applied.
    • Documents matched to the grade conditions will have the enforcement policies set in the corresponding policy (encrypted with MIP / document deletion / document decryption) applied as is.

(+) Additional settings when selecting the specified DRM document:

1. Check Creator Information

- Verify if the document creator is the same as the logged-in user
- Options: Same / Not the same

2. DRM Document Encryption Type

- Choose from DAC(ACL), MAC(Category), GRADE(Level)
- Depending on the selected type, related ID can be entered

3. DRM Document Permission Assignment

- Check document permissions for the logged-in user, creator, and added groups
- Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Expiration Date

4. Specify Extension

- Specify the extension of the target DRM document
  • Document Path Specification(Required):
    • You can specify a specific folder or the entire path within the three types of storage.
      • OneDrive
      • SharePoint
      • Select Teams/Channels
warning

To apply a policy to a specific folder in OneDrive, enter the full folder path based on the OneDrive root instead of just entering the folder name.

  • example

    • right below root공용Folder:root:/공용
    • 문서below공용Folder:root:/문서/공용 :::
  • Document Event Specification(required):

    • Set the event for the policy to be executed.
    • Both events can be selected simultaneously, and individual execution policies can be set for each event.
      • File Creation/Modification/Upload
      • File Move

3. Setting Conditions​

  • **Time:**You can specify the time zone in which the policy will be applied.
    • 시간 제한 없음If you select __PH_0__, the policy will always be applied.
    • 등록된 시간에서 선택You can specify a specific time zone through __PH_0__.
    • You can set exception times so that the policy does not apply during specific time zones.

4. Document Execution Policy Settings​

  • The document enforcement policies that can be set in the Cloud Storage policy are as follows:
    • **Encryption with MIP:**Encrypts the document with the specified MIP label.
    • **Document Deletion:**The document will be deleted and will be completely removed without moving to the recycle bin.
    • **Document Decryption:**Decrypting the document and converting it to a regular document.

5. Policy Settings​

  • You can set the usage and validity period of the policy.
  • Usage Status: You can set the activation or deactivation of the policy through the toggle button.
  • Expiration Date: You can specify a start date and an expiration date, and the expiration date will무기한You can set it to.

6. Save and Complete​

  • When all settings are complete,저장Click the button.
  • Registered in the policy list, and thereafterEdit/DeleteIt is possible.

Editing Conditional Policies for Cloud Storage​

  • You can click on the policy to edit in the policy list to change the detailed settings.
  • When changing the order of policies, the priority is reset.

Caution​

  • The policy name must be unique and cannot be duplicated.
  • Mandatory fields (*) must be filled in for the policy to be saved.
  • The extension box displayed for each document type is different, and the attachable execution policies vary, so you need to check and set them in the policy registration screen.
  • When the scope is specified as "All X documents," extensions that are incompatible with the selected execution policy may be automatically excluded upon saving (a notification popup will be displayed before saving).
  • If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
  • Items with higher priority in the policy will be executed first.
  • When editing the policy, the changes will be applied by clicking the save button.
  • The policies set on this screen apply only to the Microsoft 365 environment. Google Drive documents do not have조건부 정책 > Cloud Storage > Google WorkspaceThe policy will be applied.