Microsoft 365
This screen isMicrosoft 365 Dedicatedis. The menu is displayed only for customers using Microsoft 365. The policy targeting Google Drive isGoogle WorkspaceSet it on the screen.
SHIELD DRM conditional policy is a feature that allows you to set and manage security policies for documents stored in OneDrive, SharePoint, and Teams.
You can convert regular documents to MIP documents or DRM documents, or perform mutual conversion between MIP documents and DRM documents.
This guide explains the components and configuration methods of conditional policies for Cloud Storage in the Microsoft 365 environment.
Notice of Termination of Existing Add-In Method and Transition to Event Receivers
Microsoft has discontinued ACS (Azure Access Control) and the Add-In method as of April 2, 2026.
The Microsoft365 (Add-In) menu of the SHIELD DRM management page isReplaced with Event Receiver MenuIt has been done.
→ Policies registered with the existing Add-In method will be converted to the Event Receiver method.Data MigrationIt has been done.
→ After April 2, 2026, Policies set in Add-In mode will no longer function.
Existing Add-In Method:
.appInstall the file on each SharePoint site to receive events- Installation and management are required for each site.
- Authentication and Authorization Control through ACS (Azure Access Control)
Event Receiver method:
- Structure for Directly Receiving Events in a Cloud Environment
- Central management without a separate add-in installation process
- Receive file events (creation, modification, movement, etc.) from SharePoint and OneDrive in real-time.
Terminology整理
- ACS (Azure Access Control Service): It is a legacy app, and currently, PowerShell scripts have been registered for each tenant during the SHIELD DRM setup.
- Multi GEO sites require the registration of PowerShell scripts for each domain (a domain is added when a GEO is added).
- Add-In :
.appIt is provided as a file, and if registered in the tenant's add-in catalog, the add-in can be installed on the tenant's site.- To receive events, installation is required on each site.
- RER(Remote Event Receiver) : Currently running as an Azure Service and implemented in .NET using the SharePoint CSOM (Client-Side Object Model) library.
Detailed description link
Cloud Storage Conditional Policy Components
SHIELD DRM Admin Page
조건부 정책 > Cloud Storage > Microsoft 365Click on the menu to access.
Policy List Table Structure
- **Priority:**It indicates the order of policy implementation.
- **Policy Name:**This is the unique name of the policy.
- **Description:**The purpose of the policy or a brief description.
- **Members:**Specify the users, groups, or policy groups to which the policy applies.
- **Target document:**Document types to which the policy applies (General Document, DRM Document, MIP Document). If security level (C/S/O) conditions are set, those conditions will also be displayed.
- **Document path:**Specify the file path where the policy applies.
- **Event Trigger:**Event types in which policies are executed (file creation/modification/upload, file movement, etc.)
- **Document Encryption Policy:**Document encryption methods to which the policy will be applied (encrypted with MIP, document deletion, document decryption)
- **Revision date:**This is the date when the policy was last modified.
How to Register Conditional Policies for Cloud Storage
1. Policy Registration
Click the [Policy Registration] button to enter the policy creation screen.
2. Enter Basic Policy Information
- Policy Name (required): Enter the unique name of the policy.
- Policy Description: You can enter the purpose of the policy or a brief description.
- Member Assignment (required) :
- Select the user or group to which the policy will be applied.
- [All users], specific users, groups, or policy groups can be specified.
- Specify target document type (required) :
- Select the document type to which the conditional policy will be applied (General Document / DRM Document / MIP Document).Multiple selection availabledoes.
- Each document type is displayed with a selection area for extensions ("box") divided as follows according to the attachable execution policy.
| Target Document Type | Exposed Extension Box | Attachable Execution Policy in the Box |
|---|---|---|
| General Document | MIP Supported Extensions | Encryption with MIP / Document Deletion |
| General Document | Deletable Extensions (New) | Document Deletion |
| DRM Document | DRM Exclusive Extension (New) | Document Decryption / Document Deletion |
| DRM Document | Supported extensions for DRM and MIP | Encrypt with MIP / Decrypt document / Delete document |
| MIP Document | MIP Supported Extensions | Document Decryption / Document Deletion |
Please check the exact supported file extension list for each box in the extension specification area of the policy registration/editing screen in real-time. (The list may be added or adjusted based on the SHIELD DRM client verification results.)
- By specifying the scope as "All General/DRM/MIP Documents," the extensions of all boxes exposed for that document type are applied together.
- Some execution policies cannot be attached to certain box extensions (e.g., encryption with MIP is removable and does not apply to DRM-only boxes). If you attempt to save with this combination, a notification popup will inform you of the excluded extensions before saving. The policy itself will be saved and executed normally, and only the extensions that cannot be attached will be automatically excluded.
- Target document security level (C/S/O) conditions :
- You can additionally specify the C/S/O security level (label) conditions below the document type selection.Multiple selection availabledoes.
- If you do not select a grade, the entire grade will be subject to the same as before (backward compatibility).
- The grade ID and label ID are mapped in pairs and are judged together — the grade and label information of the target document must match completely for the policy to be applied.
- Documents matched with the grade conditions will have the enforcement policies set in the corresponding policy (encrypted with MIP / document deletion / document decryption) applied as is.
(+) Additional settings when selecting the specified DRM document:
- Check Constructor Information
- Check if the document creator is the same as the logged-in user
- Option: Same / Not Same
- DRM Document Encryption Types
- Select from DAC(ACL), MAC(Category), GRADE(Rank)
- You can enter the related ID depending on the selected type.
- DRM Document Permission Assignment
- Check document permissions for logged-in users, creators, and added groups
- Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Validity Period
- File Extension Specification
- Specify the extension of the target DRM document
- Document Path Specification(Required):
- You can specify a specific folder or the entire path within the three types of storage.
- OneDrive
- SharePoint
- Select Teams/Channels
- You can specify a specific folder or the entire path within the three types of storage.
- Document Event Specification(required):
- Set the event for the policy to be executed.
- Both events can be selected multiple times, and individual execution policies can be set for each event.
- File Creation/Modification/Upload
- File Move
3. Setting Conditions
- **Time:**You can specify the time zone in which the policy will be applied.
시간 제한 없음If you select __PH_0__, the policy will always be applied.등록된 시간에서 선택You can specify a specific time zone through __PH_0__.- You can set exception times so that policies do not apply during specific time zones.
4. Document Execution Policy Settings
- The document enforcement policies that can be set in the Cloud Storage policy are as follows:
- **Encryption with MIP:**Encrypts the document with the specified MIP label.
- **Document Deletion:**The document will be deleted and will be permanently removed without moving to the recycle bin.
- **Document Decryption:**Decrypting the document and converting it to a regular document.
5. Policy Settings
- You can set the usage and validity period of the policy.
- Usage status: You can set the activation or deactivation of the policy through the toggle button.
- Expiration Date: You can specify a start date and an expiration date, and the expiration date will
무기한You can set it to.
6. Save and Complete
- When all settings are complete,
저장Click the button. - Registered in the policy list, and thereafterEdit/DeleteIt is possible.
Editing Conditional Policies for Cloud Storage
- You can click on the policy you want to edit from the policy list to change the detailed settings.
- When changing the order of policies, the priority is reset.
Caution
- The policy name must be unique and cannot be duplicated.
- Required fields (*) must be filled in for the policy to be saved.
- The extension box displayed for each document type is different, and the attachable execution policies vary, so you need to check and set them on the policy registration screen.
- If the scope is specified as "All X documents," extensions that are not compatible with the selected execution policy may be automatically excluded upon saving (displaying a notification popup before saving).
- If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
- Items with higher priority in the policy will be executed first.
- When editing the policy, the changes will be applied by clicking the save button.
- The policies set on this screen apply only to the Microsoft 365 environment. Google Drive documents do not have
조건부 정책 > Cloud Storage > Google WorkspaceThe policy will be applied.