Basic FAQ about SHIELD DRM
Service Related
Q1. What is SHIELD DRM?
Cloud-native DRM (Digital Rights Management) service that provides document security optimized for the Microsoft 365 environment.
Automatically convert existing DRM documents to MIP (Microsoft Information Protection) documents to enable cloud collaboration (viewing/editing/co-authoring).
Q2. What are the main features?
- Providing compatibility through DRM ↔ MIP conversion (including BYOK/HYOK)
- Optimization of cloud collaboration tools such as Teams, OneDrive, and SharePoint
- Policy Linkage and Operational Visibility (Policy Establishment and Application Linkage)
Q3. What is the actual usage flow?
When you upload a file to Teams/OneDrive/SharePoint, the MIP label will be automatically applied after a certain period of time.
When applied, the modifier will show 'SharePoint app', and at the bottom of the document, 'Protected by SHIELD DRM' will be displayed.
You can upload and use the DRM document immediately without any release.
Q4. What should be prepared before the introduction?
(1) Administrator Permissions/License (Global Administrator·E3 Recommended)
(2) MIP Label Creation/Publishing
(3) Confirm Tenant Name
(4) Security365 Portal Sign Up/Settings
(5) Firewall allowed URL registration is required
Q5. What is Microsoft Throttling and what impact does it have?
Throttling is a mechanism by which Microsoft applies rate limiting to API requests, queries, networks, etc., for service stability and fair usage.
Since it may be limited during bulk processing/bursting, operational considerations such as retry and backoff strategies are necessary.
Q6. SharePoint Add-In is being discontinued, how do we respond?
Microsoft will terminate ACS (Azure Access Control Service) and SharePoint Add-In on 2026-04-02.
Accordingly, it is necessary to switch to the Event Receiver method, and transition to the migration procedure of the SHIELD DRM management page (check → consent → execute).
Authentication/Integration
Q7. Where can I check the 'App Authentication Information (App ID + App Secret)', and how do I apply it in the DS management console?
Admin page → Settings → App Credentials, copy the security token combined with the App ID and App Secret, and use it in the custom policy of the DS management console.s365_app_dataUse it by pasting it into the item.
- Applicable Version (DS Console Module)
SCPD_DS365.dll6.0.3.24 or higherSCPD_DS36564.dll6.0.3.24 or higher
Reference link
- Pre-implementation Required Checks →Preparation Requirements
- Actual Usage Procedure →Usage Instructions
- Operational Issues →MS Throttling Guide
- Policy Change Response →Migration Guide