Skip to main content

External Company Connection

External Company ConnectionThe menu is a screen for connecting and managing external companies that exchange MIP documents (mutual approval relationship). Only between companies where the connection is established, mutual sensitivity label queries and document conversions are allowed.

A connection is established when one company requests it and the other company approves it. The MIP documents of companies that are not connected are not subject to label lookup or transformation. Connection is a prerequisite for this feature and serves as a safeguard to prevent the security documents of unapproved companies from being opened.


Connection Concept​

Microsoft's MIP (Sensitivity Labels) security is closed at the company (Microsoft 365 tenant) level, so documents with MIP from external companies cannot check what labels are applied. "External Company Connection" is a feature that allows two companies exchanging documents to register and approve each other, permitting the retrieval and conversion of MIP document labels only between the connected two companies.

itemcontent
establishmentIt is established when one company requests and the other company approves. It cannot be established with just one side's request.
EffectRegardless of the request directionboth sidesYou can view each other's labels and convert documents.
unitIt is a 1:1 relationship between two companies. You can connect with multiple companies, and each connection is established and dissolved independently.
releaseIf one side is released, both sides will be disconnected. To reconnect, you must obtain approval from the other company again.

Connections do not lead to other connections. For example, even if Company A is connected to Companies B and C respectively, Companies B and C are not connected to each other, nor are they indirectly connected through Company A.


Prerequisites​

Participating in the connectionboth companiesYou must meet the following conditions. If only one side is met, it cannot be used.

#condition
1Both companies use Microsoft 365
2Both companies have completed Azure app registration.
3Both companies have completed SHIELD ID registration and app registration.
4Both companies are in a state of availability for SHIELD DRM cloud usage.
5Both companies use DS6

Azure app registration (Condition 2) is not required to establish the connection itself. However, the label lookup and document conversion for that company may fail, and it will be marked as "Needs Verification" in the connection list. Please refer to "Connection List and Status" below.

The prerequisites for using screens other than this are as follows.

  • You must be logged in to the SHIELD DRM admin page with administrator privileges.
  • **Both companies' administrators should be able to use the "External Company Connection" menu.**The requesting party is needed to send the request, and the receiving party is needed to approve the request. If the menu is not visible, please check the administrator role permission settings.
  • It is provided in a SaaS (cloud) environment.

Screen Configuration​

SHIELD DRM Admin Page연동 관리 > 외부 회사 연결Click on the menu to access. The screen is divided into two areas.

areacontent
Received requestList of connection requests sent by external companies and승인 · 반려button
Linked ListAll connections and their status (Pending Approval · Connected · Rejected · Disconnected) that this company is involved in

Both areas are always displayed, and if the list is empty, a guide message appears in its place.

Extra ID​

Extra IDis the company identifier registered with SHIELD ID. External companies need this value to request a connection to this company, and설정 > 앱 인증 정보You can check and copy from the menu.


Connection Procedure​

Step 1. Extra ID Delivery — Company to Receive the Request​

  1. The administrator of the company receiving the request설정 > 앱 인증 정보in the menuExtra IDCopy.
  2. Deliver the copied value to the administrator of the company requesting the connection.

The value can only be transmitted in this one direction. The requesting side is the counterpart company’sExtra IDYou do not need to know. This is because the name of the counterpart company is displayed in the "Received Request."

Step 2. Connection Request — Requesting Company​

  1. "Linked List" of+ 연결 요청Click the button.
  2. External company receivedExtra IDenter요청Click the button.
  3. If requested, the company will be on the connection list.with the company nameIt will be added with the status "Pending Approval." Verify the target with the displayed company name, and if it is not the intended company, withdraw the request. Please refer to "Withdraw Request and Disconnect" below.

To connect to multiple companies, you need to repeat the request for each company. You cannot specify multiple companies in a single request.

Step 3. Approval · Rejection — Requested Company​

  1. The administrator of the requested company checks the pending requests in the "Received Requests" area of the "External Company Connection" screen. There are no separate notifications when a request comes in, so please check this area directly after providing the Extra ID.
  2. After confirming the requester by company name,승인or반려Click the button.
  3. You can enter the reason for withdrawal (optional).The reason you entered will be displayed as is to the administrator of the opposing company.
  4. Once approved, both companies can query each other's labels and convert documents from that point onward.

The approval and rejection results will not be notified separately. The administrator of the requesting party checks the results through the status change of the connection list (Connected · Rejected).


Linked List and State​

The connection list shows all connections that this company is involved in.

itemExplanation
Company NameThis is the name of an external company.Extra IDis automatically retrieved and is not entered by the administrator.
Extra IDThis is an identifier for an external company. If it is long, it will be displayed in a shortened form, and the full value can be checked in the tooltip.
statusThe current status of the connection. If there is a reason for rejection, it will be displayed next to the status.
Final ChangeThis is the time when the status was last changed.
statusmeaningLabel Lookup · Document ConversionPossible tasks
Pending ApprovalThe request has been sent, and the other company has not yet responded.impossibleRequest Count (취소)
ConnectedThe other company has approved and the connection has been established.possibleDisconnect (해제)
RejectedThe counterpart company has rejected the request. If there is a reason, it will be displayed together.impossibleRe-request possible
releasedThe state where one side has disconnected.impossibleRe-request possible
  • The status is displayed from the perspective of the requesting side. Requests sent by external companies are processed in the "Received Requests" area and appear in the connection list after approval.
  • There is no deadline for pending approval. If there is no response for a long time, you can withdraw the request.
  • The history of rejected·released requests remains in the list. If you request again from the same company, a new row will not be created, and the status of the existing row will change.
  • The list provides status filters and sorting.

Display of availability status in "Connected" state​

In the "Connected" state, the results of checking whether label queries and document conversions can actually be used with the company are displayed together.

  • **If availability is confirmed:**A notice that label retrieval and conversion are available will be displayed next to the status.
  • **If not confirmed:**It will be marked as "Confirmation Required." This is usually the case when the Azure app registration of the external company has not been completed, and the label lookup for that company may fail. The external company needs to complete the Azure app registration to resolve this.

Request Cancellation and Disconnection​

Request Cancellation​

in the row with the status "Pending Approval"취소You can withdraw the sent request by clicking the button.

  • It is only possible until the other company responds.
  • If you withdraw, the corresponding request will also disappear from the other company's "Received Requests."

Disconnect​

in the row with the status "Connected"해제Click the button.

  • releaseboth companiesThe connection is lost, and the company's documents are excluded from the conversion target. It also disappears from the company list on the label lookup screen.
  • To reconnect with a released company, you must request again and obtain approval from the counterpart company.
  • If there are conditional policies referencing the company you want to release, the number of those policies will be indicated at the confirmation stage. It is recommended to first organize the conditional policies referencing that company before releasing it.
  • The release applies only to the specific connection. Connections with other companies are not affected.

View MIP labels of connected external companies​

If the connection is establishedLabel Lookupscreen(MIP 레이블 조회You can view the sensitivity labels of external companies in the menu.

  • screenCompany Selection DropdownThis will be added. The default is the logged-in company, and only external companies that are in the "Connected" state will appear in the list.
  • When you select an external company, a list of that company's sensitivity labels will be displayed. For the basic usage of the screen, please refer to the above "Label Inquiry" guide.
  • 새로 고침A button and the last query time are provided, allowing you to check the latest list while switching companies.
  • Disconnected companies will disappear from the dropdown.
  • If the Azure app registration of the external company is not completed, the connection will be maintained, but label retrieval may fail, and the reason for the failure will be displayed on the screen.
  • The permission for the "MIP Label Inquiry" menu is separate from the permission for the "External Company Connection" menu. Administrators who have established a connection but have this menu hidden cannot check the labels.

**Each company has a different label naming system.**Even documents of the same type may have different label names depending on the company. Before specifying transformation rules in the conditional policy, please check the labels of both companies on this screen. Labels are not automatically mapped.


Constraints​

itemcontent
Specify Connection TargetReceived from external company administratorExtra IDYou can only request via input. Company list retrieval or search is not provided. This is to prevent revealing which companies use SHIELD DRM.
Scope of ConnectionThe connection is only valid between the two companies and does not lead to other connections. The connection established by the connected company with a third company will not be displayed on this company's admin page.
Connection CountThere is only one connection for each pair of companies. There is no limit to the number of companies that can be connected.
NotificationNo separate notifications will be provided for received requests. You must check directly in the "Received Requests" area of the "External Company Connection" screen.
Approval Waiting DeadlineThere is none. The request does not expire, and the requesting party can withdraw it.
ResumeThe history of rejected·released cannot be deleted from the list. If you re-request, the status of the existing row will change.
Provided EnvironmentIt is provided in a SaaS (cloud) environment. On-premises connections are not supported.

Problem Solving​

Symptoms · Guidance TextCheck · Action
"Cannot confirm Extra ID"Please re-request after confirming with the external company administrator whether the entered value is correct.
"This is the Extra ID of this company."This is the case where the company entered its own value. Please enter the value received from the external company.
"This is a company that has already been requested."Check the progress status in the "Pending Approval" row of the linked list.
"The other party has already requested."This is the case when the other company requests first. The connection is established when approved in "Received Requests."
"Already connected company."This company is already in a "Connected" state. Check the status in the connection list.
It is "Connected," but the label retrieval has failed.Check the "Confirmation Required" status of the company in the linked list, and request the external company to complete the Azure app registration.
The "External Company Connection" menu is not visible.This is the case when this menu is set to hidden in the administrator role permissions. Please check the company's permission settings.

Caution​

  • **If you disconnect, the company's documents will be excluded from the conversion target.**Before the release, please check the conditional policy referencing that company.
  • **The reason for rejection is displayed as is to the administrator of the opposing company.**Do not use for internal memo purposes.
  • Extra IDPlease only share with the company that requests the connection. Companies that know the value can send connection requests. However, the connection will not be established until approved.
  • Verify the target by the company name displayed in the connection list immediately after the request. If you requested incorrectly, you can retract it before the other party responds.