Skip to main content

Conditional Policy - Cloud Storage (SHIELD DRM)

※ Last updated: 2026-07-15

Cloud Storage conditional policies are features that allow you to set and manage security policies for documents stored in OneDrive, SharePoint, and Teams.

It is possible to convert general documents to MIP documents or DRM documents, or to perform mutual conversion between MIP documents and DRM documents.

This guide explains the components and configuration methods of Cloud Storage conditional policies.


Notice of Termination of Existing Add-In Method and Transition to Event Receiver

Microsoft will discontinue ACS (Azure Access Control) and the Add-In method as of April 2, 2026.
The current SHIELD DRM management page's Microsoft365(Add-In) menu is in 2026Replaced with Event Receiver MenuIt is possible.
-> Policies registered with the existing Add-In method will be changed to the Event Receiver method.Data MigrationIt is possible.
-> After April 2, 2026, Policies set in Add-In mode no longer function.

Existing Add-In Method:

  • .appInstall the file on each SharePoint site to receive events
  • Installation and management are required for each site.
  • Authentication and authorization control through ACS (Azure Access Control)

Event Receiver method:

  • Structure for Directly Receiving Events in a Cloud Environment
  • Central management without a separate add-in installation process
  • Receiving file events (creation, modification, movement, etc.) from SharePoint and OneDrive in real-time

Terminology整理

  • ACS(Azure Access Control Service) : It is a legacy app, and currently, PowerShell scripts have been registered for each tenant during the SHIELD DRM setup.
    • Multi GEO usage sites require PowerShell script registration for each domain (a domain is added when a GEO is added).
  • Add-In : .appIt is provided as a file, and if registered in the tenant's add-in catalog, the add-in can be installed on the tenant's site.
    • To receive events, installation is required on each site.
  • RER(Remote Event Receiver) : Currently running on Azure Service and implemented in .NET using the SharePoint CSOM (Client-Side Object Model) library.

Cloud Storage Conditional Policy Components

Click on the Conditional Policy menu in the SHIELD DRM Admin Page to access the Cloud Storage screen.

Policy List Table Structure

  • **Priority:**Indicates the order of policy implementation.
  • **Policy Name:**This is the unique name of the policy.
  • **Description:**The purpose of the policy or a brief description.
  • **Members:**Specifies the users, groups, or policy groups to which the policy applies.
  • **Target document:**Document types to which the policy applies (General Document, DRM Document, MIP Document). If security grade (C/S/O) conditions are set, those conditions will also be displayed.
  • **Document Path:**Specify the file path where the policy is applied.
  • **Event Trigger:**Event Types Where Policies Are Executed (File Creation/Modification/Upload, File Movement, etc.)
  • **Document Encryption Policy:**Document encryption methods to which the policy will be applied (Encrypting with MIP, Document deletion, Document decryption)
  • **Revision Date:**This is the date when the policy was last modified.

How to Register Conditional Policies for Cloud Storage

1. Policy Registration

Click the [Policy Registration] button to enter the policy creation screen.

2. Enter Basic Policy Information

  • Policy Name (required): Enter the unique name of the policy.
  • Policy Description: You can enter the purpose of the policy or a brief description.
  • Member Designation (required) :
    • Select the user or group to which the policy will be applied.
    • [All users], specific users, groups, or policy groups can be specified.
  • Specify Document Type (required) :
    • Select the document type to which the conditional policy will be applied (General Document / DRM Document / MIP Document).Multiple selection availabledoes.
    • Each document type is displayed with a selection area for extensions ("box") divided as follows according to the applicable execution policy.
Target Document TypeExposed Extension BoxAttachable Execution Policy in the Box
General DocumentMIP Supported ExtensionsEncryption with MIP / Document Deletion
General DocumentDeletable Extensions (New)Document Deletion
DRM DocumentDRM Exclusive Extension (New)Document Decryption / Document Deletion
DRM DocumentSupported extensions for DRM and MIPEncrypt with MIP / Decrypt document / Delete document
MIP DocumentMIP Supported ExtensionsDocument Decryption / Document Deletion

Please check the exact supported extension list for each box in the extension specification area on the policy registration/editing screen in real-time. (The list may be added or adjusted based on the SHIELD DRM client verification results.)

  • When the scope is specified as "All General/DRM/MIP Documents," the extensions of all boxes exposed for that document type are applied together.
  • Some execution policies cannot be attached to specific box extensions (e.g., encryption with MIP is removable; it does not apply to DRM-only boxes). If you attempt to save with such a combination, a notification popup will inform you of the excluded extensions before saving. The policy itself will be saved and executed normally, and only the extensions that cannot be attached will be automatically excluded.
  • Document Security Level (C/S/O) Conditions :
    • You can additionally specify the C/S/O security level (label) conditions below the document type selection.Multiple selection availabledoes.
    • If you do not select a grade, the entire grade will be subject to the same as before (backward compatibility).
    • The grade ID and label ID are mapped as a pair and are judged together — the grade and label information of the target document must match for the policy to be applied.
    • Documents matched to the grade conditions will have the enforcement policies set in the corresponding policy (encrypted with MIP / document deletion / document decryption) applied as is.

(+) Additional settings when selecting the specified DRM document:

  1. Check Constructor Information
  • Check if the document creator is the same as the logged-in user
  • Option: Same / Not the same
  1. DRM Document Encryption Types
  • Select from DAC(ACL), MAC(Category), GRADE(Rating)
  • You can enter the related ID depending on the selected type.
  1. DRM Document Permission Assignment
  • Check document permissions for logged-in users, creators, and added groups
  • Permission types: Read, Edit, Output, Export, Release, Change Permission, Print Marking, Validity Period
  1. File Extension Specification
  • Specify the extension of the target DRM document
  • Document Path Specification(Required):
    • You can specify a specific folder or the entire path within the three types of storage.
      • OneDrive
      • SharePoint
      • Select Teams/Channels
  • Document Event Specification(required):
    • Set the event for the policy to be executed.
    • Both events can be selected simultaneously, and individual execution policies can be set for each event.
      • File Creation/Modification/Upload
      • File Move

3. Setting Conditions

  • **Time:**You can specify the time zone to which the policy will apply.
    • 시간 제한 없음If you select __PH_0__, the policy will always be applied.
    • 등록된 시간에서 선택You can specify a specific time zone through __PH_0__.
    • You can set exception times so that the policy does not apply during specific time zones.

4. Document Execution Policy Settings

  • The document enforcement policies that can be set in the Cloud Storage policy are as follows:
    • **Encryption with MIP:**Encrypts the document with the specified MIP label.
    • **Document Deletion:**The document will be deleted and will be permanently removed without moving to the recycle bin.
    • **Document Decryption:**Decrypt the document and convert it to a regular document.

5. Policy Settings

  • You can set the usage and validity period of the policy.
  • Usage status: You can set the activation or deactivation of the policy through the toggle button.
  • Expiration Date: You can specify a start date and an expiration date, and the expiration date무기한You can set it to.

6. Save and Complete

  • When all settings are complete,저장Click the button.
  • Registered in the policy list, and thereafterEdit/DeleteIt is possible.

Editing Conditional Policies for Cloud Storage

  • You can click on the policy to edit in the policy list to change the detailed settings.
  • When changing the order of policies, the priority is reset.

Caution

  • The policy name must be unique and cannot be duplicated.
  • Required fields (*) must be filled in for the policy to be saved.
  • The extension boxes displayed for each document type are different, and the attachable execution policies vary, so you need to check and set them in the policy registration screen.
  • When the scope is specified as "All X documents," extensions that are incompatible with the selected execution policy may be automatically excluded upon saving (with a notification popup displayed before saving).
  • If security level (C/S/O) conditions are set for the target document, the document's grade and label information must all match for the policy to be applied. If no conditions are set, the entire grade will be targeted.
  • Items with higher priority in the policy will be executed first.
  • When editing the policy, the changes will be applied by clicking the save button.