ASD's Blueprint for Secure Cloud

Azure Rights Management

This section describes the design decisions associated with Azure Rights Management with Microsoft Purview for system(s) built using ASD's Blueprint for Secure Cloud.

Estimated reading time: 4 minutes

Azure Information Protection, Azure Rights Management and sensitivity labels

The Azure Information Protection (AIP) service underpins sensitivity label access controls and is used to apply encryption, usage rights, and other restrictions to labelled information. When AIP is used in the context of Purview Information Protection it is known as Azure Rights Management, or the Azure Rights Management Service (Azure RMS). Rights Management defines controls like whether online and offline access is permitted and for what length of time, the types of operations permitted, and who the rights are assigned to.

Rights Management Issuer and Owner

When a sensitivity label that uses Azure RMS is applied to a document or email, the account that applies the label automatically becomes the Rights Management Issuer and Owner and is granted full control or owner usage rights for that document or email.

Owner usage rights

Owner usage rights permits any operation on a document or email, and includes the ability to remove protection and reprotect the document or email. When such rights are associated with a sensitivity label, a user is able to reprotect or apply a different label to already labelled information.

Using other usage rights

Organisations may implement alternative usage rights to further improve security for access to sensitive and security classified information:

  • Rights can be customised to permit or deny specific operations, for example Microsoft 365 Copilot uses the EXTRACT permission to summarise information protected with Azure RMS, removing this permission would limit access by Copilot to the labelled information.
  • Rights can independently grant different levels of access to different users for the same labelled information, for example one user can have owner rights for a document, while another user can have viewer rights for the same document.

Assigning usage rights

Usage rights can be assigned to specific users, groups and domains, including for use by external organisations:

  • Ensure consistency by assigning usage rights for sensitivity labels to the same groups as used for publishing labels and set in publishing policy configurations.
  • Permit external organisations the ability to change the sensitivity label of shared documents and email by assign owner usage rights at the domain level. Note that it would be up to the external organisations to also implemented their own restrictions for approved recipients to access information, something that is be accomplished with the Purview configurations herein.

Ownership of auto-labelled information

Auto-labelling policies with sensitivity labels that use Azure RMS should specify an account as the Rights Management Owner with owner usage rights for all information labelled by the policy. The account must be appropriately licensed and considered highly privileged as it would have access to all information labelled by the policy.

The auto-labelling policy configurations for emails ensure that all incoming PROTECTED classified emails will be protected by Azure RMS with the nominated Rights Management Owner account.

The super user feature

The super user feature ensures that authorised users or services will always have access to information protected with Azure RMS for the tenant. By defining super users and activating the feature, an administrator will have owner usage rights tenant-wide. This ensures that if information is ever required to have its encryption removed or rights modified, for example in preparing for a records transfer to the National Archives, administrators using the super user feature can perform the required changes.

Security & Governance

Design

Configuration

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra