The service that does the actual encrypting behind sensitivity labels, message encryption and DKE in Purview Information Protection, attaching usage rights to protected content. Newer tenants get it switched on automatically; older ones turn it on with PowerShell.
Also called Azure RMS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Rights Management in context, with comparison tables and the common traps.
Terms in this definition
- Sensitivity labels
Purview's way of classifying, and if needed encrypting, content in Office apps and services. They take over from the classic labels of AIP.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Double Key Encryption
Label-based encryption requiring two keys, one kept in Azure and one in the organisation's own DKE service, so Microsoft is unable to decrypt the data. Because services such as search, eDiscovery and Copilot cannot read protected content, it suits only a small amount of highly sensitive data.
- Usage rights
Rights handed out by encryption, for example through a sensitivity label. For Copilot or an agent to return encrypted content, a person needs VIEW as well as EXTRACT (copy).
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- TURN
If a direct link can't be made, RDP Shortpath for Windows 365 relays UDP traffic via Microsoft servers on port 3478 instead.
Related terms
- AD RMS
Active Directory Rights Management Services, Microsoft's older rights management server run on premises. Organisations still relying on it have to move to Azure Rights Management before Purview Message Encryption can be used.
- IRM
Protection that stops recipients doing things like printing, copying or forwarding documents and messages. Microsoft 365 delivers it through Azure Rights Management, and today it is applied with sensitivity labels.
- Microsoft Purview Message Encryption
Built on Azure Rights Management, it encrypts mail sent to people both within and beyond the organisation. Senders can pick Do Not Forward or Encrypt-Only, organisations can brand messages, and supported Outlook clients show them in-line; legacy OME, now deprecated, gave way to it.
- Rights Management issuer
Whoever applied Azure Rights Management encryption to an item. That account keeps Full Control permanently, keeps offline access, and can still open the item once it has expired or been revoked.
- Super user
An Azure Rights Management capability, disabled by default, giving approved people and services permanent ability to read and inspect the tenant's encrypted content and strip the encryption when needed.