Skip to content

Commit 15bda51

Browse files
authored
Merge pull request #167013 from batamig/aip-gov
aip gov draft
2 parents 4070e7c + 61176a7 commit 15bda51

File tree

1 file changed

+84
-1
lines changed

1 file changed

+84
-1
lines changed

articles/security/fundamentals/feature-availability.md

Lines changed: 84 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,14 @@ ms.date: 09/13/2021
1313

1414
This article describes feature availability in the Microsoft Azure and Azure Government clouds for the following security services:
1515

16+
- [Azure Information Protection](#azure-information-protection)
1617
- [Azure Security Center](#azure-security-center)
1718
- [Azure Sentinel](#azure-sentinel)
1819
- [Azure Defender for IoT](#azure-defender-for-iot)
1920

2021
> [!NOTE]
2122
> Additional security services will be added to this article soon.
22-
>
23+
>
2324
2425
## Azure Government
2526

@@ -47,6 +48,88 @@ For more information about Office 365 US Government environments, see:
4748

4849
The following sections identify when a service has an integration with Microsoft 365 and the feature availability for Office 365 GCC, Office 365 High, and Office 365 DoD.
4950

51+
## Azure Information Protection
52+
53+
Azure Information Protection (AIP) is a cloud-based solution that enables organizations to discover, classify, and protect documents and emails by applying labels to content.
54+
55+
AIP is part of the Microsoft Information Protection (MIP) solution, and extends the [labeling](/microsoft-365/compliance/sensitivity-labels) and [classification](/microsoft-365/compliance/data-classification-overview) functionality provided by Microsoft 365.
56+
57+
For more information, see the [Azure Information Protection product documentation](/azure/information-protection/).
58+
59+
- Office 365 GCC is paired with Azure Active Directory (Azure AD) in Azure. Office 365 GCC High and Office 365 DoD are paired with Azure AD in Azure Government. Make sure to pay attention to the Azure environment to understand where [interoperability is possible](#microsoft-365-integration). In the following table, interoperability that is *not* possible is marked with a dash (-) to indicate that support is not relevant.
60+
61+
- Extra configurations are required for GCC-High and DoD customers. For more information, see [Azure Information Protection Premium Government Service Description](/enterprise-mobility-security/solutions/ems-aip-premium-govt-service-description).
62+
63+
> [!NOTE]
64+
> More details about support for government customers are listed in footnotes below the table.
65+
>
66+
> Extra steps are required for configuring Azure Information Protection for GCC High and DoD customers. For more information, see the [Azure Information Protection Premium Government Service Description](/enterprise-mobility-security/solutions/ems-aip-premium-govt-service-description).
67+
>
68+
69+
|Feature/Service |Azure |Azure Government |
70+
|---------|---------|---------|
71+
|**[Azure Information Protection scanner](/azure/information-protection/deploy-aip-scanner)** <sup>[1](#aipnote1)</sup> | | |
72+
| - Office 365 GCC | GA | - |
73+
| - Office 365 GCC High | - | GA |
74+
| - Office 365 DoD | - | GA |
75+
|**Administration** | | |
76+
|[Azure Information Protection portal for scanner administration](/azure/information-protection/deploy-aip-scanner-configure-install?tabs=azure-portal-only) | | |
77+
| - Office 365 GCC | GA | - |
78+
| - Office 365 GCC High | - | GA |
79+
| - Office 365 DoD | - | GA |
80+
| **Classification and labeling** <sup>[2](#aipnote2)</sup> | | |
81+
| [AIP scanner to apply a *default label* to all files in an on-premises file server / repository](/azure/information-protection/deploy-aip-scanner-configure-install?tabs=azure-portal-only) | | |
82+
| - Office 365 GCC | GA | - |
83+
| - Office 365 GCC High | - | GA |
84+
| - Office 365 DoD | - | GA |
85+
| [AIP scanner for automated classification, labeling, and protection of supported on-premises files](/azure/information-protection/deploy-aip-scanner) | | |
86+
| - Office 365 GCC | GA | - |
87+
| - Office 365 GCC High | - | GA |
88+
| - Office 365 DoD | - | GA |
89+
| | | |
90+
91+
<sup><a name="aipnote1" /></a>1</sup> The scanner can function without Office 365 to scan files only. The scanner cannot apply labels to files without Office 365.
92+
93+
<sup><a name="aipnote2" /></a>2</sup> The classification and labeling add-in is only supported for government customers with Microsoft 365 Apps (version 9126.1001 or higher), including Professional Plus (ProPlus) and Click-to-Run (C2R) versions. Office 2010, Office 2013, and other Office 2016 versions are not supported.
94+
95+
### Office 365 features
96+
97+
|Feature/Service |Office 365 GCC |Office 365 GCC High |Office 365 DoD |
98+
|---------|---------|---------|---------|
99+
|**Administration** | | | |
100+
|- [PowerShell for RMS service administration](/powershell/module/aipservice/) | GA | GA | GA |
101+
|- [PowerShell for AIP UL client bulk operations](/powershell/module/azureinformationprotection/) | | | |
102+
|**SDK** | | | |
103+
|- [MIP and AIP Software Development Kit (SDK)](/information-protection/develop/) | GA | GA | GA |
104+
|**Customizations** | | | |
105+
|- [Document tracking and revocation](/azure/information-protection/rms-client/track-and-revoke-admin) | GA | Not available | Not available |
106+
|**Key management** | | | |
107+
|- [Bring Your Own Key (BYOK)](/azure/information-protection/byok-price-restrictions) | GA | GA | GA |
108+
|- [Double Key Encryption (DKE)](/azure/information-protection/plan-implement-tenant-key) | GA | GA | GA |
109+
|**Office files** <sup>[3](#aipnote6)</sup> | | | |
110+
|- [Protection for Microsoft Exchange Online, Microsoft SharePoint Online, and Microsoft OneDrive for Business](/azure/information-protection/requirements-applications) | GA | GA <sup>[4](#aipnote3)</sup> | GA <sup>[4](#aipnote3)</sup> |
111+
|- [Protection for on-premises Exchange and SharePoint content via the Rights Management connector](/azure/information-protection/deploy-rms-connector) | GA <sup>[5](#aipnote5)</sup> | Not available | Not available |
112+
|- [Office 365 Message Encryption](/microsoft-365/compliance/set-up-new-message-encryption-capabilities) | GA | GA | GA |
113+
|- [Set labels to automatically apply pre-configured M/MIME protection in Outlook](/azure/information-protection/rms-client/clientv2-admin-guide-customizations) | GA | GA | GA |
114+
|- [Control oversharing of information when using Outlook](/azure/information-protection/rms-client/clientv2-admin-guide-customizations) | GA | GA <sup>[6](#aipnote6)</sup> | GA <sup>[6](#aipnote6)</sup> |
115+
|**Classification and labeling** <sup>[2](#aipnote2) / [7](#aipnote7)</sup> | | | |
116+
|- Custom templates, including departmental templates | GA | GA | GA |
117+
|- Manual, default, and mandatory document classification | GA | GA | GA |
118+
|- Configure conditions for automatic and recommended classification GA | GA | GA |
119+
|- [Protection for non-Microsoft Office file formats, including PTXT, PJPG, and PFILE (generic protection)](/azure/information-protection/rms-client/clientv2-admin-guide-file-types) | GA | GA | GA |
120+
| | | | |
121+
122+
123+
<sup><a name="aipnote3" /></a>3</sup> The Mobile Device Extension for AD RMS is currently not available for government customers.
124+
125+
<sup><a name="aipnote4" /></a>4</sup> Information Rights Management with SharePoint Online (IRM-protected sites and libraries) is currently not available.
126+
127+
<sup><a name="aipnote5" /></a>5</sup> Information Rights Management (IRM) is supported only for Microsoft 365 Apps (version 9126.1001 or higher), including Professional Plus (ProPlus) and Click-to-Run (C2R) versions. Office 2010, Office 2013, and other Office 2016 versions are not supported.
128+
129+
<sup><a name="aipnote6" /></a>6</sup> Sharing of protected documents and emails from government clouds to users in the commercial cloud is not currently available. Includes Microsoft 365 Apps users in the commercial cloud, non-Microsoft 365 Apps users in the commercial cloud, and users with an RMS for Individuals license.
130+
131+
<sup><a name="aipnote7" /></a>7</sup> The number of [Sensitive Information Types](/microsoft-365/compliance/sensitive-information-type-entity-definitions) in your Microsoft 365 Security & Compliance Center may vary based on region.
132+
50133
## Azure Security Center
51134

52135
Azure Security Center is a unified infrastructure security management system that strengthens the security posture of your data centers, and provides advanced threat protection across your hybrid workloads in the cloud - whether they're in Azure or not - as well as on premises.

0 commit comments

Comments
 (0)