Microsoft Purview Information Protection enables classification, labeling, and protection of documents and emails. The service is the evolution of Azure Information Protection (AIP); the former AIP add-in for Office has been discontinued, and the functionality is now built directly into Microsoft 365.
What is Microsoft Purview Information Protection?
Information Protection uses sensitivity labels to classify documents and emails by confidentiality level, such as Public, Internal, Confidential, or Highly Confidential. Labels can be applied manually or automatically based on content inspection.
In addition to classification, rights management (built on Azure Rights Management) encrypts documents and enforces permissions. Protected documents remain protected even when shared outside the organization. Management is centralized through the Microsoft Purview compliance portal.
Core Features
- Sensitivity labels: Classification by confidentiality level, built natively into Microsoft 365 apps
- Automatic classification: Content-based detection of sensitive data for automatic or recommended labels
- Rights management: Encryption and permission control built on Azure Rights Management
- Document tracking: Monitoring of protected documents and their access
- Unified labeling: Consistent labels across Office, SharePoint, Teams, and third-party apps via the Microsoft Information Protection SDK
Typical Use Cases
Information Protection suits organizations with compliance requirements such as GDPR or industry-specific regulations. Common scenarios include protecting customer data, financial documents, HR records, and intellectual property.
Benefits
- Protection persists even outside the corporate network
- Unified classification across all Microsoft 365 apps
- Automated compliance through policy-driven labels
- Integration with data loss prevention (DLP) and other Purview services
Integration with innFactory
As a Microsoft Solutions Partner, innFactory helps you implement Microsoft Purview Information Protection: label taxonomy design, policy configuration, rights management, and compliance implementation.
Typical Use Cases
Frequently Asked Questions
What is the difference between Azure Information Protection and Microsoft Purview Information Protection?
Azure Information Protection (AIP) was the original name; the standalone AIP add-in for Office was retired in 2024. The functionality is now part of Microsoft Purview Information Protection and is managed directly within Microsoft 365 apps and the Microsoft Purview compliance portal. Azure Rights Management remains the underlying encryption technology.
How does automatic classification work?
Sensitivity labels can be applied automatically based on content inspection. The service recognizes patterns such as credit card numbers, government ID data, or custom regex patterns, and either suggests or automatically applies matching labels.
Can documents still be protected after being shared?
Yes, rights management encrypts documents and enforces permissions even outside the organization. Opening, editing, printing, and forwarding can be controlled granularly, even after the document has already been sent.
Which clients are still supported?
The classic AIP add-in for Office has been retired; labeling is now built natively into Microsoft 365 apps. For scenarios outside the Office apps, the Microsoft Purview Information Protection client is available, including for file scanning and Explorer integration.
Which file types are supported?
Native support exists for Office documents, PDFs, and images. All other file types are protected through generic wrapper-based encryption.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
