Overview
The MPIP Classifier extension allows DryvIQ to extract your Microsoft Purview Information Protection (MPIP) sensitivity labels. This requires you to register an application in your Microsoft Azure account to obtain the Application (Client) ID and Directory (Tenant) ID required to allow DryvIQ to access the security labels through the Microsoft Information Protection Sync Service.
Access Level Requirements
The Microsoft tenant user applied to the extension configuration must have sufficient rights to read the labels.
Signed Files
Microsoft does not support adding labels to signed files.
Registering the App
- Log in to your Microsoft Azure account using an administrator account.
- Click Microsoft Entra ID.
- Click Add and select App registration.
- Enter a name for the app in the Name field.
- Under Supported account types, select Accounts in this organizational directory only ([company name] only- Single tenant).
- Click Register.
- Under Manage, click API Permissions.
- Click Add a permission.
- In the Request API Permissions panel, click Azure Rights Management Services.
- Click the Application permissions option.
- Under Content, select the following permissions:
- Content.DelegatedReader
- Content.DelegatedWriter
- Content.SuperUser
- Content.Writer.
- Click Add permissions.
- You will be back on the API Permissions Page. Click Add a permission again.
- Click APIs my organization uses.
- In the search box, type “Microsoft Information Protection Sync Service” and select this option in the results list.
- Click Application permissions.
- Select the UnifiedPolicy.Tenant.Read box.
- Click Add permissions.
- Click Grant admin consent for [company name].
- Click Yes when prompted to confirm you want to grant admin consent.
- Click Certificates & secrets.
- Click New client secret.
- Enter a description in the Description field.
- Click Add.
- Copy the new Client Secret Value and save it somewhere readily accessible. You will need it to configure the extension.
- Click Overview.
- Copy the Application (client) ID and the Directory (tenant) ID. Both are needed for the extension configuration.
Adding the Classifier Settings
The Microsoft MPIP configuration must be included in the Hub YAML file during the installation process. This allows DryvIQ to pull the labels. Contact your Consulting Services representative or DryvIQ Support for assistance.
