mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-18 20:03:40 +00:00
Merge branch 'public' of https://github.com/MicrosoftDocs/windows-itpro-docs into public
This commit is contained in:
@ -80,7 +80,9 @@ The server side configuration to enable Network Unlock also requires provisionin
|
||||
|
||||
1. The Windows boot manager detects that a Network Unlock protector exists in the BitLocker configuration.
|
||||
2. The client computer uses its DHCP driver in the UEFI to obtain a valid IPv4 IP address.
|
||||
3. The client computer broadcasts a vendor-specific DHCP request that contains the Network Key (a 256-bit intermediate key) and an AES-256 session key for the reply. Both of these keys are encrypted using the 2048-bit RSA Public Key of the Network Unlock certificate from the WDS server.
|
||||
3. The client computer broadcasts a vendor-specific DHCP request that contains:
|
||||
1. A Network Key (a 256-bit intermediate key) encrypted using the 2048-bit RSA Public Key of the Network Unlock certificate from the WDS server.
|
||||
2. An AES-256 session key for the reply.
|
||||
4. The Network Unlock provider on the WDS server recognizes the vendor-specific request.
|
||||
5. The provider decrypts it with the WDS server’s BitLocker Network Unlock certificate RSA private key.
|
||||
6. The WDS provider then returns the network key encrypted with the session key using its own vendor-specific DHCP reply to the client computer. This forms an intermediate key.
|
||||
|
@ -53,7 +53,7 @@ Microsoft has made a concerted effort to enlighten several of our more popular a
|
||||
|
||||
- Mobile Office apps, including Word, Excel, PowerPoint, OneNote, and Outlook Mail and Calendar
|
||||
|
||||
- Office 365 ProPlus apps, including Word, Excel, PowerPoint, OneNote, and Outlook
|
||||
- Microsoft 365 Apps for enterprise apps, including Word, Excel, PowerPoint, OneNote, and Outlook
|
||||
|
||||
- OneDrive app
|
||||
|
||||
@ -99,7 +99,7 @@ You can add any or all of the enlightened Microsoft apps to your allowed apps li
|
||||
| PowerPoint Mobile | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** Microsoft.Office.PowerPoint<br>**App Type:** Universal app |
|
||||
| OneNote | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** Microsoft.Office.OneNote<br>**App Type:** Universal app |
|
||||
| Outlook Mail and Calendar | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** microsoft.windowscommunicationsapps<br>**App Type:** Universal app |
|
||||
| Office 365 ProPlus and Office 2019 Professional Plus | Office 365 ProPlus and Office 2019 Professional Plus apps are set up as a suite. You must use the [O365 ProPlus - Allow and Exempt AppLocker policy files (.zip files)](https://download.microsoft.com/download/7/0/D/70D72459-D72D-4673-B309-F480E3BEBCC9/O365%20ProPlus%20-%20WIP%20Enterprise%20AppLocker%20Policy%20Files.zip) to turn the suite on for WIP.<br>We don't recommend setting up Office by using individual paths or publisher rules. |
|
||||
| Microsoft 365 Apps for enterprise and Office 2019 Professional Plus | Microsoft 365 Apps for enterprise and Office 2019 Professional Plus apps are set up as a suite. You must use the [O365 ProPlus - Allow and Exempt AppLocker policy files (.zip files)](https://download.microsoft.com/download/7/0/D/70D72459-D72D-4673-B309-F480E3BEBCC9/O365%20ProPlus%20-%20WIP%20Enterprise%20AppLocker%20Policy%20Files.zip) to turn the suite on for WIP.<br>We don't recommend setting up Office by using individual paths or publisher rules. |
|
||||
| Microsoft Photos | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** Microsoft.Windows.Photos<br>**App Type:** Universal app |
|
||||
| Groove Music | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** Microsoft.ZuneMusic<br>**App Type:** Universal app |
|
||||
| Microsoft Movies & TV | **Publisher:** `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`<br>**Product Name:** Microsoft.ZuneVideo<br>**App Type:** Universal app |
|
||||
|
@ -1,122 +0,0 @@
|
||||
---
|
||||
title: How Windows Information Protection (WIP) protects files with a sensitivity label (Windows 10)
|
||||
description: Explains how Windows Information Protection works with other Microsoft information protection technologies to protect files that have a sensitivity label.
|
||||
keywords: sensitivity, labels, WIP, Windows Information Protection, EDP, Enterprise Data Protection
|
||||
ms.prod: w10
|
||||
ms.mktglfcycl: explore
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
author: dulcemontemayor
|
||||
ms.author: dansimp
|
||||
manager: dansimp
|
||||
audience: ITPro
|
||||
ms.collection: M365-security-compliance
|
||||
ms.topic: conceptual
|
||||
ms.date: 04/30/2019
|
||||
ms.reviewer:
|
||||
---
|
||||
|
||||
# How Windows Information Protection (WIP) protects a file that has a sensitivity label
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559)
|
||||
- Windows 10, version 1903
|
||||
- Windows 10, version 1809
|
||||
|
||||
>[!IMPORTANT]
|
||||
>Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
|
||||
|
||||
This topic explains how Windows Information Protection works with other Microsoft information protection technologies to protect files that have a sensitivity label.
|
||||
Microsoft information protection technologies work together as an integrated solution to help enterprises:
|
||||
|
||||
- Discover corporate data on endpoint devices
|
||||
- Classify and label information based on its content and context
|
||||
- Protect corporate data from unintentionally leaving to non-business environments
|
||||
- Enable audit reports of user interactions with corporate data on endpoint devices
|
||||
|
||||
Microsoft information protection technologies include:
|
||||
|
||||
- [Windows Information Protection (WIP)](protect-enterprise-data-using-wip.md) is built in to Windows 10 and protects local data at rest on endpoint devices, and manages apps to protect local data in use. Data that leaves the endpoint device, such as email attachment, is not protected by WIP.
|
||||
|
||||
- [Azure Information Protection](https://docs.microsoft.com/azure/information-protection/what-is-information-protection) is a cloud-based solution that can be purchased either standalone or as part of Microsoft 365 Enterprise. It helps an organization classify and protect its documents and emails by applying labels. Azure Information Protection is applied directly to content, and roams with the content as it's moved between locations and cloud services.
|
||||
|
||||
- [Microsoft Cloud App Security](https://docs.microsoft.com/cloud-app-security/what-is-cloud-app-security) is a cloud access security broker (CASB) solution that allows you to discover, classify, protect, and monitor user data in first-party and third-party Software-as-a-Service (SaaS) apps used by your organization.
|
||||
|
||||
## How WIP protects sensitivity labels with endpoint data loss prevention
|
||||
|
||||
You can create and manage [sensitivity labels](https://docs.microsoft.com/office365/securitycompliance/labels) in the Microsoft 365 compliance center.
|
||||
When you [create a sensitivity label](https://docs.microsoft.com/microsoft-365/compliance/create-sensitivity-labels), you can specify that endpoint data loss prevention applies to content with that label.
|
||||
|
||||

|
||||
|
||||
Office app users can choose a sensitivity label from a menu and apply it to a file.
|
||||
|
||||

|
||||
|
||||
WIP enforces default endpoint protection as follows:
|
||||
|
||||
- If endpoint data loss prevention is enabled, the device enforces work protection for any file with the label
|
||||
- If endpoint data loss prevention is not enabled:
|
||||
- The device enforces work protection to a file downloaded from a work site
|
||||
- The device does not enforce work protection to a file downloaded from a personal site
|
||||
|
||||
Here's an example where a file remains protected without any work context beyond the sensitivity label:
|
||||
|
||||
1. Sara creates a PDF file on a Mac and labels it as **Confidential**.
|
||||
1. She emails the PDF from her Gmail account to Laura.
|
||||
1. Laura opens the PDF file on her Windows 10 device.
|
||||
1. Windows Defender Advanced Threat Protection (Windows Defender ATP) scans Windows 10 for any file that gets modified or created, including files that were created on a personal site.
|
||||
1. Windows Defender ATP triggers WIP policy.
|
||||
1. WIP policy protects the file even though it came from a personal site.
|
||||
|
||||
## How WIP protects automatically classified files
|
||||
|
||||
The next sections cover how Windows Defender ATP extends discovery and protection of sensitive information with improvements in Windows 10 version 1903.
|
||||
|
||||
### Discovery
|
||||
|
||||
Windows Defender ATP can extract the content of the file itself and evaluate whether it contains sensitive information types such as credit card numbers or employee ID numbers.
|
||||
When you create a sensitivity label, you can specify that the label be added to any file that contains a sensitive information type.
|
||||
|
||||

|
||||
|
||||
A default set of [sensitive information types](https://docs.microsoft.com/office365/securitycompliance/what-the-sensitive-information-types-look-for) in Microsoft 365 compliance center includes credit card numbers, phone numbers, driver's license numbers, and so on.
|
||||
You can also [create a custom sensitive information type](https://docs.microsoft.com/office365/securitycompliance/create-a-custom-sensitive-information-type), which can include any keyword or expression that you want to evaluate.
|
||||
|
||||
### Protection
|
||||
|
||||
When a file is created or edited on a Windows 10 endpoint, Windows Defender ATP extracts the content and evaluates if it contains any default or custom sensitive information types that have been defined.
|
||||
If the file has a match, Windows Defender ATP applies endpoint data loss prevention even if the file had no label previously.
|
||||
|
||||
Windows Defender ATP is integrated with Azure Information Protection for data discovery and reports sensitive information types that were discovered.
|
||||
Azure Information Protection aggregates the files with sensitivity labels and the sensitive information types they contain across the enterprise.
|
||||
|
||||

|
||||
|
||||
You can see sensitive information types in Microsoft 365 compliance under **Classifications**. Default sensitive information types have Microsoft as the publisher. The publisher for custom types is the tenant name.
|
||||
|
||||

|
||||
|
||||
>[!NOTE]
|
||||
>Automatic classification does not change the file itself, but it applies protection based on the label.
|
||||
>WIP protects a file that contains a sensitive information type as a work file.
|
||||
>Azure Information Protection works differently in that it extends a file with a new attribute so the protection persists if the file is copied.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Endpoint data loss prevention requires Windows 10, version 1809
|
||||
- Auto labelling requires Windows 10, version 1903
|
||||
- Devices need to be onboarded to [Windows Defender ATP](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/windows-defender-advanced-threat-protection), which scans content for a label and applies WIP policy
|
||||
- [Sensitivity labels](https://docs.microsoft.com/office365/securitycompliance/labels) need to be configured in Microsoft 365 compliance center
|
||||
- WIP policy needs to be applied to endpoint devices by using [Intune](create-wip-policy-using-intune-azure.md) or [Microsoft Endpoint Configuration Manager](overview-create-wip-policy-configmgr.md)
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
Reference in New Issue
Block a user