From d11f74b061b3eb61f4f4fa880585b8f31eb707f8 Mon Sep 17 00:00:00 2001 From: LizRoss Date: Mon, 9 Jan 2017 11:05:46 -0800 Subject: [PATCH] Updated text --- windows/keep-secure/TOC.md | 2 +- ...ange-history-for-keep-windows-10-secure.md | 2 +- ...ended-office-365-configurations-for-wip.md | 64 ------------------- windows/keep-secure/using-owa-with-wip.md | 57 ++++------------- 4 files changed, 16 insertions(+), 109 deletions(-) delete mode 100644 windows/keep-secure/recommended-office-365-configurations-for-wip.md diff --git a/windows/keep-secure/TOC.md b/windows/keep-secure/TOC.md index 3118984f33..6f4a4635e9 100644 --- a/windows/keep-secure/TOC.md +++ b/windows/keep-secure/TOC.md @@ -37,8 +37,8 @@ ### [General guidance and best practices for Windows Information Protection (WIP)](guidance-and-best-practices-wip.md) #### [Enlightened apps for use with Windows Information Protection (WIP)](enlightened-microsoft-apps-and-wip.md) #### [Unenlightened and enlightened app behavior while using Windows Information Protection (WIP)](app-behavior-with-wip.md) -#### [Recommended Office 365 Mail and Calendar apps configuration with Windows Information Protection (WIP)](recommended-office-365-configurations-for-wip.md) #### [Recommended Enterprise Cloud Resources and Neutral Resources network settings with Windows Information Protection (WIP)](recommended-network-definitions-for-wip.md) +#### [Using Outlook Web Access with Windows Information Protection (WIP)](using-owa-with-wip.md) ## [Use Windows Event Forwarding to help with intrusion detection](use-windows-event-forwarding-to-assist-in-instrusion-detection.md) ## [Override Process Mitigation Options to help enforce app-related security policies](override-mitigation-options-for-app-related-security-policies.md) ## [VPN technical guide](vpn-guide.md) diff --git a/windows/keep-secure/change-history-for-keep-windows-10-secure.md b/windows/keep-secure/change-history-for-keep-windows-10-secure.md index 705b515233..900762eca3 100644 --- a/windows/keep-secure/change-history-for-keep-windows-10-secure.md +++ b/windows/keep-secure/change-history-for-keep-windows-10-secure.md @@ -15,8 +15,8 @@ This topic lists new and updated topics in the [Keep Windows 10 secure](index.md ## January 2017 |New or changed topic |Description | |---------------------|------------| -|[Recommended Office 365 Mail and Calendar apps configuration with Windows Information Protection (WIP)](recommended-office-365-configurations-for-wip.md) |New | |[Recommended Enterprise Cloud Resources and Neutral Resources network settings with Windows Information Protection (WIP)](recommended-network-definitions-for-wip.md) |New | +|[Using Outlook Web Access with Windows Information Protection (WIP)](using-owa-with-wip.md) |New | ## December 2016 |New or changed topic |Description | diff --git a/windows/keep-secure/recommended-office-365-configurations-for-wip.md b/windows/keep-secure/recommended-office-365-configurations-for-wip.md deleted file mode 100644 index 193528b36e..0000000000 --- a/windows/keep-secure/recommended-office-365-configurations-for-wip.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: Using Outlook Web Access with Windows Information Protection (WIP) (Windows 10) -description: Recommendations about how to configure Office 365 Mail and Calendar apps, including Outlook Web Access (OWA) and the various client apps, with Windows Information Protection (WIP). -keywords: WIP, Windows Information Protection, EDP, Enterprise Data Protection, WIP and Office 2016 configuration, WIP and Office 365 Mail app -ms.prod: w10 -ms.mktglfcycl: explore -ms.sitesec: library -ms.pagetype: security -localizationpriority: high ---- - -# Using Outlook Web Access with Windows Information Protection (WIP) -**Applies to:** - -- Windows 10, version 1607 -- Windows 10 Mobile - ->Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare). - -Because the Office 365 Mail and Calendar apps, including Outlook Web Access (OWA) and the various client apps, can be used both personally and as part of your organization, we recommend the following configurations: - - - - - - - - - - - - - - - - - - - - - - - - -
OptionOWA behaviorOffice 365 behavior
Disable OWA. Employees can only use Microsoft Outlook 2016 or the Office 365 Mail app.Disabled.Both Outlook 2016 and the Office 365 Mail app behave properly, regardless of how you've configured outlook.office.com in your network settings.
An employee's mailbox is automatically marked as corporate data.
Don't configure outlook.office.com in any of your networking settings.All mailboxes are automatically marked as personal. This means employees attempting to copy work content into OWA receive prompts and that files downloaded from OWA aren't automatically protected as corporate data.
Do any of the following: -
    -
  • Create a domain (such as mail.contoso.com, redirecting to outlook.office.com) that can be used by your employees to access work email.
  • -
  • Add the new domain to the Enterprise Cloud Resources network element in your WIP policy.
  • -
  • Add the following URLs to the Neutral Resources network element in your WIP policy: -
      -
    • outlook.office365.com
    • -
    • outlook.office.com
    • -
    • outlook-sdf.office.com
    • -
    • attachment.outlook.office.net
    • -
    -
  • -
-
Inbox content accessed through the new domain is automatically marked as corporate data, while content accessed through personal email is automatically marked as personal.
Add outlook.office.com to the Enterprise Cloud Resources network element in your WIP policy.All mailboxes are automatically marked as work. This means any personal inboxes hosted on Office 365 are also automatically marked as corporate data.
- - - - - - diff --git a/windows/keep-secure/using-owa-with-wip.md b/windows/keep-secure/using-owa-with-wip.md index b243ede2f4..7610b5120a 100644 --- a/windows/keep-secure/using-owa-with-wip.md +++ b/windows/keep-secure/using-owa-with-wip.md @@ -1,7 +1,7 @@ --- -title: Recommended Office 365 Mail and Calendar apps configuration with Windows Information Protection (WIP) (Windows 10) -description: Recommendations about how to configure Office 365 Mail and Calendar apps, including Outlook Web Access (OWA) and the various client apps, with Windows Information Protection (WIP). -keywords: WIP, Windows Information Protection, EDP, Enterprise Data Protection, WIP and Office 2016 configuration, WIP and Office 365 Mail app +title: Using Outlook Web Access with Windows Information Protection (WIP) (Windows 10) +description: Options for using Outlook Web Access (OWA) with Windows Information Protection (WIP). +keywords: WIP, Windows Information Protection, EDP, Enterprise Data Protection, WIP and OWA configuration ms.prod: w10 ms.mktglfcycl: explore ms.sitesec: library @@ -9,7 +9,7 @@ ms.pagetype: security localizationpriority: high --- -# Recommended Office 365 Mail and Calendar apps configuration with Windows Information Protection (WIP) +# Using Outlook Web Access with Windows Information Protection (WIP) **Applies to:** - Windows 10, version 1607 @@ -17,46 +17,17 @@ localizationpriority: high >Learn more about what features and functionality are supported in each Windows edition at [Compare Windows 10 Editions](https://www.microsoft.com/en-us/WindowsForBusiness/Compare). -Because the Office 365 Mail and Calendar apps, including Outlook Web Access (OWA) and the various client apps, can be used both personally and as part of your organization, we recommend the following configurations: - - - - - - - - - - - - - - - - - - - - - - - - -
OptionOWA behaviorOffice 365 behavior
Disable OWA. Employees can only use Microsoft Outlook 2016 or the Office 365 Mail app.Disabled.Both Outlook 2016 and the Office 365 Mail app behave properly, regardless of how you've configured outlook.office.com in your network settings.
An employee's mailbox is automatically marked as corporate data.
Don't configure outlook.office.com in any of your networking settings.All mailboxes are automatically marked as personal. This means employees attempting to copy work content into OWA receive prompts and that files downloaded from OWA aren't automatically protected as corporate data.
Do any of the following: -
    -
  • Create a domain (such as mail.contoso.com, redirecting to outlook.office.com) that can be used by your employees to access work email.
  • -
  • Add the new domain to the Enterprise Cloud Resources network element in your WIP policy.
  • -
  • Add the following URLs to the Neutral Resources network element in your WIP policy: -
      -
    • outlook.office365.com
    • -
    • outlook.office.com
    • -
    • outlook-sdf.office.com
    • -
    • attachment.outlook.office.net
    • -
    -
  • -
-
Inbox content accessed through the new domain is automatically marked as corporate data, while content accessed through personal email is automatically marked as personal.
Add outlook.office.com to the Enterprise Cloud Resources network element in your WIP policy.All mailboxes are automatically marked as work. This means any personal inboxes hosted on Office 365 are also automatically marked as corporate data.
+Because Outlook Web Access (OWA) can be used both personally and as part of your organization, you have the following options to configure it with Windows Information Protection (WIP): +|Option |OWA behavior | +|-------|-------------| +|Disable OWA. Employees can only use Microsoft Outlook 2016 or the Office 365 Mail app. | Disabled. | +|Don't configure outlook.office.com in any of your networking settings. |All mailboxes are automatically marked as personal. This means employees attempting to copy work content into OWA receive prompts and that files downloaded from OWA aren't automatically protected as corporate data. | +|Do all of the following: |Inbox content accessed through the new domain is automatically marked as corporate data, while content accessed through personal email is automatically marked as personal. | +|Add outlook.office.com to the Enterprise Cloud Resources network element in your WIP policy. |All mailboxes are automatically marked as corporate. This means any personal inboxes hosted on Office 365 are also automatically marked as corporate data. | + +>[!NOTE] +>These limitations don’t apply to Outlook 2016 or to the Office365 Mail and Calendar apps. These apps will work properly, marking an employee’s mailbox as corporate data, regardless of how you’ve configured outlook.office.com in your network settings.