{"id":7601,"date":"2013-09-02T15:11:22","date_gmt":"2013-09-02T14:11:22","guid":{"rendered":"http:\/\/www.itwriting.com\/blog\/?p=7601"},"modified":"2013-09-02T15:11:22","modified_gmt":"2013-09-02T14:11:22","slug":"hands-on-with-microsofts-azure-cloud-rights-management-not-ready-yet","status":"publish","type":"post","link":"https:\/\/www.itwriting.com\/blog\/7601-hands-on-with-microsofts-azure-cloud-rights-management-not-ready-yet.html","title":{"rendered":"Hands on with Microsoft\u2019s Azure Cloud Rights Management: not ready yet"},"content":{"rendered":"<p>If you could describe the perfect document security system, it might go something like this. \u201cI\u2019d like to share this document with X, Y, and Z, but I\u2019d like control over whether they can modify it, I\u2019d like to forbid them to share it with anyone else, and I\u2019d like to be able to destroy their copy at a time I specify\u201d.<\/p>\n<p>This is pretty much what Microsoft\u2019s new Azure Rights Management system promises, kind-of:<\/p>\n<blockquote>\n<p>ITPros have the flexibility in their choice of storage locale for their data and Security Officers have the flexibility of maintaining policies across these various storage classes. It can be kept on premise, placed in an business cloud data store such as SharePoint, or it can placed pretty much anywhere and remain safe (e.g. thumb drive, personal consumer-grade cloud drives).<\/p>\n<\/blockquote>\n<p>says the <a href=\"http:\/\/blogs.technet.com\/b\/rms\/archive\/2013\/08\/29\/the-new-microsoft-rms-is-live-in-preview.aspx\" target=\"_blank\">blog post<\/a>. <\/p>\n<p>There is a crucial distinction to be made though. Does Rights Management truly enforce document security, so that it cannot be bypassed without deep hacking; or is it more of an aide-memoire, helping users to do the right thing but not really enforcing it?<\/p>\n<p>I tried the preview of Azure Rights Management, available <a href=\"https:\/\/portal.aadrm.com\/\" target=\"_blank\">here<\/a>. Currently it seems more the latter, rather than any sort of deep protection, but see what you think. It is in preview, and a number of features are missing, so expect improvements.<\/p>\n<p>I signed up and installed the software into my Windows 8 PC. <\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb.png\" width=\"404\" height=\"304\" \/><\/a><\/p>\n<p>The way this works is that \u201cenlightened\u201d applications (currently Microsoft Office and Foxit PDF, though even they are not fully enlightened as far as I can tell) get enhancements to their user interface so you can protect documents. You can also protect *any* document by right-click in Explorer:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image1.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb1.png\" width=\"244\" height=\"78\" \/><\/a><\/p>\n<p>I typed a document in Word and hit Share Protected in the ribbon. Unfortunately I immediately got an error, that the network location cannot be reached:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image2.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb2.png\" width=\"404\" height=\"307\" \/><\/a><\/p>\n<p>I contacted the team about this, who asked for the log file and then gave me a quick response. The reason for the error was that Rights Management was looking for a server on my network that I sent to the skip long ago.<\/p>\n<p>Many years ago I must have tried Microsoft IRM (Information Rights Management) though I barely remember. The new software was finding the old information in my Active Directory, and not trying to contact Azure at all.<\/p>\n<p>This is unlikely to be a common problem, but illustrates that Microsoft is extending its existing rights management system, not creating a new one.<\/p>\n<p>With that fixed, I was able to protect and share a document. This is the dialog:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image3.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb3.png\" width=\"404\" height=\"304\" \/><\/a><\/p>\n<p>It is not a Word dialog, but rather part of the Rights Management application that you install. You get the same dialog if you right-click any file in Explorer and choose Share Protected.<\/p>\n<p>I entered a Gmail email address and sent the protected document, which was now wrapped in a file with a .pfile (Protected File) extension.<\/p>\n<p>Next, I got my Gmail on another machine. <\/p>\n<p>First, I tried to open the file on Android. Unfortunately only x86 Windows is supported at the moment: <\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image4.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb4.png\" width=\"404\" height=\"453\" \/><\/a><\/p>\n<p>There is an SDK for Android, but that is all.<\/p>\n<p>I tried again on a Windows machine. Here is the email:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image5.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb5.png\" width=\"404\" height=\"207\" \/><\/a><\/p>\n<p>There is also note in the email:<\/p>\n<blockquote>\n<p>[Note: This Preview build has some limitations at this time. For example, sharing protected files with users external to your organization will result in access control without additional usage restrictions. <a href=\"http:\/\/go.microsoft.com\/fwlink\/?LinkId=321092\">Learn More about the Preview<\/a>]<\/p>\n<\/blockquote>\n<p>I was about to discover some more of these limitations. I attempted to sign up using the Gmail address. Registration involves solving a vile CAPTCHA <\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image6.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb6.png\" width=\"404\" height=\"385\" \/><\/a><\/p>\n<p>but got this message:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image7.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb7.png\" width=\"404\" height=\"174\" \/><\/a><\/p>\n<p>In other words, you cannot yet use the service with Gmail addresses. I tried it with a Hotmail address; but Microsoft is being even-handed; that did not work either.<\/p>\n<p>Next, I tried another email address at a different, private email domain (yes, I have lots of email addresses). No go:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image8.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb8.png\" width=\"404\" height=\"186\" \/><\/a><\/p>\n<p>The message said that the address I used was from an organisation that has Office 365 (this is correct). It then remarked, bewilderingly:<\/p>\n<blockquote>\n<p>If you have an account you can view protected files. If you don\u2019t have an Office 365 account yet, we\u2019ll soon add support\u2026<\/p>\n<\/blockquote>\n<p>This email address does have an Office 365 account. I am not sure what the message means; whether it means the Office 365 account needs to sign up for rights management at \u00a32 per user per month, or what, but it was clearly not suitable for my test.<\/p>\n<p>I tried yet another email address that is not in any way linked to Office 365 and I was up and running. Of course I had to resend the protected file, otherwise this message appears:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image9.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb9.png\" width=\"404\" height=\"172\" \/><\/a><\/p>\n<p>Incidentally, I think the UI for this dialog is wrong. It is not an error, it is working as designed, so it should not be titled \u201cerror\u201d. I see little mistakes like this frequently and they do contribute to user frustration.<\/p>\n<p>Finally, I received a document to an enabled email address and was able to open it:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image10.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb10.png\" width=\"404\" height=\"256\" \/><\/a><\/p>\n<p>For some reason, the packaging results in a document called \u201cAzure IRM docx.docx\u201d which is odd, but never mind.<\/p>\n<p>My question though: to what extent is this document protected? I took the screen grab using the Snipping Tool and pasted it into my blog for all to read, for example. The clipboard also works:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image11.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb11.png\" width=\"404\" height=\"94\" \/><\/a><\/p>\n<p>That said, the plan is for tighter protection to be offered in due course, at lease in \u201cenlightened\u201d applications. The problem with the preview is that if you share to someone in a different email domain, you are forced to give full access. Note the warning in the dialog:<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image13.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb13.png\" width=\"404\" height=\"146\" \/><\/a><\/p>\n<p>Inherently though, the client application has to have decrypted access to the file in order to open it. All the rights management service does, really, is to decrypt the file for users logged into the Azure system and identified by their email address. What happens after that is a matter of implementation.<\/p>\n<p>The consequences of documents getting into the wrong hands are a hot topic today, after Wikileaks et al. Is Microsoft\u2019s IRM a solution?<\/p>\n<p>Making this Azure-based and open to any recipient (once the limitation on \u201cpublic\u201d email addresses is lifted\u201d) makes sense to me. However I note the following:<\/p>\n<ul>\n<li>As currently implemented, this provides limited security. It does encrypt the document, so an intercepted email cannot easily be read, but once opened by the recipient, anything could happen. <\/li>\n<li>The usability of the preview is horrid. Do you really want your trusted recipient to struggle with a CAPTCHA? <\/li>\n<li>Support beyond Windows is essential, and I am surprised that this even went into preview without it. <\/li>\n<\/ul>\n<p>I should add that I am sceptical whether this can ever work. Would it not be easier, and just as effective (or ineffective), simply to have data on a web site with secure log-in? The idea of securely emailing documents to external recipients is great, but it seems to add immense complexity for little added value. I may be missing something here and would welcome comments.<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>had to sign in twice since I didn\u2019t check \u201cRemember password!&quot;<\/p>\n<p><a href=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image12.png\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" style=\"border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px\" border=\"0\" alt=\"image\" src=\"http:\/\/www.itwriting.com\/blog\/wp-content\/uploads\/2013\/09\/image_thumb12.png\" width=\"244\" height=\"228\" \/><\/a><\/p>\n<p>If you try recursion, it will package the already packaged file.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you could describe the perfect document security system, it might go something like this. \u201cI\u2019d like to share this document with X, Y, and Z, but I\u2019d like control over whether they can modify it, I\u2019d like to forbid them to share it with anyone else, and I\u2019d like to be able to destroy &hellip; <a href=\"https:\/\/www.itwriting.com\/blog\/7601-hands-on-with-microsofts-azure-cloud-rights-management-not-ready-yet.html\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Hands on with Microsoft\u2019s Azure Cloud Rights Management: not ready yet<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,75],"tags":[506,586,810],"class_list":["post-7601","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-irm","tag-microsoft","tag-security"],"_links":{"self":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/7601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/comments?post=7601"}],"version-history":[{"count":0,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/7601\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/media?parent=7601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/categories?post=7601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/tags?post=7601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}