This article is contributed. See the original author and article here.

To provide a unified and streamlined customer experience, the Azure Information Protection labeling and policy management in the Azure Portal, and the AIP classic client, will be deprecated on March 31st, 2021as announced in our previous blog.


 


We highly recommend customers on classic AIP labeling to migrate to unified labeling before this sunset timeline for a seamless transition to unified labeling.


 


Note: This deprecation does not apply in the following scenarios:



  • For customers who have already been approved for extended support. Customers with extended support will continue using the AIP area in the Azure Portal with no impact until the end date of their extended support.

  • For GCC/GCC-H/DoD customers. Support is extended for GCC/GCC-H/DoD customers until the end of September 2021.


 


The deprecation does not affect the Azure Information Protection areas in the Azure portal related to the on-premises scanner and analytics. AIP analytics is still available in the Azure Portal, but we encourage customers to start using the Microsoft 365 Compliance center Activity Explorer.


 


After deprecation, editing labels and policies in the Azure portal will no longer be available. The only admin action that will still be available after deprecation is to activate unified labeling. Classic client will continue to function as configured; however, no further support is provided, and maintenance versions will no longer be released for the classic client.


 


This blog lists key admin components that will be deprecated and describes how this impacts the admin. For details on migration, see the previous communications on UL migration steps.


 


1) Admin tries to add new labels in AIP portal



  • Admins will not be able to add new labels in the AIP portal.

  • The Add a new label link and the ellipses link () next to each label will be disabled or removed.

  • Admins will not be able to do any of the following:

    • Add new labels

    • Add new sub-labels

    • Delete a label

    • Move labels up or down




Fig 1: Home > Azure Information Protection > Labels


Gopal_Shankar_0-1614807736336.png


 


2) Admin tries to edit labels in AIP portal



  • Labels will be set to read-only mode.


Fig 2: Home > Azure Information Protection > Labels > Label Name


Gopal_Shankar_1-1614797493019.png


 


3) Admin tries to edit label conditions in the AIP portal



  • The Add new condition link will be removed.


Fig 3a: Home > Azure Information Protection > Labels > Label Name > Configure Condition


Gopal_Shankar_2-1614797562582.png


 


Fig 3b: Home > Azure Information Protection > Labels > Label Name > Configure Condition



  • Admins will be able to view conditions in read-only mode.

  • Admins will not be able to edit condition settings.


Gopal_Shankar_3-1614797562590.png


4) Admin tries to edit policies in the AIP portal



  • Admins will not be able to add new policies.

  • Admins will only be able to view the policy.

  • Admins will not be able to save or delete policies.


Fig 4: Home > Azure Information Protection > Policies > Policy


 

Gopal_Shankar_6-1614797673276.png


 


5) Admin tries to edit policies (export, advance settings)



  • Admins will not be able to add new policies.

  • Admins will be able to select the ellipsis () and right-click each to manage a policy. Admins will be able to select the Export and Advanced settings options.

  • In the ellipses link (), the Move up/down and Delete options will not be available.


Fig 5: Home > Azure Information Protection > Policies > Policy


 


Gopal_Shankar_8-1614797723589.png


 


6) Admin tries to add users to policies



  • Admins will be able to view users.

  • Admins will not be able to add or remove users.


Fig 6a: Home > Azure Information Protection > Policies > Policy >


 


Gopal_Shankar_9-1614797760112.png


Fig 6b: Home > Azure Information Protection > Policies > Policy > Select which users or groups get this policy.


 


 


Gopal_Shankar_10-1614797798384.png


 


7) Admin tries to edit the advanced setting configuration in the AIP portal



  • Admins will be able to view settings in read-only mode.

  • Admins will not be able to add new settings or remove settings.


 


Fig 7: Home > Azure Information Protection > Policies > Policy > Advanced Settings


 


Gopal_Shankar_11-1614797836474.png


 


8).Admin tries to activate protection in the AIP portal



  • Admins will only be able to see the status (activated/deactivated).

  • Admins will not be able to activate/deactivate.


 


Fig 8: Home > Azure Information Protection > Protection Activation


 


Gopal_Shankar_12-1614797891890.png


 


9) Admin tries to edit protection templates in the AIP portal


For customers that are working with protection templates instead of labels, Admins could manage the protection templates from the portal. Moving forward:



  • Admins will be able to view protection templates in read-only mode.

  • Admins will not be able to edit/change protection settings in the AIP Portal.

  • Admins can use AIP PowerShell cmdlets to edit protection.

  • Admin will not be able to convert templates to labels using the portal but can still use PowerShell command


Fig 9: Home > Azure Information Protection > Labels


Gopal_Shankar_13-1614797970834.png


 


10) Admin tries to edit protection in the AIP portal



  • Admins will be able to view protection in read-only mode.

  • Admins will not be able to edit/change protection settings in the AIP Portal.

  • Admins can use AIP PowerShell cmdlets to edit protection.


Fig 10: Home > Azure Information Protection > Labels > Label Name > Protection Settings


 


Gopal_Shankar_14-1614798023895.png


 


11) Admin tries to add, import, delete languages in the AIP portal


 



  • Admins will only be able to export language settings.

  • Admins will not be able to add, import, or delete languages.


Fig 11: Home > Azure Information Protection > Languages


 


 


Gopal_Shankar_15-1614798052564.png


12) Admin tries to activate/deactivate unified labeling in AIP portal


 



  • Admins will be able to activate unified labeling from the AIP portal.

  • Admins will be able to copy policies to the Microsoft 365 Compliance center.

  • Admins will not be able to publish policies in the AIP portal.


Fig 12a: Home > Azure Information Protection > Unified Labeling > Activate


 


Gopal_Shankar_16-1614798111850.png


Fig 12b: Home > Azure Information Protection > Unified Labeling >


 


Gopal_Shankar_17-1614798132653.png


13) Using the AIP classic client


 



  • Users will be able to apply label and protection and to consume protected files.

  • The AIP classic client is out of support. 

  • Maintenance versions for the AIP classic client will not be released.


14) AIP labels in Microsoft Cloud App Security



  • Microsoft Cloud App Security will not support AIP labels after March 31st, 2021. Only unified labels will be supported.

  • Existing policies in Microsoft Cloud App Security will not apply or discover AIP labels in files. An alert will be sent to the admin in case the policy had AIP labels.

  • Microsoft Cloud App Security will support only unified label for policies and for labels discovery.


Managing labels and policies in the Microsoft 365 Compliance center


Fig 14a: Microsoft 365 compliance > Solutions > Information Protection > Labels >


After you activate and migrate to unified labeling, your labels will be available in the Microsoft 365 Compliance center.



  • Moving forward, you can manage your labels and policies in the Microsoft 365 Compliance center.

  • For more information about creating, managing labels and policies in the Compliance center, see the Microsoft 365 compliance documentation.


Gopal_Shankar_18-1614798230288.png


Fig 14b: Microsoft 365 compliance > Solutions > Information Protection > Label policies >  


 


Gopal_Shankar_19-1614798248485.png


AIP portal and classic client admin experience summary




























































#



Admin



Not Impacted



Impacted



1



Admin tries to add a new label.


 


 





Admin will not be able to add a new label. 


Admin will not have the shortcuts or any right-click options.



2



Admin tries to edit a label



Admin will be able to view a label in read-only mode. 


 



Admin will not be able to edit or delete label content and settings



3



Admin tries to edit label conditions



Admin will be able to view conditions in read-only mode. 



Admin will not be able to edit conditions



4



Admin tries to edit policy



Admin will be able to only view policy



Admin will not be able to save or delete a policy.



5



Admin tries to edit policies (export, advance settings)



Admin will be able to select the ellipsis and right-click options to manage each policy.


Admins will be able to select Export and Advanced settings buttons. 



Admin will not be able to add new policy.


In the shortcut, the link will not have move up/down or delete options. 



6



Admin tries to add user



Admin will be able to view users



Admin will not be able to add a user or remove a user



7



Admin tries to edit advanced settings



Admin will be able to view settings in read-only mode. 



Admin will not be able to add new settings or remove settings 



8



Admin tries to activate protection



Admin will be able to see the status (activated / deactivated)



Admin will not be able to activate / or deactivate













9



Admin tries to edit protection templates in the AIP portal



Admins will be able to view protection templates in read-only mode.


Admins can use AIP PowerShell cmdlets to edit protection.


 



Admins will not be able to edit / change protection settings in the AIP Portal.


Admin will not be able to convert templates to labels using the portal but can still use PowerShell command































10



Admin tries to edit protection



Admin will be able to view protection in read-only mode. 



Admin will not be able to edit protection



11



Admin tries to add, import, delete language



Admin will be able to only export



Admin will not be able to add, import, delete



12



Admin tries to activate unified labeling



Admin will be able to activate and copy the policy



Admin will not be able to publish labels in the AIP portal



13



End users using classic client



Users will be able to apply labels and protection and to consume protected files



AIP classic is out of support. Maintenance versions will not be released.













14



AIP labels in Microsoft Cloud App Security





AIP labels will not be supported. Only unified labels will be supported.



 


Some important links about unified labeling


 



 


Top 5 frequently asked questions



  1. How can I find my status on extended support?



  • CSS will be able to assist you to find status on extended support.



  1. How to request extended support?



  • You can request extended support using the form posted here.



  1. What are the requirements for requesting extended support?



  • Provide details of the feature/functionality that is blocking your migration.



  1. Who should I contact regarding migration questions?



  • There are various channels. Yammer, CSS, or your CXE representative.



  1. What is the SLA for reviewing the extended support request?



  • The SLA for reviewing extended support requests is 2-3 weeks. We will provide approval or reject response or will request additional information to assess the situation.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.