Microsoft 資訊保護 SDK - 使用者自訂權限

Microsoft 資訊保護 SDK 支援兩種主要的標籤驅動權限:基於範本的與使用者定義的。

  • 基於範本的權限:標籤管理員在 Microsoft Purview 入口網站 中定義這些權限。 這些標籤由集中管理,設定變更會影響已擁有檔案副本的使用者。 例如,若管理員將某位使用者從授權使用者名單中移除,該使用者下次嘗試取得授權時將無法存取受保護的資料。

  • 使用者自訂權限:最終使用者或應用程式在 標註時定義這些權利。 將權限以使用者對角色或使用者對權限的對應集合形式傳遞給 MIP SDK。 MIP SDK 將這些權利寫入受保護文件的發佈授權條款中。 與範本權限不同,分享後無法集中管理或修改這些權限,除非直接存取並修改文件。

使用者、權利與角色

由於使用者在標籤時定義權利,您的應用程式必須提供介面,讓使用者或服務輸入電子郵件地址、權限或角色。 要設定存取權限,可以傳遞一組UserRolesUserRights或物件,定義誰對文件擁有何層級的存取權限。

// Create a List<string> of the first set of permissions. 
List<string> users = new List<string>()
{
    "alice@contoso.com",
    "bob@contoso.com"
};

// Create a List<string> of the Rights the above users should have. 
List<string> rights = new List<string>()
{
    Rights.View,
    Rights.Edit                
};

// Create a UserRights object containing the defined users and rights.
UserRights userRights = new UserRights(users, rights);

// Add them to a new List<UserRights>
List<UserRights> userRightsList = new List<UserRights>()
{
    userRights
};

結果是一個 List<UserRights> 集合,指定 Alice 和 Bob 在受保護檔案上同時擁有 VIEW 和 EDIT。 若要新增更多擁有 不同 權限的使用者,請重複建立第二個 UserRights 物件的過程,傳遞新的使用者與權限,然後透過 List<UserRights> 呼叫 userRightsList.Add(userRights2)加入集合。

同樣的模式也適用於 UserRoles。 要實作它,請用角色替換權利並建立一個List<UserRoles>集合。

域保護

為網域套用使用者自訂權限需要一個知名的郵件前綴,以及目標網域作為郵件位址。 那個地址看起來像 AllStaff-7184AB3F-CCD1-46F3-8233-3E09E9CF0E66@contoso.com。

在你的應用程式中,使用者應該能指定網域,例如 contoso.com 或 fabrikam.com。 當應用程式建立保護描述符時,會在網域後綴前加上 AllStaff-7184AB3F-CCD1-46F3-8233-3E09E9CF0E66@ 。

這個知名群組也是你授予 組織中所有已認證使用者權利的方式。 該AllStaff-7184AB3F-CCD1-46F3-8233-3E09E9CF0E66@群組包含指定 Microsoft Entra 租戶中的每一位使用者,因此它是 Active Directory Rights Management Services(AD RMS)中 ANYONE 群組最接近的對應單位。 範圍始終是單一租戶:沒有跨租戶身份能賦予任何認證使用者權限,因此為每個想包含的組織新增 AllStaff-...@domain 獨立條目。 如需詳細資訊,請參閱 設定 Azure 資訊保護的使用權限。

在以下範例中,使用者指定 alice@contoso.com 和 所有 Fabrikam.com 為有效的接收者。

// Create a List<string> of the first set of permissions. 
List<string> users = new List<string>()
{
    "alice@contoso.com",
    "AllStaff-7184AB3F-CCD1-46F3-8233-3E09E9CF0E66@fabrikam.com"
};

// Create a List<string> of the Rights the above users should have. 
List<string> rights = new List<string>()
{
    Rights.View,
    Rights.Edit                
};

// Create a UserRights object containing the defined users and rights.
UserRights userRights = new UserRights(users, rights);

// Add them to a new List<UserRights>
List<UserRights> userRightsList = new List<UserRights>()
{
    userRights
};

啟用保護

若要設定保護,請從 FileHandler.SetProtection() 或 List<UserRoles> 物件建立 ProtectionDescriptor,然後將該描述元傳遞給 List<UserRights>。 最後,將變更提交到檔案中,寫入新檔案。

何時對檔案套用保護

當你用 FileHandler.SetLabel()設定標籤時,MIP SDK 就具備所有需要的操作與保護功能。 當標籤使用使用者自訂權限(UDP)時,應用程式無法事先知道該標籤是否為 UDP 標籤。 MIP SDK 會拋出 Microsoft.InformationProtection.Exceptions.AdhocProtectionRequiredException 的例外來呈現這些資訊。 你的 FileHandler 程式碼應該會偵測到這個例外,然後觸發使用者或服務介面來定義自訂權限。 完成後,你可以設定保護措施。 以下範例展示了端對端的模式,但假設你已經實作了一個函式來建構物件 List<UserRights> 。

try
{
    // Attempt to set the label. If it's a UDP label, this will throw. 
    handler.SetLabel(engine.GetLabelById(options.LabelId), labelingOptions, new ProtectionSettings());
}

catch (Microsoft.InformationProtection.Exceptions.AdhocProtectionRequiredException)
{
    // Assumes you've create a function that returns the List<UserRights> as previously detailed. 
    List<UserRights> userRightsList = GetUserRights();

    // Create a ProtectionDescriptor using the set of UserRights.
    ProtectionDescriptor protectionDescriptor = new ProtectionDescriptor(userRightsList);
    
    // Apply protection to the file using the new ProtectionDescriptor. 
    handler.SetProtection(protectionDescriptor, new ProtectionSettings());

    // Set the label. This will now succeed as protection has been defined. 
    handler.SetLabel(engine.GetLabelById(options.LabelId), labelingOptions, new ProtectionSettings());

    // Commit the change. 
    var result = Task.Run(async () => await handler.CommitAsync("myFileOutput.xlsx")).Result;
}

自訂保護

你也可以用這個流程,透過設定保護後跳過步驟 SetLabel() ,只設定保護。 如果你的應用程式不需要套用標籤,例外處理程式就不需要。 要設定防護,請遵循 ProtectionDescriptor ——>SetProtection() 模式>CommitAsync() 。

下一步