Video summary
Unified Labeling Client Installation | Azure Information Protection
Main summary
Key takeaways
Main topic
- How to install and verify the Azure Information Protection (AIP) Unified Labeling Client on Windows.
- How it differs from the AIP Classic client.
- Includes a verification workflow to confirm whether policies/sensitivity labels actually apply, plus log collection/troubleshooting steps.
- Cross-platform note: iOS/Android built-in clients natively support Unified Labeling.
Key tech/product concepts & differences
1) Where clients retrieve labels/policies from
-
AIP Classic client
- Queries portal.office.com
-
AIP Unified Labeling client
- Queries protection.office.com
This is presented as the “basic fundamental” distinction.
2) Installation options (Unified vs Classic)
-
Download discovery
- Search setup using: “IP unified labeling client”
-
Installer formats
- Includes an EXE
- If deploying via SCCM/deployment manager, also download an MSI
-
During installation
- Classic client includes an extra option: “Install demo policy.”
- Unified labeling client does not install the demo policy
-
Configuration expectations
- The narrator indicates there’s no configuration change required—“everything will fall in place.”
3) Different labeling UI in Outlook
-
Classic client
- Shows “Protect here”
-
Unified labeling client
- Shows “Sensitivity”
This reflects how classification/protection is presented to the end user in Outlook.
Tutorial/guide: policy + label verification
What the video verifies
- An AIP policy assigned to the signed-in user is working.
- After installing the Unified Labeling client, labels appear in the label bar.
Example sensitivity info type (custom)
- The video validates a custom sensitivity info type.
- Example rule described:
- If keywords (e.g., related to “human resource documents” / a keyword) exist in a document, then it should be protected.
Verification checklist
- Confirm the sensitivity info type is displayed under Sensitivity labels.
- Confirm encryption is applied and the keyword appears under Automatic labeling.
End-to-end email test
- Send a test email containing the configured keyword/regex trigger.
- Initially, it may appear as the default label (e.g., “General” / default label).
- After sending, check the email in Sent Items:
- It should show that it was automatically labeled as the custom sensitivity label (e.g., “first-us”).
- This serves as proof that policy and detection are functioning.
Troubleshooting: log export for AIP clients
Collecting logs (Unified Labeling client)
- In the Unified Labeling client UI:
- Choose Help & feedback
- Select Export logs
- Logs export to a compressed (zip) folder
Manual log folder path
-
AppData → Local → Microsoft → MSIP → Logs
-
Open the logs to review:
- how logs were generated,
- which endpoints were accessed,
- why labels may not apply to a specific document.
Same general approach for Classic client
- Help & feedback → Export logs
- Same general folder location and typically the same compressed output behavior.
Cross-platform change (iOS/Android)
- The video notes a recent announcement:
- Built-in AIP clients on iOS and Android now natively support Unified Labeling.
- In iOS Outlook:
- When composing a new email, users can classify and protect
- The label list includes the custom label created in the Unified Labeling console
- The email becomes protected/classified accordingly
Video summary (as stated)
- Install AIP Unified Labeling client (and compare with Classic)
- Explain and validate how policies and sensitivity labels work
- Show how to export logs for troubleshooting
- Mention that iOS/Android clients support Unified Labeling
- Preview: next video—how Azure RMS protection works when combined with AIP
Main speakers/sources
- Speaker: Unspecified individual (described as “hi guys…” style), likely the video host/instructor
- Primary source systems mentioned:
- Azure Information Protection
- protection.office.com
- portal.office.com