Set up JIT Access for super users in Purview
The topic I’m about to discuss sits at the edge of Compliance, Information Protection and Identity and Access Management (IAM). Let’s assume you already implemented Microsoft Purview Information Protection labeling. You have a label called top secret, and it encrypts the file when it’s assigned. The user did not share it with anybody and left the company. How do you gain access to the file and it’s content that is encrypted? This is where super users come to the picture. “The super user feature of the Azure Rights Management service from Microsoft Purview Information Protection ensures that authorized people and services can always read and inspect the data that Azure Rights Management encrypts for your organization. If necessary, the encryption protection can then be removed or changed."[1] This feature is not enabled by default, so if you want to take advantage of it you’ll need to set it up first. There is a way to configure super users without compromising on zero trust, and this is what I’m going to show you. ...