You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多租户Web应用中借助Azure AD App移除SharePoint文件AIP保护方案咨询

Great question! Let's walk through both using the MIP SDK with your existing setup and the REST API option you're asking about to remove AIP protection from SharePoint documents.

Using the MIP SDK to Remove AIP Protection

Your current code already initializes the MIP File Engine, so we just need to add the logic to handle the SharePoint file and remove its protection. Here's how to adjust your implementation:

1. Verify Permissions First

Make sure your Azure AD app has the application permissions (not delegated) required:

  • InformationProtectionPolicy.Read.All
  • InformationProtectionPolicy.Write.All
  • Sites.ReadWrite.All (to access and modify SharePoint files)
    Don't forget to grant admin consent for these permissions in the Azure Portal.

2. Fix the Identity Setup (Critical!)

Since you're using the Client Credential flow (application-level permissions), the Identity in your engineSettings should reference your Azure AD app's service principal, not the end user's UPN. Update that line in your controller code:

// Replace the existing Identity line with this
engineSettings.Identity = new Identity(appInfo.ApplicationId, IdentityType.ServicePrincipal);

3. Add Protection Removal Logic

After initializing the fileEngine, add code to acquire the SharePoint file handler and remove protection:

// Replace with your target SharePoint document URL
string sharePointFileUrl = "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx";

// Configure options for the remote SharePoint file
var handlerOptions = new FileHandlerOptions()
{
    FileName = Path.GetFileName(sharePointFileUrl),
    FileState = FileState.Remote // Indicates we're working with a cloud-hosted file
};

// Acquire the file handler from the engine
var fileHandler = await fileEngine.AcquireFileAsync(sharePointFileUrl, handlerOptions);

try
{
    // Check if the file is actually protected before proceeding
    if (fileHandler.IsProtected)
    {
        // Remove the AIP protection
        await fileHandler.RemoveProtectionAsync();
        // Commit changes back to SharePoint
        await fileHandler.CommitAsync();
    }
}
finally
{
    // Clean up resources
    fileHandler.Dispose();
    await fileEngine.DisposeAsync();
    await fileProfile.DisposeAsync();
}

4. Switch to Async/Await (Avoid Deadlocks)

Your current code uses Task.Run(async () => ...).Result which can cause deadlocks in web apps. Convert your controller action to an async method instead:

public async Task<IActionResult> RemoveDocumentProtection()
{
    // Your existing initialization code here (updated with the correct Identity)
    
    // Add the protection removal logic above here
    
    return Ok("AIP protection removed successfully!");
}
Using the REST API to Remove AIP Protection

If you prefer a lighter-weight approach without the MIP SDK dependency, you can use the Microsoft Information Protection REST API's RemoveProtection endpoint.

1. Required Permissions

Same as the SDK approach: your Azure AD app needs the application permissions InformationProtectionPolicy.Read.All, InformationProtectionPolicy.Write.All, and Sites.ReadWrite.All (with admin consent).

2. Get an Access Token

Use your existing authentication code to get a token for the resource https://api.microsoft.com:

AuthenticationContext authContext = new AuthenticationContext(authority, tokenCache);
var clientCred = new ClientCredential(appInfo.ApplicationId, clientSecret);
var result = await authContext.AcquireTokenAsync("https://api.microsoft.com", clientCred);
string accessToken = result.AccessToken;

3. Call the REST API

Send a POST request to the removeProtection endpoint with details about your SharePoint file. You can use either the file's URL or its site/file GUIDs:

POST https://api.microsoft.com/informationprotection/removeProtection HTTP/1.1
Authorization: Bearer {access_token}
Content-Type: application/json

{
    "fileLocation": {
        "@odata.type": "#microsoft.graph.sharePointFileLocation",
        "siteUrl": "https://yourtenant.sharepoint.com/sites/yoursite",
        "fileUrl": "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx"
    }
}

If you have the site and file GUIDs, you can use those instead for more precise targeting:

{
    "fileLocation": {
        "@odata.type": "#microsoft.graph.sharePointFileLocation",
        "siteId": "12345678-1234-1234-1234-1234567890ab",
        "fileId": "98765432-4321-4321-4321-ba0987654321",
        "fileUrl": "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx"
    }
}

Which Option Should You Choose?

  • MIP SDK: Best if you need to handle file content, apply complex protection rules, or integrate with other MIP features (like labeling) in your app.
  • REST API: Better for simple, one-off operations or when you want to avoid adding the MIP SDK dependency to your project.

内容的提问来源于stack exchange,提问作者Garima

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 09:17:01