多租户Web应用中借助Azure AD App移除SharePoint文件AIP保护方案咨询
Great question! Let's walk through both using the MIP SDK with your existing setup and the REST API option you're asking about to remove AIP protection from SharePoint documents.
Your current code already initializes the MIP File Engine, so we just need to add the logic to handle the SharePoint file and remove its protection. Here's how to adjust your implementation:
1. Verify Permissions First
Make sure your Azure AD app has the application permissions (not delegated) required:
InformationProtectionPolicy.Read.AllInformationProtectionPolicy.Write.AllSites.ReadWrite.All(to access and modify SharePoint files)
Don't forget to grant admin consent for these permissions in the Azure Portal.
2. Fix the Identity Setup (Critical!)
Since you're using the Client Credential flow (application-level permissions), the Identity in your engineSettings should reference your Azure AD app's service principal, not the end user's UPN. Update that line in your controller code:
// Replace the existing Identity line with this engineSettings.Identity = new Identity(appInfo.ApplicationId, IdentityType.ServicePrincipal);
3. Add Protection Removal Logic
After initializing the fileEngine, add code to acquire the SharePoint file handler and remove protection:
// Replace with your target SharePoint document URL string sharePointFileUrl = "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx"; // Configure options for the remote SharePoint file var handlerOptions = new FileHandlerOptions() { FileName = Path.GetFileName(sharePointFileUrl), FileState = FileState.Remote // Indicates we're working with a cloud-hosted file }; // Acquire the file handler from the engine var fileHandler = await fileEngine.AcquireFileAsync(sharePointFileUrl, handlerOptions); try { // Check if the file is actually protected before proceeding if (fileHandler.IsProtected) { // Remove the AIP protection await fileHandler.RemoveProtectionAsync(); // Commit changes back to SharePoint await fileHandler.CommitAsync(); } } finally { // Clean up resources fileHandler.Dispose(); await fileEngine.DisposeAsync(); await fileProfile.DisposeAsync(); }
4. Switch to Async/Await (Avoid Deadlocks)
Your current code uses Task.Run(async () => ...).Result which can cause deadlocks in web apps. Convert your controller action to an async method instead:
public async Task<IActionResult> RemoveDocumentProtection() { // Your existing initialization code here (updated with the correct Identity) // Add the protection removal logic above here return Ok("AIP protection removed successfully!"); }
If you prefer a lighter-weight approach without the MIP SDK dependency, you can use the Microsoft Information Protection REST API's RemoveProtection endpoint.
1. Required Permissions
Same as the SDK approach: your Azure AD app needs the application permissions InformationProtectionPolicy.Read.All, InformationProtectionPolicy.Write.All, and Sites.ReadWrite.All (with admin consent).
2. Get an Access Token
Use your existing authentication code to get a token for the resource https://api.microsoft.com:
AuthenticationContext authContext = new AuthenticationContext(authority, tokenCache); var clientCred = new ClientCredential(appInfo.ApplicationId, clientSecret); var result = await authContext.AcquireTokenAsync("https://api.microsoft.com", clientCred); string accessToken = result.AccessToken;
3. Call the REST API
Send a POST request to the removeProtection endpoint with details about your SharePoint file. You can use either the file's URL or its site/file GUIDs:
POST https://api.microsoft.com/informationprotection/removeProtection HTTP/1.1 Authorization: Bearer {access_token} Content-Type: application/json { "fileLocation": { "@odata.type": "#microsoft.graph.sharePointFileLocation", "siteUrl": "https://yourtenant.sharepoint.com/sites/yoursite", "fileUrl": "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx" } }
If you have the site and file GUIDs, you can use those instead for more precise targeting:
{ "fileLocation": { "@odata.type": "#microsoft.graph.sharePointFileLocation", "siteId": "12345678-1234-1234-1234-1234567890ab", "fileId": "98765432-4321-4321-4321-ba0987654321", "fileUrl": "https://yourtenant.sharepoint.com/sites/yoursite/Shared%20Documents/protected-document.docx" } }
Which Option Should You Choose?
- MIP SDK: Best if you need to handle file content, apply complex protection rules, or integrate with other MIP features (like labeling) in your app.
- REST API: Better for simple, one-off operations or when you want to avoid adding the MIP SDK dependency to your project.
内容的提问来源于stack exchange,提问作者Garima

