{"id":743,"date":"2015-01-02T17:24:44","date_gmt":"2015-01-02T15:24:44","guid":{"rendered":"https:\/\/www.vioreliftode.com\/?p=743"},"modified":"2016-04-14T14:28:25","modified_gmt":"2016-04-14T12:28:25","slug":"classified-information-and-mobile-devices-challenges-with-sharepoint-office-web-apps-ad-rms","status":"publish","type":"post","link":"https:\/\/www.vioreliftode.com\/index.php\/classified-information-and-mobile-devices-challenges-with-sharepoint-office-web-apps-ad-rms\/","title":{"rendered":"Classified information and mobile devices (challenges with SharePoint + Office Web Apps + AD RMS)"},"content":{"rendered":"<input class=\"fooboxshare_post_id\" type=\"hidden\" value=\"743\"\/><p><em>Each company has its own security policies and defines ways to access <a href=\"http:\/\/en.wikipedia.org\/wiki\/Classified_information\" target=\"_blank\">classified information<\/a>. If we speak from security and technology point of view, a document can became unsecured as soon as is leaving the secured server where is stored. Encryption is indeed a good mechanism that allows classified information to be hosted for example on client devices (PC, notebook, tablet, smartphone \u2026), but the classified information owner doesn\u2019t have the same full control over the information as it has on the secured server.<\/em><br \/>\n<em> That&#8217;s why the information is classified. One extreme is to simply block, or make as hard as possible to access the information, case in which the solution will not be adopted by the users and will be expensive to implement and maintain. The other extreme is to not enforce any kind of protection, or control, case in which the trust is lost.<\/em><br \/>\n<em> The solution is somewhere in the middle &#8211; define ways to access classified information that prevents the majority of situations that can compromise \/ violate \/ cause damage.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>I personally think specific level of classified information can be accessed on mobile devices and in the same time still have specific level of control over it.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><span style=\"text-decoration: underline;\">Key technologies involved:<\/span><\/strong><\/p>\n<ul>\n<li><span style=\"text-decoration: underline;\">Office Web Apps<\/span> &#8211; <em>is an Office server product that delivers browser-based versions of Word, PowerPoint, Excel, and OneNote.<\/em> More details <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/dn135237(v=office.15).aspx\" target=\"_blank\">here<\/a> and <a href=\"http:\/\/en.wikipedia.org\/wiki\/Office_Online\" target=\"_blank\">here<\/a>.<\/li>\n<li><span style=\"text-decoration: underline;\">SharePoint<\/span> &#8211; <em>is a collaboration environment that organizations of all sizes can use to increase the efficiency of business processes. SharePoint 2013 sites provide secure environments that administrators can configure to provide personalized access to documents and other information. Search features enable users to find content efficiently regardless of the physical location of data.<\/em> More details <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/cc303422(v=office.15).aspx\" target=\"_blank\">here<\/a> and <a href=\"http:\/\/en.wikipedia.org\/wiki\/SharePoint\" target=\"_blank\">here<\/a>.<\/li>\n<li><span style=\"text-decoration: underline;\">Active Directory Rights Management Services (AD RMS)<\/span> &#8211; <em>is an information protection technology that works with AD RMS\u2013enabled applications to help safeguard digital information from unauthorized use. Content owners can define who can open, modify, print, forward, or take other actions with the information.<\/em> More details <a href=\"http:\/\/technet.microsoft.com\/en-us\/windowsserver\/dd448611.aspx\" target=\"_blank\">here<\/a> and <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/74272acc-0f2d-4dc2-876f-15b156a0b4e0.aspx\" target=\"_blank\">here<\/a>.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/blogs.office.com\/2012\/11\/09\/whats-new-with-information-rights-management-in-sharepoint-and-sharepoint-online\/\" target=\"_blank\">What\u2019s New with Information Rights Management in SharePoint and SharePoint Online?<\/a><br \/>\n<em>&#8220;Protected documents can be rendered in the browser\u000bAlso new to Office 2013, Office Web Apps can render protected documents. This means that if an authenticated user does not have a compatible Office client, they can still view the documents using Office Web Apps. Note that in the case of Web Apps, the document is presented in read-only mode. Also note that screen capturing of protected content in the browser is not blocked (as it is on clients), but, the information about the protected documents is cleared from the browser cache. Library admins can always prevent this capability by selecting the Prevent opening documents in the browser for this Document Library check box on the Information Right Management setting page (shown below in figure 5).&#8221;<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/support.office.com\/en-us\/article\/Use-Office-Online-on-your-Android-iPhone-or-Windows-Phone-8f8e95d5-d42e-4d96-9a53-fbf7d38c648d?ui=en-US&amp;rs=en-US&amp;ad=US\" target=\"_blank\">Use Office Online on your Android, iPhone, or Windows Phone<\/a><br \/>\n<em>&#8220;Thanks to the web browser in your cell phone, your phone can display online documents, using the mobile version of Office Online: Office Mobile Viewers. Office Mobile Viewers display Word, Excel, and PowerPoint documents that are stored online, or sent to your Microsoft email account as attachments. The documents are open for viewing only, not editing.&#8221;<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/blogs.technet.com\/b\/office_web_apps_server_2013_support_blog\/archive\/2014\/03\/12\/irm-information-rights-management-features-and-limitations-using-office-web-apps-on-premise.aspx\" target=\"_blank\">IRM (Information Rights Management) features and limitations using Office Web Apps On-Premise<\/a><br \/>\n<em>&#8220;Office Web Apps does not support the following features normally offered for non-IRM protected documents.\u00a0 These features are currently suppressed from the user interface:<\/em><\/p>\n<ul>\n<li><em>Edit in browser<\/em><\/li>\n<li><em>Print<\/em><\/li>\n<li><em>Save<\/em><\/li>\n<li><em>Copy selection<\/em><\/li>\n<li><em>Add comments&#8221;<\/em><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Almost all the above links refers to official Microsoft sites where Office Web Apps is advertised as being mobile capable (render Office Documents in browser) and also capable to render protected documents.<\/p>\n<p>&nbsp;<\/p>\n<p>SharePoint + Office Web Apps + AD RMS <span style=\"text-decoration: underline;\"><strong>can be<\/strong><\/span> an ideal platform to allow viewing sensitive documents on mobile devices. I implemented this setup and I experienced some limitations. I also discovered some security holes (in my opinion), but found ways to bypass them.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">The idea is simple:<\/span><\/p>\n<ol>\n<li>The documents stored on SharePoint are stored unencrypted. Basically the document is stored inside a MSSQL database, or Remote BLOB Storage. It is your IT department responsibility to secure the servers (MSSQL TDE, CipherPoint Eclipse for SharePoint, DocAve SharePoint Management \u2026).<\/li>\n<li>In SharePoint you can configure IRM (Information Rights Management) that will help you to apply a specific policy for your files.<\/li>\n<li>AD RMS will encrypt all the download documents applying the IRM policy previously defined.<\/li>\n<li>For the SharePoint Document Libraries where an IRM policy is defines, the browser view of the Office documents is read-only and has couple of additional protection layers (prevents right click, print, \u2026).<\/li>\n<li>The Office Web Apps Server can render in browser the office documents because in SharePoint the documents are stored unencrypted. That&#8217;s why is very important to secure (<a href=\"http:\/\/technet.microsoft.com\/en-us\/network\/bb531150.aspx\" target=\"_blank\">IPsec<\/a>) also the communication channels between MSSQL, SharePoint servers, Office Web Apps.<\/li>\n<li>Obviously you need to implement <a href=\"http:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security\" target=\"_blank\">TLS<\/a> for SharePoint, Office Web Apps, MSSQL.<\/li>\n<li>The user will be able to view the sensitive document on his mobile device in browser. The user needs connectivity with the SharePoint farm + Office Web Apps server (ideally through VPN).<\/li>\n<li>If the user downloads the file, the document will be protected by AD RMS. At this moment (the date when this article was written) the Office Mobile version is not capable to decrypt Office documents protected by AD RMS. So, basically the user has on its mobile device a document who contains sensitive data, but the document is encrypted and unusable on mobile devices. If the document is transferred to a PC, MS Office will require connectivity with the AD RMS servers. If the connectivity and user authentication is not performed with the RMS server, then the content remains inaccessible.<\/li>\n<li>No browsing caching for the secured view. Basically a &#8220;clean&#8221; device, in case is lost, or stolen.<\/li>\n<li>Indeed, screen capturing of protected content in the browser is not blocked, but such restrictions can be applied using a mobile device management solution.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>This setup is not &#8220;bullet proof&#8221;. The idea is to allow sensitive documents to be accessed from the mobile devices and in the same time apply some level of control and protection over the information delivered to those devices.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Indeed SharePoint + Office Web Apps + AD RMS are working <strong><span style=\"text-decoration: underline;\">almost<\/span><\/strong> as advertised in the above MS websites. I say <strong><span style=\"text-decoration: underline;\">almost<\/span><\/strong> because there are <span style=\"text-decoration: underline;\"><strong>two things that bothers me<\/strong><\/span>.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>1. The embed view does not work for the documents hosted by an IRM enabled document library.<\/strong><\/span><br \/>\nThis view is very useful because custom mobile apps can reuse this functionality (perfect for small screens). <a href=\"http:\/\/blogs.technet.com\/b\/office_web_apps_server_2013_support_blog\/archive\/2013\/12\/30\/office-web-apps-2013-sharepoint-2013-information-rights-management-irm-protected-document-libraries-preview-broken.aspx\" target=\"_blank\">Microsoft is aware of this issue<\/a>, but still no fix released.<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_01.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-746\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_01.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 01\" width=\"741\" height=\"461\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_01.png 741w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_01-300x186.png 300w\" sizes=\"(max-width: 741px) 100vw, 741px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_02.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-747\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_02.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 02\" width=\"765\" height=\"492\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_02.png 765w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_02-300x192.png 300w\" sizes=\"(max-width: 765px) 100vw, 765px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_03.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-748\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_03.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 03\" width=\"740\" height=\"481\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_03.png 740w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_03-300x195.png 300w\" sizes=\"(max-width: 740px) 100vw, 740px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>2. The protection against copy &amp; paste is available on the PC &amp; tablet view of Office Web Apps for the IRM enabled document libraries, but is not available (copy and paste is possible) on the mobile view (smartphones).<\/strong><\/span><br \/>\nBasically the look and feel is not consistent across devices. Protection against copy &amp; paste is kind of necessary in this case, otherwise I don&#8217;t see a big difference in not protecting at all the documents. It\u2019s again the &#8220;middle&#8221; scenario &#8211; you don&#8217;t block the access entirely, but for the majority of the users, preventing copy &amp; paste represents some level of control over the classified information.<\/p>\n<p>&nbsp;<\/p>\n<p>Next, I will reproduce the issue and also provide a way to bypass it (a workaround, not a fix).<br \/>\nI opened with Microsoft a support call [REG:114121212162050] and hopefully they will take it in consideration seriously &#8211; especially because this behavior is available also for the cloud version of SharePoint (SharePoint Online) and Office Web Apps (Office Online).<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Example of PC view of Office Web Apps for the IRM enabled document libraries.<\/span><br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_04.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-749\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_04-1024x783.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 04\" width=\"474\" height=\"362\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_04-1024x783.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_04-300x229.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_04.png 1035w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_05.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-750\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_05-1024x784.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 05\" width=\"474\" height=\"362\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_05-1024x784.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_05-300x229.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_05.png 1038w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_06.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-751\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_06-1024x783.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 06\" width=\"474\" height=\"362\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_06-1024x783.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_06-300x229.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_06.png 1035w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Example of tablet (iPad) view of Office Web Apps for the IRM enabled document libraries.<\/span><br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_07.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-752\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_07-1024x768.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 07\" width=\"474\" height=\"355\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_07-1024x768.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_07-300x225.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_07.png 2048w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_08.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-753\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_08-1024x768.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 08\" width=\"474\" height=\"355\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_08-1024x768.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_08-300x225.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_08.png 2048w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_09.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-754\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_09-1024x768.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 09\" width=\"474\" height=\"355\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_09-1024x768.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_09-300x225.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_09.png 2048w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Example of smartphone (iPhone) view of Office Web Apps for the IRM enabled document libraries.<\/span><br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_10.png\"><img loading=\"lazy\" class=\"alignleft wp-image-755 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_10-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 10\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_10-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_10-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_10.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><br \/>\nIf we look carefully, we can notice the Microsoft Word Web App view is different from the one provided for PC, or tablet. That&#8217;s because indeed the view is different. This time the browser rendering points the smartphone directly to the Office Web Apps server (the protected-right-click-and-copy-paste SharePoint view is not involved anymore).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_11.png\"><img loading=\"lazy\" class=\"alignleft wp-image-756 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_11-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 11\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_11-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_11-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_11.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><br \/>\nAnd because the Office Web Apps server is not aware of the IRM policy, it will simply provide the view for the mobile devices, same as a regular unprotected files (where copy and paste functionality is present)<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_12.png\"><img loading=\"lazy\" class=\"alignleft wp-image-757 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_12-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 12\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_12-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_12-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_12.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_13.png\"><img loading=\"lazy\" class=\"alignleft wp-image-758 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_13-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 13\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_13-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_13-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_13.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_14.png\"><img loading=\"lazy\" class=\"alignleft wp-image-759 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_14-300x169.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 14\" width=\"300\" height=\"169\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_14-300x169.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_14-1024x576.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_14.png 1136w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_15.png\"><img loading=\"lazy\" class=\"alignleft wp-image-760 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_15-300x169.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 15\" width=\"300\" height=\"169\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_15-300x169.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_15-1024x576.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_15.png 1136w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_16.png\"><img loading=\"lazy\" class=\"alignleft wp-image-761 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_16-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 16\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_16-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_16-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_16.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><br \/>\nThe mobile user can copy the URL of the mobile view, paste it into an e-mail and access the link on PC.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_17.png\"><img loading=\"lazy\" class=\"alignleft wp-image-762 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_17-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 17\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_17-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_17-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_17.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_18.png\"><img loading=\"lazy\" class=\"alignleft wp-image-763 size-large\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_18-1024x507.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 18\" width=\"474\" height=\"234\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_18-1024x507.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_18-300x148.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_18.png 1281w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_19.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-764\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_19-1024x783.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 19\" width=\"474\" height=\"362\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_19-1024x783.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_19-300x229.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_19.png 1036w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><br \/>\nCase in which the user was able to bypass the default protect view of Microsoft Word Web App (PC version).<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Workaround<\/strong><\/span><br \/>\n<span style=\"line-height: 1.5;\"><span style=\"text-decoration: underline;\">Attempt 1 &#8211; unsuccessful<\/span><br \/>\n<\/span><span style=\"line-height: 1.5;\">Office Web Apps has the App_Browsers part of each mobile view. Unfortunately configuring the browser definition file doesn&#8217;t work for Office Web Apps.<br \/>\n<\/span><span style=\"line-height: 1.5;\"><a href=\"\u000bhttp:\/\/technet.microsoft.com\/en-us\/library\/ff393836(v=office.15).aspx\" target=\"_blank\">\u000bhttp:\/\/technet.microsoft.com\/en-us\/library\/ff393836(v=office.15).aspx<\/a><br \/>\n<\/span><a href=\"http:\/\/sharepoint.smayes.com\/tag\/compat-browser\/\" target=\"_blank\"><span style=\"line-height: 1.5;\">http:\/\/sharepoint.smayes.com\/tag\/compat-browser\/<\/span><\/a><br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_20.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-765\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_20.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 20\" width=\"758\" height=\"480\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_20.png 758w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_20-300x189.png 300w\" sizes=\"(max-width: 758px) 100vw, 758px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\">Attempt 2 &#8211; successful<\/span><br \/>\nOn the Office Web Apps servers install <a href=\"http:\/\/www.iis.net\/downloads\/microsoft\/url-rewrite\" target=\"_blank\">URL Rewrite<\/a> IIS extension and configure the server to &#8220;believe&#8221; all the request sent by the mobile devices (defined in the compat.browser) are in fact requests sent by tablets.<\/p>\n<p>&nbsp;<\/p>\n<p>Office Web Apps is a HTTP based solution and is heavily relying on the IIS web server. The workaround is simple.<br \/>\nThe in-browser view of Office Documents for PCs and tablets is in fact a SharePoint page with an IFRAME where the Office Web Apps response is displayed.<br \/>\nOffice Web Apps server has a simplified view designed for mobile devices. When a user who&#8217;s using a smartphone connects on SharePoint and access for example a MS word document, he is accessing the same IFRAME&#8217;ed SharePoint page (as for PC and tablets), but this time the Office Web Apps response is &#8220;window.top.location.replace&#8221; who redirects the mobile device to the simplified view (the response is not trapped in the frame controlled\u00a0by the SharePoint page). \u000bThe problem now is the simplified mobile view doesn&#8217;t have any kind of copy &amp; paste protection implemented for the IRM enabled document libraries.<\/p>\n<p>&nbsp;<\/p>\n<p>The URL Rewrite module allows the web server administrators to control the userAgent string and change it as they wish. Office Web Apps server rely on the userAgent string to figure out what kind of response will provide (PC\/Tablet or mobile view). So, basically if we are able to control the userAgent string, we are able to control the Office Web Apps behavior.<\/p>\n<p>&nbsp;<\/p>\n<p>OK, but the PC\/Tablet view is not optimized for small screens (mobile devices). This is true, is not optimized, but is also not looking that bad (see the bellow screenshots &#8211; iPhone 5).<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_21.png\"><img loading=\"lazy\" class=\"alignleft wp-image-766 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_21-300x169.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 21\" width=\"300\" height=\"169\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_21-300x169.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_21-1024x576.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_21.png 1136w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nThe landscape view is quite close to how it looks on PC and tablet.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_22.png\"><img loading=\"lazy\" class=\"alignleft wp-image-767 size-medium\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_22-169x300.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 22\" width=\"169\" height=\"300\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_22-169x300.png 169w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_22-576x1024.png 576w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_22.png 640w\" sizes=\"(max-width: 169px) 100vw, 169px\" \/><\/a><br \/>\nThe portrait view is indeed not practical, but this time is the protected view (copy &amp; paste not possible) and let&#8217;s not forget this is a workaround &#8211; provide the PC\/tablet view (not optimized for small screens) to mobile devices.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>How to configure IIS URL Rewrite to control the userAgent string?<\/strong><\/span><br \/>\n<strong>1.<\/strong> You need to <a href=\"http:\/\/www.iis.net\/downloads\/microsoft\/url-rewrite\" target=\"_blank\">download<\/a> and install IIS URL Rewrite module on the Office Web Apps server.<br \/>\n<strong>2.<\/strong> At the <span style=\"text-decoration: underline;\"><strong>server level<\/strong><\/span> configure HTTP_USER_AGENT as managed server variable.<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_23.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-768\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_23.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 23\" width=\"989\" height=\"762\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_23.png 989w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_23-300x231.png 300w\" sizes=\"(max-width: 989px) 100vw, 989px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_24.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-769\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_24.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 24\" width=\"989\" height=\"763\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_24.png 989w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_24-300x231.png 300w\" sizes=\"(max-width: 989px) 100vw, 989px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_25.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-770\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_25.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 25\" width=\"990\" height=\"763\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_25.png 990w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_25-300x231.png 300w\" sizes=\"(max-width: 990px) 100vw, 990px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>3.<\/strong> Add the following URL rewrite rule to the web.config located in C:\\Program Files\\Microsoft Office Web Apps\\RootWebSite.<\/p>\n<pre class=\"brush: xml; title: ; notranslate\" title=\"\">\r\n&amp;lt;system.webServer&amp;gt;\r\n\t&amp;lt;rewrite&amp;gt;\r\n\t\t&amp;lt;rules&amp;gt;\r\n\t\t\t&amp;lt;rule name=&quot;IsNotMobile&quot; enabled=&quot;true&quot; patternSyntax=&quot;ECMAScript&quot; stopProcessing=&quot;true&quot;&amp;gt;\r\n\t\t\t\t&amp;lt;match url=&quot;.*&quot; \/&amp;gt;\r\n\t\t\t\t&amp;lt;action type=&quot;None&quot; logRewrittenUrl=&quot;true&quot; \/&amp;gt;\r\n\t\t\t\t&amp;lt;serverVariables&amp;gt;\r\n\t\t\t\t\t&amp;lt;set name=&quot;HTTP_USER_AGENT&quot; value=&quot;Mozilla\/5.0 (iPad; CPU OS 7_1_2 like Mac OS X) AppleWebKit\/537.51.2 (KHTML, like Gecko) Version\/7.0 Mobile\/11D257 Safari\/9537.53&quot; \/&amp;gt;\r\n\t\t\t\t&amp;lt;\/serverVariables&amp;gt;\r\n\t\t\t\t&amp;lt;conditions&amp;gt;\r\n\t\t\t\t\t&amp;lt;add input=&quot;{HTTP_USER_AGENT}&quot; pattern=&quot;((iPhone)|(HTC)|(SAMSUNG)|([Ss]amsung)|(Nokia)|(BlackBerry)|(SymbianOS)|(Android)|(Mobile)|(Dolfin)|(Windows Phone)|(Windows CE)|(DoCoMo)|(FOMA)|(UP.Browser)|(SoftBank)|(MIB)|(KDDI)|(KYOCERA)|(T-Mobile Dash)|(KUN)|(S[0-9]*HT)|(NetFront)|(Mozilla\/4.0 \\(compatible; MSIE 6.0; Windows NT 5.1; T-01A\\)))&quot; \/&amp;gt;\r\n\t\t\t\t&amp;lt;\/conditions&amp;gt;\r\n\t\t\t&amp;lt;\/rule&amp;gt;\r\n\t\t&amp;lt;\/rules&amp;gt;\r\n\t&amp;lt;\/rewrite&amp;gt;\r\n&amp;lt;\/system.webServer&amp;gt;\r\n<\/pre>\n<p><a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_26.png\"><img loading=\"lazy\" class=\"alignleft size-full wp-image-771\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_26.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 26\" width=\"941\" height=\"866\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_26.png 941w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_26-300x276.png 300w\" sizes=\"(max-width: 941px) 100vw, 941px\" \/><\/a><\/p>\n<p>This URL rewrite rule is simply catching all the requests sent by mobile devices (where the HTTP_USER_AGENT string matches mobile devices) and replace it with another string (in my case the iPad userAgent string).<\/p>\n<p>Based on my checks the output provided by Office Web Apps to iPad is generally compatible \/ can be rendered without problems on all the other mobile devices.<br \/>\n<a href=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_27.png\"><img loading=\"lazy\" class=\"alignleft size-large wp-image-772\" src=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_27-1024x845.png\" alt=\"Classified information and mobile devices challenges with SharePoint Office Web Apps AD RMS 27\" width=\"474\" height=\"391\" srcset=\"https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_27-1024x845.png 1024w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_27-300x247.png 300w, https:\/\/www.vioreliftode.com\/wp-content\/uploads\/2015\/01\/Classified_information_and_mobile_devices_challenges_with_SharePoint_Office_Web_Apps_AD_RMS_27.png 1157w\" sizes=\"(max-width: 474px) 100vw, 474px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Each company has its own security policies and defines ways to access classified information. If we speak from security and technology point of view, a document can became unsecured as soon as is leaving the secured server where is stored. Encryption is indeed a good mechanism that allows classified information to be hosted for example &hellip; <a href=\"https:\/\/www.vioreliftode.com\/index.php\/classified-information-and-mobile-devices-challenges-with-sharepoint-office-web-apps-ad-rms\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Classified information and mobile devices (challenges with SharePoint + Office Web Apps + AD RMS)<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"Classified information and mobile devices (challenges with SharePoint + Office Web Apps + AD RMS) http:\/\/wp.me\/p4NfDd-bZ","jetpack_is_tweetstorm":false},"categories":[32,29],"tags":[44,48,57,58,8,9],"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4NfDd-bZ","_links":{"self":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts\/743"}],"collection":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/comments?post=743"}],"version-history":[{"count":0,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/posts\/743\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/media?parent=743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/categories?post=743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vioreliftode.com\/index.php\/wp-json\/wp\/v2\/tags?post=743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}