Azure 信息保护客户端管理员指南Azure Information Protection client administrator guide

适用于: Active Directory Rights Management Services, Azure 信息保护,windows 10,Windows 8.1,windows 8,windows server 2019,windows server 2016,windows Server 2012 R2,windows server 2012Applies to: Active Directory Rights Management Services, Azure Information Protection, Windows 10, Windows 8.1, Windows 8, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

说明: 适用于 Windows 的 Azure 信息保护客户端Instructions for: Azure Information Protection client for Windows

备注

为了提供统一、简化的客户体验,Azure 门户中的 Azure 信息保护客户端(经典) 和标签管理 将于 2021 年 3 月 31 日 弃用 。To provide a unified and streamlined customer experience, Azure Information Protection client (classic) and Label Management in the Azure Portal are being deprecated as of March 31, 2021. 在此时间框架内,所有 Azure 信息保护客户都可以使用 Microsoft 信息保护统一标记平台转换到我们的统一标记解决方案。This time-frame allows all current Azure Information Protection customers to transition to our unified labeling solution using the Microsoft Information Protection Unified Labeling platform. 有关详细信息,请参阅官方弃用通知Learn more in the official deprecation notice.

若要部署 AIP 经典客户端,请打开支持票证以获取下载访问权限。To deploy the AIP classic client, open a support ticket to get download access.

如果你负责企业网络上的 Azure 信息保护客户端,或如果你想要获取除了 Azure 信息保护客户端用户指南以外的更多技术信息,请使用本指南中的信息。Use the information in this guide if you are responsible for the Azure Information Protection client on an enterprise network, or if you want more technical information than is in the Azure Information Protection client user guide.

例如:For example:

  • 了解此客户端的不同组件以及是否应安装这些组件Understand the different components of this client and whether you should install it

  • 如何为用户安装客户端,以及有关先决条件、安装选项和参数及验证检查的信息How to install the client for users, with information about prerequisites, installation options and parameters, and verification checks

  • 如何适应通常需要编辑注册表的自定义配置How to accommodate custom configurations that often require editing the registry

  • 查找客户端文件和使用情况日志Locate the client files and usage logs

  • 确定客户端支持的文件类型Identify the file types supported by the client

  • 为用户配置和使用文档跟踪站点Configure and use the document tracking site for users

  • 将客户端与 PowerShell 结合用于命令行控制Use the client with PowerShell for command-line control

是否有本文档未解决的问题?Have a question that's not addressed by this documentation? 请访问 Azure 信息保护 Yammer 站点Visit our Azure Information Protection Yammer site.

Azure 信息保护客户端的技术概述Technical overview of the Azure Information Protection client

Azure 信息保护客户端包括以下内容:The Azure Information Protection client includes the following:

  • 一个 Office 加载项,可安装 Azure 信息保护栏以便用户选择分类标签;一个功能区上的“保护”按钮,可获取其他选项****。An Office add-in, that installs the Azure Information Protection bar for users to select classification labels, and a Protect button on the ribbon for additional options. 对于 Outlook,在功能区上还可以使用“不转发”按钮****。For Outlook, a Do Not Forward button is also available for the ribbon.

  • Windows 文件资源管理器,便于用户将分类标签和保护应用到文件的右键单击选项。Windows File Explorer, right-click options for users to apply classification labels and protection to files.

  • 一个查看器,可在本机应用程序无法将其打开时显示受保护的文件。A viewer to display protected files when a native application cannot open it.

  • 一个 PowerShell 模块,用于从文件应用和删除分类标签和保护。A PowerShell module to apply and remove classification labels and protection from files.

    此模块包含 用于安装和配置 Azure 信息保护扫描程序(在 Windows Server 上作为服务运行)的 cmdlet。This module includes cmdlets to install and configure the Azure Information Protection scanner, which runs as a service on Windows Server. 借助此服务,可发现和保护数据存储(例如,网络共享和 SharePoint Server 库)中的文件并对其进行分类。This service lets you discover, classify, and protect files on data stores such as network shares and SharePoint Server libraries.

  • 权限管理客户端,可与 Azure 权限管理 (Azure RMS) 或 Active Directory Rights Management Services (AD RMS) 进行通信。The Rights Management client that communicates with Azure Rights Management (Azure RMS) or Active Directory Rights Management Services (AD RMS).

Azure 信息保护客户端最适合用于其 Azure 服务;Azure 信息保护及其数据保护服务(Azure 权限管理)。The Azure Information Protection client is best suited to work with its Azure services; Azure Information Protection and its data protection service, Azure Rights Management. 不过,Azure 信息保护客户端也可用于本地版本的 Rights Management ( AD RMS),只是存在一些限制。However, with some limitations, the Azure Information Protection client also works with the on-premises version of Rights Management, AD RMS. 有关 Azure 信息保护和 AD RMS 所支持功能的全面比较,请参阅比较 Azure信息保护和 AD RMSFor a comprehensive comparison of features that are supported by Azure Information Protection and AD RMS, see Comparing Azure Information Protection and AD RMS.

如果安装了 AD RMS,想迁移到 Azure 信息保护,请参阅从 AD RMS 迁移到 Azure 信息保护If you have AD RMS and want to migrate to Azure Information Protection, see Migrating from AD RMS to Azure Information Protection.

你是否应该部署 Azure 信息保护客户端?Should you deploy the Azure Information Protection client?

部署 Azure 信息保护客户端如果你不使用 Office 365 安全 & 符合性中心中的敏感标签 ,而是使用从 azure 下载的 Azure 信息保护标签,则可使用以下任一项:Deploy the Azure Information Protection client if you are not using sensitivity labels in the Office 365 Security & Compliance Center but instead, using Azure Information Protection labels that you download from Azure, and any of the following applies:

  • 想要通过从 Office 应用程序(Word、Excel、PowerPoint、Outlook)中选择标签对文档和电子邮件进行分类(或保护)。You want to classify (and optionally, protect) documents and email messages by selecting labels from within your Office applications (Word, Excel, PowerPoint, Outlook).

  • 想要通过使用文件资源管理器(支持除 Office、多选和文件夹支持的文件类型以外的其他文件类型)对文件进行分类(或保护)。You want to classify (and optionally, protect) files by using File Explorer, supporting additional file types than those supported by Office, multi-select, and folders.

  • 想要通过使用 PowerShell 命令运行对文档进行分类(或保护)的脚本。You want to run scripts that classify (and optionally, protect) documents by using PowerShell commands.

  • 想要运行一项服务来发现(或保护)存储在本地的文件并对其进行分类。You want to run a service that discovers, classifies (and optionally, protects) files that are stored on-premises.

  • 想要在本机应用程序显示未安装文件或无法打开这些文档时查看受保护的文档。You want to view protected documents when a native application to display the file is not installed or cannot open these documents.

  • 只想通过使用文件资源管理器或使用 PowerShell 命令保护文件。You want to just protect files by using File Explorer or by using PowerShell commands.

  • 想要用户和管理员能够跟踪和撤销受保护的文档。You want users and administrators to be able to track and revoke protected documents.

  • 想要从文件和容器(取消保护)批量删除加密,以进行数据恢复。You want to remove encryption from files and containers (unprotect) in bulk for data recovery purposes.

  • 运行 Office 2010 并且想要通过使用 Azure 权限管理服务保护文档和电子邮件。You run Office 2010 and want to protect documents and email messages by using the Azure Rights Management service.

示例显示了 Office 应用程序中的 Azure 信息保护客户端加载项、组织的分类标签,以及功能区上新的“保护”按钮****:Example showing the Azure Information Protection client add-in for an Office application, displaying the classification labels for your organization, and the new Protect button on the ribbon:

具有默认策略的 Azure 信息保护栏

安装和支持 Azure 信息保护客户端Installing and supporting the Azure Information Protection client

可通过使用可执行文件或 Windows Installer 文件来安装 Azure 信息保护客户端。You can install the Azure Information Protection client by using an executable or a Windows installer file. 如需详细了解每个选项和说明,请参阅为用户安装 Azure 信息保护客户端For more information about each choice, and instructions, see Install the Azure Information Protection client for users.

使用以下部分获取有关安装客户端的支持信息。Use the following sections for supporting information about installing the client.

安装检查和疑难解答Installation checks and troubleshooting

安装客户端后,请使用“帮助和反馈”选项打开“Microsoft Azure 信息保护”对话框********:When the client is installed, use the Help and Feedback option to open the Microsoft Azure Information Protection dialog box:

  • 在 Office 应用程序中:在“开始”选项卡上的“保护”组中,依次选择“保护”和“帮助和反馈”。From an Office application: On the Home tab, in the Protection group, select Protect, and then select Help and Feedback.

  • 在文件资源管理器中:右键单击选择一个/多个文件或文件夹,然后依次选择“分类和保护”和“帮助和反馈”。From File Explorer: Right-select a file, files, or folder, select Classify and protect, and then select Help and Feedback.

帮助和反馈”部分Help and Feedback section

默认情况下,“提供详细信息”**** 链接转到 Azure 信息保护网站,但也可以根据 Azure 信息保护策略中的一项策略设置,将其配置为转到自定义 URL。The Tell me more link by default, goes to the Azure Information Protection website but you can configure it for a custom URL as one of the policy settings in the Azure Information Protection policy.

仅当指定高级客户端设置时,才会显示“报告问题”链接****。The Report an Issue link displays only if you specify an advanced client setting. 配置此设置时,指定 HTTP 链接,例如支持人员的电子邮件地址。When you configure this setting, you specify an HTTP link such as the email address of your help desk.

“导出日志”**** 自动收集并附加 Azure 信息保护客户端的日志文件,如果必须将日志文件发送给 Microsoft 支持人员的话。The Export Logs automatically collects and attaches log files for the Azure Information Protection client if you have been asked to send these to Microsoft Support. 最终用户也可使用此选项将这些日志文件发送给你的支持人员。This option can also be used by end users to send these log files to your help desk.

“重置设置”会注销用户、删除当前下载的 Azure 信息保护策略,并重置 Azure Rights Management 服务的用户设置****。The Reset Settings signs out the user, deletes the currently downloaded Azure Information Protection policy, and resets the user settings for the Azure Rights Management service.

备注

如果客户端出现技术问题,请参阅 支持选项和社区资源If you have technical problems with the client, see Support options and community resources.

有关“重置设置”选项的详细信息More information about the Reset Settings option
  • 不是本地管理员也能使用此选项,并且不会在事件查看器中记录此操作。You do not have to be a local administrator to use this option and this action is not logged in the Event Viewer.

  • 除非文件被锁定,否则此操作将删除以下位置中的所有文件。Unless files are locked, this action deletes all the files in the following locations. 这些文件包括客户端证书、Rights Management 模板、Azure 信息保护策略和缓存的用户凭据。These files include client certificates, Rights Management templates, the Azure Information Protection policy, and the cached user credentials. 不会删除客户端日志文件。The client log files are not deleted.

    • %LocalAppData%\Microsoft\DRM%LocalAppData%\Microsoft\DRM

    • %LocalAppData%\Microsoft\MSIPC%LocalAppData%\Microsoft\MSIPC

    • %LocalAppData%\Microsoft\MSIP\Policy.msip%LocalAppData%\Microsoft\MSIP\Policy.msip

    • %LocalAppData%\Microsoft\MSIP\TokenCache%LocalAppData%\Microsoft\MSIP\TokenCache

  • 将删除以下注册表项和设置。The following registry keys and settings are deleted. 如果以下任意注册表项具有自定义值,则必须在重置客户端后重新对其进行配置。If the settings for any of these registry keys have custom values, these must be reconfigured after you reset the client.

    对于企业网络,通常使用组策略配置这些设置,在这种情况下,在计算机上刷新组策略时,将自动重新应用这些设置。Typically for enterprise networks, these settings are configured by using group policy, in which case they are automatically reapplied when group policy is refreshed on the computer. 但是,某些设置可能通过脚本一次性配置,或手动配置。However, there might be some settings that are configured one time with a script, or manually configured. 在这些情况下,必须执行其他步骤来重新配置这些设置。In these cases, you must take additional steps to reconfigure these settings. 例如,由于要从 AD RMS 迁移并且网络上仍有服务连接点,因此计算机要运行一次脚本才能配置用于重定向到 Azure 信息保护的设置。As an example, computers might run a script one time to configure settings for redirection to Azure Information Protection because you are migrating from AD RMS and still have a Service Connection Point on your network. 重置客户端后,计算机必须再次运行此脚本。After resetting the client, the computer must run this script again.

    • HKEY_CURRENT_USER \SOFTWARE\Microsoft\Office\15.0\Common\IdentityHKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Common\Identity

    • HKEY_CURRENT_USER \SOFTWARE\Microsoft\Office\14.0\Common\DRMHKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\14.0\Common\DRM

    • HKEY_CURRENT_USER \SOFTWARE\Microsoft\Office\15.0\Common\DRMHKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Common\DRM

    • HKEY_CURRENT_USER \SOFTWARE\Microsoft\Office\16.0\Common\DRMHKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\DRM

    • HKEY_CURRENT_USER \SOFTWARE\Classes\Local Settings\Software\Microsoft\MSIPCHKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\MSIPC

  • 当前登录的用户已注销。The currently signed in user is signed out.

客户端状态”部分Client status section

使用“连接身份”值来确认显示的用户名是否是要用于 Azure 信息保护身份验证的帐户。Use the Connected as value to confirm that the displayed user name identifies the account to be used for Azure Information Protection authentication. 此用户名必须与用于 Office 365 或 Azure Active Directory 的帐户匹配。This user name must match an account used for Office 365 or Azure Active Directory. 帐户还必须属于为 Azure 信息保护配置的租户。The account must also belong to a tenant that is configured for Azure Information Protection.

如果需要以与显示用户名不同的用户身份登录,请参阅以其他用户身份登录自定义项。If you need to sign in as a different user to the one displayed, see the Sign in as a different user customization.

“最后连接”**** 显示客户端最后一次连接到组织的 Azure 信息保护服务的时间。The Last connection displays when the client last connected to your organization's Azure Information Protection service. 可以将此信息与信息保护策略安装**** 日期和时间结合,以确认 Azure 信息保护策略上次安装或更新的时间。You can use this information with the Information Protection policy was installed on date and time to confirm when the Azure Information Protection policy was last installed or updated. 当客户端连接服务时,如果它发现与其当前策略有差异,则会自动下载最新策略,频率同样也是每 24 小时。When the client connects to the service, it automatically downloads the latest policy if it finds changes from its current policy, and also every 24 hours. 如果在显示时间后完成策略更改,关闭并重新打开 Office 应用程序。If you have made policy changes after the displayed time, close and reopen the Office application.

如果看到此客户端未获许可使用 Office Professional Plus:Azure 信息保护客户端检测到安装的 Office 版本不支持应用 Rights Management 保护。If you see This client is not licensed for Office Professional Plus: The Azure Information Protection client has detected that the installed edition of Office does not support applying Rights Management protection. 执行此检测时,便会发现应用保护的标签未显示在 Azure 信息保护栏上。When this detection is made, labels that apply protection do not display on the Azure Information Protection bar.

使用“版本”信息可以确认安装的是哪个版本的客户端。Use the Version information to confirm which version of the client is installed. 可以单击“最近更新”链接来查看客户端的“版本发行历史记录”,检查是否为最新发行版本以及相应的修补程序和新功能。You can check whether this is the latest release version and the corresponding fixes and new features by clicking the What's New link, to read the Version release history for the client.

支持多种语言Support for multiple languages

Azure 信息保护客户端支持 Office 365 支持的同种语言。The Azure Information Protection client supports the same languages that Office 365 supports. 有关这些语言的列表,请参阅 Office 国际可用性页面的 Office 365、Exchange Online Protection 和 Power BI**** 部分。For a list of these languages, see the Office 365, Exchange Online Protection, and Power BI section from the International availability page from Office.

对于这些语言,Azure 信息保护客户端中的菜单选项、对话框和消息将以用户的语言显示。For these languages, menu options, dialog boxes, and messages from the Azure Information Protection client display in the user's language. 由于有一个安装程序可检测语言,因此不需要进行额外配置即可安装不同语言的 Azure 信息保护客户端。There is a single installer that detects the language, so no additional configuration is required to install the Azure Information Protection client for different languages.

但是,在 Azure 信息保护策略中配置标签时,不会自动翻译指定的标签名称和说明。However, label names and descriptions that you specify are not automatically translated when you configure labels in the Azure Information Protection policy. 从 2017 年 8 月 30 日起,当前的默认政策包含对部分语言的支持。Beginning with August 30, 2017, the current default policy includes support for some languages. 若要以用户首选语言向其显示标签,必须提供你的翻译并将 Azure 信息保护策略配置为使用这些翻译。For users to see labels in their preferred language, provide your own translations and configure the Azure Information Protection policy to use these translations. 有关详细信息,请参阅如何在 Azure 信息保护中配置不同语言的标签For more information, see How to configure labels for different languages in Azure Information Protection. 视觉标记未翻译,且不支持多种语言。Visual markings are not translated and do not support more than one language.

安装后任务Post installation tasks

安装 Azure 信息保护客户端后,请务必告知用户如何标记文档和电子邮件,并指导用户如何选择适合特定方案的标签。After you have installed the Azure Information Protection client, make sure that you give users instructions for how to label their documents and emails, and guidance for which labels to choose for specific scenarios. 例如:For example:

升级和维护 Azure 信息保护客户端Upgrading and maintaining the Azure Information Protection client

Azure 信息保护团队会定期更新 Azure 信息保护客户端,以提供新功能和修补程序。The Azure Information Protection team regularly updates the Azure Information Protection client for new functionality and fixes. 公告会发布到团队的 Yammer 网站Announcements are posted to the team's Yammer site.

如果使用的是 Windows 更新,Azure 信息保护客户端会自动升级客户端的正式版本,无论客户端是如何安装的。If you are using Windows Update, the Azure Information Protection client automatically upgrades the general availability version of the client, irrespective of how the client was installed. 新客户端版本会在发布后的几周内发布到目录中。New client releases are published to the catalog a few weeks after the release.

或者,你可以使用更新的版本安装来手动升级客户端。Alternatively, you can manually upgrade the client with a newer release installation. 必须使用这种方法来升级预览版。You must use this method to upgrade preview versions.

手动升级时,只有当要更改安装方法时,才需要先卸载旧版本。When you manually upgrade, uninstall the previous version first only if you're changing the installation method. 例如,从客户端的可执行文件 (.exe) 版本更改为客户端的 Windows 安装程序 (.msi) 版本。For example, you change from the executable (.exe) version of the client to the Windows installer (.msi) version of the client. 或当需要安装旧版客户端时。Or, if you need to install a previous version of the client. 例如,出于测试目的已安装当前预览版,现在需要还原到当前正式版本。For example, you have the current preview version installed for testing and now need to revert to the current general availability version.

使用版本发行历史记录和支持策略了解 Azure 信息保护客户端的支持策略、目前支持的版本以及受支持版本的新增功能和变更之处。Use the Version release history and support policy to understand the support policy for the Azure Information Protection client, which versions are currently supported, and what's new and changed for the supported releases.

升级 Azure 信息保护扫描程序Upgrading the Azure Information Protection scanner

使用以下说明将扫描程序从早于1.48.204.0 的正式发行版升级到当前版本的扫描程序。Use the following instructions to upgrade the scanner from a general availability version older than 1.48.204.0 to the current version of the scanner.

将扫描仪升级到当前版本To upgrade the scanner to the current version

重要

对于平滑升级路径,请不要在运行扫描程序的计算机上安装 Azure 信息保护客户端,作为升级扫描仪的第一步。For a smooth upgrade path, do not install the the Azure Information Protection client on the computer running the scanner as your first step to upgrade the scanner. 请改用以下升级说明。Instead, use the following upgrade instructions.

从版本1.48.204.0 开始,先前版本中的升级过程会自动更改扫描程序,以从 Azure 门户获取其配置设置。Beginning with version 1.48.204.0, the upgrade process from previous versions automatically changes the scanner to gets its configuration settings from the Azure portal. 此外,还会更新扫描程序配置数据库的架构,并且还会从 AzInfoProtection 重命名此数据库:In addition, the schema is updated for the scanner's configuration database, and this database is also renamed from AzInfoProtection:

  • 如果未指定你自己的配置文件名称,则配置数据库将**AIPScanner_ <computer_name> **重命名。If you do not specify your own profile name, the configuration database is renamed AIPScanner_<computer_name>.

  • 如果指定自己的配置文件名称,则配置数据库将**AIPScanner_ <profile_name> **重命名。If you specify your own profile name, the configuration database is renamed AIPScanner_<profile_name>.

虽然可以按不同的顺序升级扫描程序,但建议执行以下步骤:Although it's possible to upgrade the scanner in a different order, we recommend the following steps:

  1. 使用 Azure 门户创建新的扫描程序配置文件,其中包含扫描程序和数据存储库的设置及其所需的任何设置。Use the Azure portal to create a new scanner profile that includes settings for the scanner and your data repositories with any settings that they need. 有关此步骤的帮助,请参阅从扫描程序部署说明 在 Azure 门户中配置扫描器For help with this step, see Configure the scanner in the Azure portal from the scanner deployment instructions.

    如果运行扫描程序的计算机与 internet 断开连接,则仍需执行此步骤。If the computer running the scanner is disconnected from the internet, you still need to do this step. 然后,在 Azure 门户中,使用“导出”**** 选项将扫描程序配置文件导出到文件中。Then, from the Azure portal, use the Export option to export your scanner profile to a file.

  2. 在扫描程序计算机上,停止扫描程序服务“Azure 信息保护扫描程序”****。On the scanner computer, stop the scanner service, Azure Information Protection Scanner.

  3. 通过 (GA) 版本安装当前的正式发行版来升级 Azure 信息保护客户端。Upgrade the Azure Information Protection client by installing the current general availability (GA) version.

  4. 在 PowerShell 会话中,使用你在步骤1中指定的相同配置文件名称运行 install-aipscanner 命令。In a PowerShell session, run the Update-AIPScanner command with the same profile name that you specified in step 1. 例如:Update-AIPScanner –Profile EuropeFor example: Update-AIPScanner –Profile Europe

  5. 仅当扫描程序在断开连接的计算机上运行时:立即运行 set-aipscannerconfiguration 并指定包含导出的设置的文件。Only if the scanner is running on a disconnected computer: Now run Import-AIPScannerConfiguration and specify the file that contains the exported settings.

  6. 重启 Azure 信息保护扫描程序服务“Azure 信息保护扫描程序”****。Restart the Azure Information Protection Scanner service, Azure Information Protection Scanner.

你现在可以使用 部署 Azure 信息保护扫描程序中的其余说明自动分类和保护文件,并忽略安装扫描程序的步骤。You can now use the rest of the instructions in Deploying the Azure Information Protection scanner to automatically classify and protect files, omitting the step to install the scanner. 由于已经安装了扫描仪,因此没有理由再次安装。Because the scanner is already installed, there's no reason to install it again.

如果在运行 Update-AIPScanner 命令之前未在 Azure 门户中配置扫描程序,则将没有要指定用于标识升级过程的扫描程序配置设置的配置文件名称。If you don't configure the scanner in the Azure portal before you run the Update-AIPScanner command, you won't have a profile name to specify that identifies your scanner configuration settings for the upgrade process.

在这种情况下,当在 Azure 门户中配置扫描程序时,必须指定与运行 Update-AIPScanner 命令时使用的完全相同的配置文件名称。In this scenario, when you configure the scanner in the Azure portal, you must specify exactly the same profile name that was used when you ran the Update-AIPScanner command. 如果名称不匹配,则不会为设置配置扫描程序。If the name doesn't match, the scanner will not be configured for your settings.

提示

若要识别具有此错误配置的扫描仪,请使用 Azure 门户中的 " Azure 信息保护-节点 " 窗格。To identify scanners that have this misconfiguration, use the Azure Information Protection - Nodes pane in the Azure portal.

对于具有 internet 连接的扫描仪,它们使用 Azure 信息保护客户端的正式版本号显示其计算机名称,但没有配置文件名称。For scanners that have internet connectivity, they display their computer name with the GA version number of the Azure Information Protection client, but no profile name. 只有版本号为1.41.51.0 的扫描仪才能在此窗格中显示 "配置文件名称"。Only scanners that have a version number 1.41.51.0 should display no profile name on this pane.

如果在运行 Update-AIPScanner 命令时未指定配置文件名称,则计算机名称将用于自动为扫描程序创建配置文件名称。If you didn't specify a profile name when you ran the Update-AIPScanner command, the computer name is used to automatically create the profile name for the scanner.

将扫描程序配置数据库移动到其他 SQL Server 实例Moving the scanner configuration database to a different SQL Server instance

在当前 GA 版中,如果在运行升级命令后尝试将扫描程序配置数据库移到新的 SQL Server 实例,则会出现一个已知问题。In the current GA version, there is a known issue if you try to move the scanner configuration database to a new SQL Server instance after you run the upgrade command.

如果你知道要移动 GA 版本的扫描程序配置数据库,请执行以下操作:If you know that you want move the scanner configuration database for the GA version, do the following:

  1. 使用 Uninstall-AIPScanner 卸载扫描程序。Uninstall the scanner by using Uninstall-AIPScanner.

  2. 如果尚未升级到 Azure 信息保护客户端的当前 GA 版本,请立即升级客户端。If you haven't yet upgraded to the current GA version of the Azure Information Protection client, upgrade the client now.

  3. 使用 Install-AIPScanner 安装扫描程序,指定新的 SQL Server 实例和配置文件名称。Install the scanner by using Install-AIPScanner, specifying the new SQL Server instance and profile name.

  4. 可选: 如果你不希望扫描程序重新扫描所有文件,请导出 ScannerFiles 表,然后将其导入到新数据库。Optional: If you do not want the scanner to rescan all files, export the ScannerFiles table and import it to the new database.

卸载 Azure 信息保护客户端Uninstalling the Azure Information Protection client

可使用以下任一选项卸载客户端:You can use any of the following options to uninstall the client:

  • 使用 "控制面板" 卸载程序:单击Microsoft Azure 信息保护 > 卸载Use Control Panel to uninstall a program: Click Microsoft Azure Information Protection > Uninstall

  • 重新运行可执行文件(如 AzInfoProtection.exe),并从“修改安装程序”**** 页上,单击“卸载”****。Rerun the executable (for example, AzInfoProtection.exe), and from the Modify Setup page, click Uninstall.

  • 使用 /uninstall 运行可执行文件。Run the executable with /uninstall. 例如: AzInfoProtection.exe /uninstallFor example: AzInfoProtection.exe /uninstall

后续步骤Next steps

要安装客户端,请参阅为用户安装 Azure 信息保护客户端To install the client, see Install the Azure Information Protection client for users.

若已安装客户端,要了解支持此客户端所需的其他信息,请参阅以下内容:If you've already installed the client, see the following for additional information that you might need to support this client: