You are designing a data security solution for a Microsoft 365 tenant that contains highly confidential files. You need to ensure that these files are encrypted and can only be accessed by authorized users, even if the files are downloaded and stored on a personal device. Which technology should you use?
Microsoft Purview Information Protection with encryption and usage rights is the current, unified file-protection service in Microsoft 365. It lets you apply labels that encrypt files (Word, Excel, PowerPoint, PDF) and attach usage rights—such as View, Edit, Copy, Print, and Forward—that are enforced by Azure Rights Management. These rights are embedded in the file metadata and travel with the file wherever it goes, so even if a user downloads a document to a USB stick or emails it to a third party, access is still governed by the policy. This persistent protection, combined with user-friendly labeling and DLP integration, makes it the correct answer for protecting data at rest and in motion within and outside the tenant.
Why this answer
Microsoft Purview Information Protection with encryption and usage rights (option B) is correct because it applies persistent protection to the file itself via sensitivity labels, so the encryption and usage restrictions travel with the document even after it is downloaded to a personal device, and only authorized users with the granted rights can open it. Office 365 Message Encryption (A) only protects email messages in transit and does not persist on files stored locally. BitLocker (C) encrypts the whole drive at the OS level, so protection is lost once the file leaves that device.
Azure Information Protection (D) is the legacy predecessor now superseded by Purview Information Protection, making B the current, appropriate choice.