Microsoft loves acronyms — and a beloved concept often ends up with many names. Terms such as MIP, RMS, OME, and PME are frequently used interchangeably, even though they describe different parts of the protection model in Microsoft 365. In this article, we clear things up and explain how the three most important technologies work together to protect documents and emails across the Microsoft 365 platform.
When an organization uses sensitivity labels, three underlying technologies work together to identify, classify, and protect information:
- Microsoft Purview Information Protection (MIP)
- Azure Rights Management (RMS)
- Purview Message Encryption (PME)
Together, these technologies form the basic data protection model in Microsoft 365.
Microsoft Purview Information Protection (MIP)
MIP is the framework that governs how information is classified and labeled in Microsoft 365. Through MIP, organizations define what types of data exist, how they should be handled, and which restrictions apply when information is labeled with different sensitivity labels. This applies to documents, emails, and other formats such as PDF. These configurations are managed through the solutions in Microsoft Purview, such as Information Protection.
MIP is where protection rules are established in the form of policies. Which labels should exist? Who should use them? What level of protection should apply to each label? What should happen if sensitive information is detected? Should certain documents be encrypted? When a user selects a label in Word, Outlook, or Teams, it is MIP that determines which policy is triggered.

Azure Rights Management (RMS)
While MIP defines what should happen, RMS is the technology that actually enforces protection in form of encryption. RMS is Microsoft’s cloud-based encryption service — the engine that enforces access control and usage rights when a file is labeled with a sensitivity label configured with encryption.
Historically, RMS was delivered as part of Azure Information Protection (AIP). Although AIP as a product has been retired, the RMS engine lives on as an integrated part of MIP. It is still this technology that encrypts documents, generates the keys that determine who gets access, and validates users when content is opened — whether locally in Office applications, via web clients, or on mobile devices.
When a file is protected, RMS determines whether a user is allowed to read, edit, or print the content. RMS also follows the file outside the organization and ensures that protection is preserved even if the file ends up in the wrong hands.
Purview Message Encryption (PME)
Purview Message Encryption (PME) is the solution used to protect emails in Microsoft 365. Although PME is often referred to as a separate technology, it also uses RMS as its encryption engine. RMS therefore enforces access control for both files and emails, while PME adds a layer specifically tailored to how emails are sent, received, and opened.
The difference between document protection and email protection is not about which encryption engine is used, but about how the protection is delivered. When a document is labeled with a sensitivity label that includes protection rules, the file itself is encrypted and the protection travels with it wherever it goes. When an email is protected, this is handled by PME through Exchange, which uses RMS rules to determine who can read the email, how the recipient must authenticate, and whether forwarding or downloading is allowed.
PME provides an email-optimized presentation of the same access and protection rules that MIP defines and RMS enforces. This includes support for one-time passcodes, viewing through secure portals, blocking forwarding, and controlled sharing experiences for recipients outside the organization. The result is a consistent protection model where documents and emails are handled the same way at the policy and engine level, but differently in terms of user experience.
How the technologies fit together
To summarize:
- MIP defines how information should be classified and protected (the governance layer)
- RMS performs the encryption and enforces access (the encryption layer)
- PME handles encryption and access control in the email flow (the communication layer)
Together, these three technologies form the complete data protection model for documents and emails in Microsoft 365.
Learn more about MIP on Microsoft Learn