Define what a usage right controls
IRM associates permitted usage with protected content and identities, but behavior depends on application, format and mechanism. In the inspected Microsoft documentation, use licenses allow protected content to be opened while valid without fresh authorization on every opening. That does not mean every application supports offline access. Distinguish file access, read or edit rights and privileged-identity exceptions. The protection issuer has special capabilities; do not test only that account to establish that an ordinary recipient lost access. An any-authenticated-user configuration may encrypt content without restricting the audience to a specific list. Encryption and recipient selection are separate decisions.
Revocation depends on license, identity and copy
The worksheet assumes an ordinary recipient with a license valid until 09:00 UTC the next day. Group membership is removed at 10:00 UTC today, leaving 23 hours of validity under the exercise assumptions. Do not declare immediate revocation without examining the license and client offline capability. Tracking documentation also describes downloaded copies receiving a new ContentID under certain conditions: revoking the original identifier does not establish revocation of those copies. Record file, protection mechanism, relevant identifier, identity, application, online/offline mode and test time. No tenant was operated in this lesson. The validation plan should use representative recipients and include legitimate success, expected denial and known limitations.
Select sanitization for relevant data and media
Sanitization seeks to make target-data recovery infeasible for a defined effort level. The current inspected reference is NIST SP800-88 Rev.2, finalized in September 2025, with a July2026 FAQ. Distinguish clear, purge and destroy according to required protection, media and reuse; do not choose a technique by habit or command name. SSDs and magnetic media do not share all properties. Virtual storage abstracts physical media and requires understanding effective options and provider evidence. A volume removed from the console or an absent file does not alone establish sanitization of every copy. NIST guidance needs appropriate scope; federal-agency-specific requirements are not automatically universal obligations.
Check cryptographic-erase preconditions
Cryptographic erase depends on suitable cryptography, prior data protection and handling relevant keys. In the worksheet, the primary key was removed, but an escrow key copy remains and an export is unassessed; data had also been stored in plaintext before encryption. Those conditions prevent declaring the objective demonstrated merely by removing the key. Changing an alias, revoking permission or temporarily disabling a key is also not equivalent to sanitizing material that enables decryption. In a wrapping design, identify every path to recover data keys and copy scope. Selective sanitization needs confidence that target data never escaped the encrypted boundary considered. The exercise deletes no actual keys or media.
Separate technical completion from result acceptance
Operation verification inspects outcomes, errors and anomalies. Validation decides whether sanitization was effective for relevant data, sensitivity and risks. A command may finish successfully without a technique suitable for the medium or covering the entire target. Record method, technique, tool and version, media identity, outcome, owners and disposition. Rev.2 does not impose universal elaborate sampling after clear or purge unless policy requires it; that does not remove the need for assurance. If scope is insufficient or risk unacceptable, do not accept completion without appropriate further treatment. Summary: revoking usage, deleting a reference and sanitizing data are distinct outcomes. Coordinate applicable retention and preservation before any actual destructive action.
FICTIONAL WORKSHEET, NO TENANT OR MEDIA CHANGED
Recipient: ordinary, neither issuer nor owner
License granted: 2026-10-07 09:00Z
Group removed: 2026-10-07 10:00Z
Cached license valid until: 2026-10-08 09:00Z
Remaining validity: 23 hours; immediate revocation unproven
Original: ContentID c1; copy: ContentID c2
Revoking c1 does not establish revoking c2
Sanitization: primary key removed; escrow remains
Prior plaintext: yes; unassessed export: yes
Tool reports success; adequate target scope unproven
CE acceptance and validation: pending/rejected in this worksheet.A still-valid fictional license may retain offline usage; an escrow key and prior plaintext prevent concluding sanitization from the primary key alone.
Common pitfalls
Testing the issuer as an ordinary recipient; ignoring copy ContentIDs; confusing permission removal with key destruction; command success as complete validation.
Related topics: Architecture, identity and data lifecycle · Acceptance criteria and operations
Distinguish revocation, copies and sanitization with evidence suited to mechanism and scope.
Reference: Guidelines for Media Sanitization · CCSP examination outline effective 2026-08-01; January2026 V2 PDF