Virtru Platform Demo: ABAC for Outlook, SharePoint, and Beyond
See Virtru's attribute-based access control in action: ABAC-enforced email, ABAC file sharing across coalition partners, and tamper-resistant TDF encryption — end to end.
Attribute-Based Access Control for Multi-Domain Data Sharing
Securing sensitive data across coalition and multi-partner environments requires more than perimeter controls. Attribute-based access control (ABAC) enforces data access at the object level — evaluating user attributes like clearance, nationality, and role against data classifications in real time, on every access attempt. The result is dynamic, policy-driven access that follows the data wherever it goes.
This demo walks through Virtru's ABAC implementation in a self-managed environment, across the full data-sharing lifecycle. You'll see classification markings automatically ingested from Titus-tagged documents, outbound email blocked when recipient attributes don't match data policy, and ABAC file sharing enforced across a shared SharePoint repository — where three users with different clearance levels see different files in the same document library, without any manual folder permissioning.
Persistent Protection Beyond the Network Boundary
What distinguishes Virtru's approach is that ABAC enforcement travels with the file. Every protected object is encrypted with the Trusted Data Format (TDF) — an open standard that binds the ciphertext to its access policy. An authorized user can decrypt and open the file from any device, on any network. An unauthorized user cannot — even if they have the file in hand. The demo's final sequence demonstrates this directly: a TDF transferred to an unauthorized endpoint will not preview, will not decrypt, and will not yield to repeated attempts.
Virtru's Policy Enforcement Points (PEPs) apply consistent ABAC policy across email (Outlook), cloud file storage (SharePoint), and endpoint — all governed from a single control plane, without requiring separate infrastructure for each channel.
To learn more about how to deploy these capabilities for your organization, contact our team today for a demo.
Read transcript Hide transcript
In coalition and multi-domain operations, the hardest problem isn't encrypting data, it's sharing it. The Virtru platform delivers persistent attribute driven data protection across any type of data with no reliance on network perimeter controls. In this demo, you'll see a scenario using email and SharePoint, but you can imagine these same controls applied to any file type or workflow where sensitive information must be shared securely. We start with a data analyst, cleared at secret, Nationality USA, who has a SITREP report marked using Titus.
The platform ingests classification markings where ever they reside, document headers and footers, file metadata, X headers, or inline portion marks. No manual retagging required.
He drafts an email, adds Titus tags to the message, and attaches the report, addressing it to a coalition partner from the UK, also cleared it secret, but without the appropriate releasability attribute for this content.
When the user clicks send, the Virtru policy enforcement point intercepts the message. It authenticates the sender, then scans both the email body and all attachments against the active policy set.
The platform blocks delivery and identifies the specific unauthorized recipient.
Note that this is not a warning, it is a hard block. The send button is disabled and there is no dismissal path.
The user attempts to adjust the Titus label on the email itself to bypass the restriction, but it doesn't work.
The platform is scanning attachment markings independently and will take the most restrictive classification across every piece of content in the send. Email body, attachments, all of it. The policy is enforced at the data level, not just the message level.
Once the unauthorized recipient is removed, the message sends, and in sent items, both the message body and the attachment are now encrypted as PDF files.
The authorized recipient, a French partner cleared at top secret, opens the message in Outlook. The Virtru add in side panel handles decryption in line after authentication. No VPN, no special network. Authorization is resolved by the Virtru platform against the user's attributes. When the attachment is opened, it launches in the Virtru desktop application because the file carries a .tdf extension that marks it as a protected object. Any obligations bound to the policy are enforced at open time. In this case, the document is watermarked with the recipient's identity, tied to the authenticated session, not a static label.
The watermark follows whoever opens the file. The user can decrypt a local copy for offline work. The decryption event is logged. The user now uploads that file to a shared SharePoint document library.
The Virtru policy enforcement point connected to SharePoint intercepts the upload, reads the classification markings embedded in the file — secret, France, USA — and automatically re-encrypts it as a PDF on ingest. The file is protected the moment it enters the repository. Here's where attribute-based visibility trimming becomes concrete. This is the same document library, same URL, for all three users.
Claude Bardot, at top secret, with both France and USA releasability, sees the most files. George Washington, secret with USA releasability, sees a subset.
Nigel Hastings sees fewer still. No manual folder permissions, no separate repositories: one library, policy-enforced access at the object level.
Final test: What happens if a protected file ends up on the wrong machine? We take the PDF that Nigel Hastings is not authorized to access and place it directly on his desktop, simulating lateral movement or an accidental transfer. The Virtru Desktop Policy Enforcement Point intercepts the open request. Nigel's identity is evaluated against the file's policy.
He does not have the required attributes. The file will not preview. It will not decrypt. Repeated attempts return the same result.
The encryption is not dependent on the network, the device, or whether the user is inside or outside the boundary. The file is the enforcement point. The Virtru Platform delivers persistent attribute driven data protection across email, cloud repositories, and endpoints with policy enforced at the data object, not the perimeter. Classification is ingested automatically.
Encryption is applied on send, upload, and download. Unauthorized access is blocked at every layer, regardless of how the file travels.
Built on the Trusted Data Format open standard, designed for multi-domain, multi-partner mission environments. Whether you work for a government agency or a commercial organization, Virtru is simple to procure and fast to deploy, with optional support services available should you need them. Volume discounts are available for both licensing and support. To get started, visit virtru.com and request a demo.
Related Resources
Get expert insights on how to address your data protection challenges

Virtru Platform Demo: ABAC for Outlook, SharePoint, and Beyond

Zero Trust File Sharing with the Virtru Platform

The Virtru Platform: Extensible Security and SDKs for Mission Apps

How It Works: Virtru Collaborate

Virtru Collaborate: Eliminate the Tradeoff Between Compliance and Collaboration

Introducing Virtru Collaborate

Virtru Collaborate: Securely Store, Organize, and Share Sensitive Files

Google E2EE vs. Virtru for Gmail: Sender and Recipient Experience

Virtru Data Security Platform: Email Workflows

How to Use Virtru for Gmail

Virtru Secure Share for Microsoft OneDrive, SharePoint, and Teams

Virtru for Mergers and Acquisitions: 'It was immediately useful.'
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.