What are the main features and advantages of Foxit RMS UnProtect and Protect for Foxit Reader Plugin?
Rights Control – Protects sensitive PDFs with policy-based access rules.
Secure Access – Limits viewing, copying, and sharing permissions.
Policy Templates – Applies consistent protection settings with less effort.
Enterprise Integration – Works smoothly with rights management environments.
Protected Workflows – Supports safer document handling across business teams.
Professional Standards – Reliable controls preserve document integrity and compliance.
AD RMS Integration – Extends Microsoft AD RMS access control to PDFs.
Protect And Unprotect – Encrypts and decrypts RMS-protected PDFs inside Reader.
Rights Policy Templates – Uses official server templates plus custom permission sets.
Extended Policy Controls – Restricts pages, IP ranges, prints and accesses.
Core Capacity – Client coverage for Windows, macOS and Linux.
Important – No OCR, e-signatures or PDF editing included.
This plugin adds Microsoft Rights Management functions to Foxit PDF Reader, so a Reader installation can both apply RMS encryption to PDF files and remove it again when the user is authorised. It turns a free viewer into an RMS client for PDF documents without deploying a full PDF editor.
Central Rights Control – Permissions travel with the file, not the folder.
No Editor Needed – Reader users protect documents without a full editor.
Mixed Fleet Coverage – Same rights workflow across Windows, macOS, Linux.
Auditable Access – Records who opened which document and when.
Revocable Documents – Access can be withdrawn after files leave.
Familiar Office Workflow – Mirrors how Office files are RMS protected.
It encrypts the PDF against a Microsoft Rights Management server and writes the permission set into the file itself. In Foxit PDF Reader the user goes to Protect > Restrict Access, picks a rights policy template from the RMS server or defines permissions manually, and the file is saved in encrypted form. Removing protection is the reverse path: Protect > Restrict Access > Unrestricted Access, which only succeeds if the signed-in account holds the right to decrypt. Because the encryption is bound to the RMS server and not to a password, forwarding the file to an unauthorised colleague does not grant access.
No. The plugin is a client-side component and needs either Microsoft Azure Rights Management or an on-premise Active Directory Rights Management Services deployment behind it. With Azure RMS, the user signs in to the rights management service directly from Foxit PDF Reader. With on-premise AD RMS, the AD RMS mobile device extension has to be deployed and Foxit authorised on the server side before clients can connect. If your organisation has no RMS infrastructure at all, this plugin has nothing to talk to and will not protect anything.
The UnProtect-only plugin handles decryption of RMS-protected PDFs, while the UnProtect and Protect plugin adds the ability to apply RMS protection from the Reader client. In practice this decides whether your users are consumers of protected documents or also producers of them. A support desk that only needs to open classified PDFs from other departments can stay on the UnProtect edition. A team that classifies and encrypts its own contracts, HR files or board documents needs the Protect capability, because template-based encryption and permission settings are only available there.
| Function | RMS UnProtect | RMS UnProtect and Protect |
|---|---|---|
| Open protected PDFs | ✓ | ✓ |
| Remove RMS protection | ✓ | ✓ |
| Apply RMS protection | ✕ | ✓ |
| Rights policy templates | ✕ | ✓ |
| Windows, Mac, Linux | ✓ | ✓ |
No, the RMS plugin covers rights management only and contains no text recognition and no certificate-based or legally binding signature workflow. It also does not add page editing, form creation or conversion functions to Foxit PDF Reader. Buyers who need scanned documents made searchable, or who need a signed contract that holds up as evidence, need a PDF editor product in addition to this plugin. What the plugin does deliver instead is enforcement after distribution: the document owner can still restrict printing, copying and forwarding once the file is out of the building.
How to sign PDF documents safely
For more details about digital document workflows, read our guide:
Beyond the standard read, print and copy rights, the extended policy adds page-level access, an allowed IP range, a maximum number of accesses and a maximum number of prints. Dynamic security watermarks can also be stamped on the file so the viewer's identity is visible in screenshots or phone photos. An expiry date can be set, after which the document no longer opens. Note that the access-count and print-count limits require the web service and SQL configuration on an on-premise RMS server first, so they are not available out of the box in every environment.
Check which Foxit PDF Reader build is deployed on your clients, because RMS protection is tied to the MSI deployment package on Windows and to the edition downloaded from Foxit's own website on macOS. Reader builds obtained from other channels can typically only open protected files, and unlicensed use displays an evaluation watermark in the document. Second, confirm whether your RMS environment is Azure-based or on-premise, since on-premise deployments require the AD RMS mobile device extension and PowerShell authorisation of the Foxit client. Getting these two points wrong is the most common reason the Protect ribbon never appears for users.
Yes. The Foxit Configuration Tool includes dynamic revocation, which lets an administrator add either a specific document or a specific user to a revocation list. Revocation is handled on the RMS server side and requires the web service and SQL configuration to be in place first.
The recipient sees a wrapper page instead of the content, prompting them to install Foxit PDF Reader or Foxit PDF Editor to open the file. Administrators can replace that wrapper page with their own PDF, for example one carrying internal instructions or a helpdesk contact.
Yes, Microsoft IRM Specification V1, V2 and PPDF are supported, with IRM V2 used as the default format when PDFs are encrypted. Be aware that Microsoft IRM Protection does not carry Foxit's dynamic watermark, extended policy or dynamic revocation, so choosing IRM for interoperability means giving up those three controls.
Yes. Audit logging records who accessed a protected document, which document it was, when and how it was opened, and whether the attempt succeeded. Logs are viewed in the Foxit Configuration Tool and can be exported as a .reg file that administrators distribute to client machines.
| Operating Systems | Windows 11 Windows 10 Windows 8.1 Windows 7 |
| Processor | 1.3 GHz or faster x86 compatible processor, or ARM processor Microsoft SQ1 or better |
| Memory RAM | 512 MB minimum 1 GB or greater recommended |
| Hard Disk | 1 GB available hard drive space |
| Display | Standard display compatible with the respective operating system |
| Key Features & Modules | Open and decrypt RMS protected PDF files in Foxit Reader. Apply RMS protection and manage policy templates in Foxit Reader MSI package. Microsoft AD RMS integration with Microsoft AD RMS 2.1 compliance. RMS settings, metadata encryption, account switching, template refresh, unrestricted access workflow, wrapper prompt behavior for non Foxit viewers. No official evidence in the reviewed sources for OCR, batch processing, Bates numbering, Office plugins, or a virtual PDF printer in this plugin SKU. |
| Note | Available in Foxit Reader MSI package only for protect and unprotect workflows. A paid RMS license is required after the 14 day trial. Microsoft Rights Management Services Client 2.1 is a documented dependency. Current Foxit PDF Reader system requirements target Windows 10 and Windows 11. |
| Operating Systems |
macOS Sonoma 14 |
| Processor | Intel or Apple Silicon |
| Memory RAM | 1 GB RAM |
| Hard Disk | 1.2 GB available hard disk space |
| Display | Standard display compatible with the respective operating system |
| Key Features & Modules | RMS encryption and decryption inside Foxit PDF Reader for Mac. Auditing logs, extended policy handling, user revocation, wrapper customization, RMS account switching, and unrestricted access workflow are documented in the Mac manual. No separate Mac plugin installer page for this exact RMS Reader plugin SKU was found in the reviewed official sources. No official evidence in the reviewed sources for OCR, batch processing, Bates numbering, Office plugins, or a virtual PDF printer for this Mac RMS workflow. |
| Note | Foxit RMS workflows in Foxit PDF Reader for Mac. Foxit PDF Reader page supports macOS 10.15 through macOS 14. |
| Operating Systems | Linux kernel 2.6 or higher |
| Processor | 1.3 GHz or faster |
| Memory RAM | At least 512 MB RAM |
| Hard Disk | At least 1 GB available disk space |
| Display | Standard display compatible with the respective operating system |
| Key Features & Modules | RMS unprotect and protect plugin compatibility is listed for Linux on reseller system requirement pages. Foxit Reader version 9.0 or higher required. No official Foxit Linux technical page for this exact plugin SKU was found in the reviewed official sources. No official evidence in the reviewed sources for OCR, batch processing, Bates numbering, Office plugins, or a virtual PDF printer in this Linux plugin context. |
| Note |
Linux supports Foxit RMS UnProtect and Protect for Foxit Reader Plugin on Linux kernel 2.6 or higher. |
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies