<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Foxit RMS UnProtect and Protect for Foxit Reader Plugin?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>AD RMS Integration</strong> – Extends Microsoft AD RMS access control to PDFs.<br /> <strong>Protect And Unprotect</strong> – Encrypts and decrypts RMS-protected PDFs inside Reader.<br /> <strong>Rights Policy Templates</strong> – Uses official server templates plus custom permission sets.<br /> <strong>Extended Policy Controls</strong> – Restricts pages, IP ranges, prints and accesses.<br /> <strong>Core Capacity</strong> – Client coverage for Windows, macOS and Linux.<br /> <strong>Important</strong> – No OCR, e-signatures or PDF editing included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Foxit RMS UnProtect and Protect for Foxit Reader Plugin?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This plugin adds Microsoft Rights Management functions to Foxit PDF Reader, so a Reader installation can both apply RMS encryption to PDF files and remove it again when the user is authorised. It turns a free viewer into an RMS client for PDF documents without deploying a full PDF editor.<br /> <br /> <strong>Central Rights Control</strong> – Permissions travel with the file, not the folder.<br /> <strong>No Editor Needed</strong> – Reader users protect documents without a full editor.<br /> <strong>Mixed Fleet Coverage</strong> – Same rights workflow across Windows, macOS, Linux.<br /> <strong>Auditable Access</strong> – Records who opened which document and when.<br /> <strong>Revocable Documents</strong> – Access can be withdrawn after files leave.<br /> <strong>Familiar Office Workflow</strong> – Mirrors how Office files are RMS protected.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="https://keys.express/EN/blog/post/creating-professional-pdfs-step-by-step-guides-for-word-and-pdf-expert" target="_blank"><strong>Create professional PDFs with Word and PDF tools</strong><br />For help with document and PDF workflows, read our guide:</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What does the Foxit RMS plugin actually do to a PDF?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">It encrypts the PDF against a Microsoft Rights Management server and writes the permission set into the file itself. In Foxit PDF Reader the user goes to Protect &gt; Restrict Access, picks a rights policy template from the RMS server or defines permissions manually, and the file is saved in encrypted form. Removing protection is the reverse path: Protect &gt; Restrict Access &gt; Unrestricted Access, which only succeeds if the signed-in account holds the right to decrypt. Because the encryption is bound to the RMS server and not to a password, forwarding the file to an unauthorised colleague does not grant access.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the plugin work without a Microsoft RMS server?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The plugin is a client-side component and needs either Microsoft Azure Rights Management or an on-premise Active Directory Rights Management Services deployment behind it. With Azure RMS, the user signs in to the rights management service directly from Foxit PDF Reader. With on-premise AD RMS, the AD RMS mobile device extension has to be deployed and Foxit authorised on the server side before clients can connect. If your organisation has no RMS infrastructure at all, this plugin has nothing to talk to and will not protect anything.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the UnProtect plugin and the UnProtect and Protect plugin?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The UnProtect-only plugin handles decryption of RMS-protected PDFs, while the UnProtect and Protect plugin adds the ability to apply RMS protection from the Reader client. In practice this decides whether your users are consumers of protected documents or also producers of them. A support desk that only needs to open classified PDFs from other departments can stay on the UnProtect edition. A team that classifies and encrypts its own contracts, HR files or board documents needs the Protect capability, because template-based encryption and permission settings are only available there.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Function</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">RMS UnProtect</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">RMS UnProtect and Protect</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Open protected PDFs</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Remove RMS protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Apply RMS protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Rights policy templates</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Windows, Mac, Linux</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this plugin include OCR or legally binding e-signatures?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No, the RMS plugin covers rights management only and contains no text recognition and no certificate-based or legally binding signature workflow. It also does not add page editing, form creation or conversion functions to Foxit PDF Reader. Buyers who need scanned documents made searchable, or who need a signed contract that holds up as evidence, need a PDF editor product in addition to this plugin. What the plugin does deliver instead is enforcement after distribution: the document owner can still restrict printing, copying and forwarding once the file is out of the building.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="https://keys.express/EN/blog/post/how-to-safely-and-reliably-sign-your-pdf-document" target="_blank"><strong>How to sign PDF documents safely</strong><br />For more details about digital document workflows, read our guide:</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which permissions can be enforced on a protected document?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Beyond the standard read, print and copy rights, the extended policy adds page-level access, an allowed IP range, a maximum number of accesses and a maximum number of prints. Dynamic security watermarks can also be stamped on the file so the viewer's identity is visible in screenshots or phone photos. An expiry date can be set, after which the document no longer opens. Note that the access-count and print-count limits require the web service and SQL configuration on an on-premise RMS server first, so they are not available out of the box in every environment.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should administrators check before choosing this plugin?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Check which Foxit PDF Reader build is deployed on your clients, because RMS protection is tied to the MSI deployment package on Windows and to the edition downloaded from Foxit's own website on macOS. Reader builds obtained from other channels can typically only open protected files, and unlicensed use displays an evaluation watermark in the document. Second, confirm whether your RMS environment is Azure-based or on-premise, since on-premise deployments require the AD RMS mobile device extension and PowerShell authorisation of the Foxit client. Getting these two points wrong is the most common reason the Protect ribbon never appears for users.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Foxit RMS UnProtect and Protect for Foxit Reader Plugin</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can access to an already distributed PDF be withdrawn later?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The Foxit Configuration Tool includes dynamic revocation, which lets an administrator add either a specific document or a specific user to a revocation list. Revocation is handled on the RMS server side and requires the web service and SQL configuration to be in place first.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens if a protected PDF is opened in another PDF viewer?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The recipient sees a wrapper page instead of the content, prompting them to install Foxit PDF Reader or Foxit PDF Editor to open the file. Administrators can replace that wrapper page with their own PDF, for example one carrying internal instructions or a helpdesk contact.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is the encryption compatible with Microsoft's own IRM format?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, Microsoft IRM Specification V1, V2 and PPDF are supported, with IRM V2 used as the default format when PDFs are encrypted. Be aware that Microsoft IRM Protection does not carry Foxit's dynamic watermark, extended policy or dynamic revocation, so choosing IRM for interoperability means giving up those three controls.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can document access be logged for compliance reporting?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Audit logging records who accessed a protected document, which document it was, when and how it was opened, and whether the attempt succeeded. Logs are viewed in the Foxit Configuration Tool and can be exported as a .reg file that administrators distribute to client machines.</p>