Skip to main content

PDF Double Key Encryption with Adobe Acrobat

Applies to:
Adobe Acrobat ProAdobe Acrobat StandardAdobe Acrobat ReaderMicrosoft PurviewMPIP LabelsDKE

Overview​

Adobe Acrobat supports Microsoft Purview Information Protection (MPIP) with native Double Key Encryption (DKE) integration. This allows your users to apply DKE sensitivity labels directly from Adobe Acrobat — protecting PDF documents with the same level of encryption as Word, Excel, and PowerPoint files.

Native PDF Protection

Apply DKE labels directly from Adobe Acrobat's Protect PDF menu — no plugins required

Double Key Encryption

PDF content is encrypted with two keys — one from Microsoft, one from DuoKey. Microsoft never has access to the full key.

Zero Trust Ready

Combined with DuoKey's Zero Trust Access Control, control who can decrypt PDFs by user, IP, location, and group

Prerequisites

  • Adobe Acrobat Pro, Standard, or Reader — version 23.003.20201 or later (June 2023+)
  • DuoKey DKE Web Service configured and operational
  • Microsoft Purview sensitivity labels with DKE configured
  • Windows 10/11 or macOS
  • Microsoft 365 E5 or equivalent license with Purview Information Protection

Part 1: Administrator Setup​

Step 1: Request Adobe Client ID​

Before enabling DKE for PDF, you need to register the Adobe Client ID with your DuoKey DKE service.

Contact DuoKey Support

Contact DuoKey Support and request DKE support for PDF

Receive Confirmation

The support team will add the Adobe Client ID to your existing DKE Web Service application
Note
This is a one-time setup. Once the Adobe Client ID is registered, all users in your organization can use DKE labels in Adobe Acrobat.

Step 2: Configure Windows Registry​

Add the following three DWORD (32-bit) registry values to enable DKE, external browser authentication, and MPIP labeling in Adobe Acrobat.

Registry Path​

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown
Important
For 32-bit Acrobat on 64-bit Windows, use the WOW6432Node path instead: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown

Required Registry Values​

NameTypeValueDescription
bEnableDKEAdminREG_DWORD1Enables Double Key Encryption support in Acrobat
bMIPExternalAuthAdminREG_DWORD1Enables browser-based authentication for MPIP (required for DKE)
bMIPLabellingREG_DWORD1Enables Microsoft Purview sensitivity labeling in Acrobat
Tip
You can deploy these registry values via Group Policy (GPO), Microsoft Intune, or SCCM for organization-wide rollout.

Step 2b: Configure macOS (Alternative)​

For macOS deployments, use the following Terminal commands:

Step 3: Configure Adobe Acrobat Security Settings​

In Adobe Acrobat, certain security settings must be adjusted for DKE to function properly.

Open Preferences

In Adobe Acrobat, go to Menu > Preferences (or press Ctrl + K)

Navigate to Security

Select Security (Enhanced) in the left panel

Disable Protected Mode

Uncheck Enable Protected Mode at startup

Disable Enhanced Security

Uncheck Enable Enhanced Security

Restart Acrobat

Close and reopen Adobe Acrobat for changes to take effect
SettingRequired ValueReason
Enable Protected Mode at startupDisabledProtected Mode prevents DKE service communication
Enable Enhanced SecurityDisabledEnhanced Security blocks external key service calls
Warning
Disabling these settings is required for DKE to communicate with the DuoKey key service. This is a known Adobe requirement documented in their official MPIP support guide.

Optional: Enable Document Message Bar (DMB)​

The Document Message Bar shows the applied sensitivity label at the top of protected documents.

Windows Registry​

Computer\HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\MicrosoftAIP
NameTypeValue
bShowDMBREG_DWORD1

Optional: Mandatory Labeling​

Force users to apply a sensitivity label before saving any PDF document.

Registry PathNameTypeValue
...\FeatureLockDownbMIPCheckPolicyOnDocSaveREG_DWORD1
Note
Mandatory labeling must also be configured in the Microsoft Purview Compliance Portal under label policies for it to take effect.

Part 2: Applying DKE Labels to PDF Documents​

Once the administrator setup is complete, end users can apply DKE sensitivity labels to any PDF document.

Step 1: Open the PDF and Access Protection​

Open a PDF document in Adobe Acrobat, then navigate to the Protect a PDF panel.

Go to All tools > Protect a PDF > Select a Microsoft Sensitivity Label.

Protect a PDF - Menu

Step 2: Select a Microsoft Sensitivity Label​

Click Select a Microsoft Sensitivity Label. The tooltip shows "Powered by Microsoft Information Protection".

Select a Microsoft Sensitivity Label

Step 3: Choose the DKE Label​

A dialog box appears with all available sensitivity labels from your Microsoft Purview configuration. Select your DKE label (e.g., "DuoKey - Double Key Encryption").

Select DKE Label

The available labels shown are your organization's Purview sensitivity labels:

  • DuoKey - Double Key Encryption — DKE protected (highest protection)
  • Interne, Restreint, Confidentiel, Secret — Standard MPIP labels
  • Public, Restricted, Internal — Other classification levels

Step 4: Apply the Label​

Select the "DuoKey - Double Key Encryption" label (a checkmark appears) and click Apply.

Apply DKE Label

Step 5: PDF is Now DKE-Encrypted​

The PDF is now protected with Double Key Encryption. A banner at the top of the document confirms:

"This document is protected by Microsoft Purview Information Protection with label 'DuoKey - Double Key Encryption'"

And a second banner shows:

"This service is provided by DuoKey for Office 365 engine"

DKE Encrypted PDF

Tip
The DKE-encrypted PDF can be shared with authorized users. Recipients must have Adobe Acrobat with MPIP support enabled and be authorized in your DuoKey access control policies to decrypt the document.

How It Works​

User Applies Label

User selects a DKE sensitivity label in Adobe Acrobat

Microsoft Encrypts

Microsoft 365 encrypts the document with its key (Key 1)

DuoKey Encrypts

DuoKey's DKE service adds a second layer of encryption (Key 2) using MPC

Document Protected

The PDF is now double-encrypted — neither Microsoft nor DuoKey alone can decrypt it

Decryption Request

When an authorized user opens the PDF, both keys are required to decrypt

Zero Trust Check

DuoKey's Zero Trust Access Control evaluates the request (user, IP, location, group) before releasing Key 2
Important

Microsoft never has access to the full encryption key. The DuoKey key (Key 2) is managed entirely by your organization through DuoKey's MPC-based infrastructure.

Registry Configuration Summary​

Registry KeyNameValuePurpose
...\FeatureLockDownbMIPLabelling1Enable MPIP sensitivity labels
...\FeatureLockDownbEnableDKEAdmin1Enable Double Key Encryption
...\FeatureLockDownbMIPExternalAuthAdmin1Enable browser-based authentication
...\MicrosoftAIPbShowDMB1Show document message bar (optional)
...\FeatureLockDownbMIPCheckPolicyOnDocSave1Mandatory labeling (optional)
...\MicrosoftAIPbEnableLogging1Enable MIP debug logging (troubleshooting)

Troubleshooting​

GPO / Intune Deployment​