Help with Encrypting Emails in Outlook

LM-5132 100 Reputation points
2024-11-18T19:33:27.0433333+00:00

Hello,

I need some assistance with encrypting emails in Outlook, please. I've read numerous posts and articles from Microsoft Learn, but I'm still unsure about the best way to send confidential information via email.

I have a Microsoft account through my college and have downloaded the applications, so I am using the Outlook desktop version. When I compose an email and click "Options", I see a lock icon that allows me to encrypt emails, and this feature works correctly.

User's image

However, I'm facing issues with my work Outlook account. When I attempt to encrypt an email via OWA (Outlook Web App), there is no option for encryption. To address this, I downloaded the Microsoft apps from my work account onto a separate laptop from the one I use for my school account because I didn't want to have both versions (school and work) on the same laptop.

Here’s the problem: It seems that the encryption option is available on the desktop version of Outlook but not in OWA, forcing me to use the desktop Outlook. When I try to encrypt emails on my work account using the desktop version, I receive the error message: "Microsoft Outlook was not able to create a message with restricted permission."

User's image

Additionally, I asked a coworker to send an encrypted email, and she encountered two different error messages: "Connect to Right Management Servers and get templates," and "No logged-on Office users are configured for Information Rights Management (IRM)."

User's image User's image

All our applications are Software as a Service (SaaS) and hosted in Microsoft 365. I believe all users should be able to encrypt emails or password-protect them.

I have three questions:

  1. Why is there no option to encrypt in OWA? Is it because emails are already encrypted in transit by default via SSL/TLS? This is not End-to-end, just in transit.
  2. Why can't I send encrypted emails from my work Outlook desktop while I can from my school Outlook desktop?
  3. What is the best and most user-friendly way to email confidential information? Should I use the encrypt option, S/MIME, or do I need to set up public/private keys?

Thank you very much! As a temporary workaround, We have been using password-protected documents, but we need to start using end-to-end encryption when necessary.

Thank you,

Lee Manning

Microsoft Exchange Online
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,609 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
578 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 149.7K Reputation points MVP
    2024-11-18T19:46:34.3533333+00:00

    Your org has to be licensed and the feature has to be enabled:

    https://learn.microsoft.com/en-us/purview/set-up-new-message-encryption-capabilities


  2. Mengying Li (Shanghai Wicresoft Co Ltd) 315 Reputation points Microsoft Vendor
    2024-11-19T07:16:20.3+00:00

    Hi, @LM-5132

    Thank you for posting your question in the Microsoft Q&A forum.

    According to your description, you have encountered the problem that the encryption option in Outlook is not available.

    First of all, regarding the problem of no encryption option in OWA. You can first use Exchange Online PowerShell to verify whether the tenant is correctly configured for Microsoft Purview Message Encryption. Use the command to check whether the Information Rights Management (IRM) feature is enabled in Outlook Web Edition.

    Get-OwaMailboxPolicy | FL *IRMEnabled*
    

    Regarding your second question, it is not possible to send encrypted emails from the work Outlook desktop. I agree with @Andy David - MVP's answer that your organization needs to obtain permission and enable the feature. The only prerequisite for using Microsoft Purview Message Encryption is that Azure Rights Management must be activated in the organization's tenant.

    Regarding the question of whether you should use the encryption option S/MIME or set up public/private keys, S/MIME is a widely accepted method for sending digitally signed and encrypted messages. You can also choose to use various encryption technologies together.

    Refer to: Resolve Microsoft Purview Message Encryption issues - Microsoft 365 | Microsoft Learn

    Set up Microsoft Purview Message Encryption | Microsoft Learn

    Best,

    Jeanne


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.