

Outlook email encryption uses public and private keys to prevent unauthorized users from reading the content. In this blog post, we focus on message encryption only. With this technology, email messages can be encrypted, and the recipient is protected from spoofing and from receiving tampered messages. S/MIME is a message security service that protects against data breaches and ensures message integrity. Secure/Multipurpose Internet Mail Extensions (S/MIME) is a certificate-based encryption and digital signature technology in Outlook. Note: If you don’t have one of those plans, you can purchase a standalone license for Azure Information Protection to get all the OME capabilities. To use OME, you should have one of the following Office 365 plans: Alternatively, they can receive a one-time passcode to view the message. To read an encrypted message, recipients must be signed in with their Microsoft account credentials. The recipient does not need an Office 365 subscription or even Outlook to read the content or even send an encrypted reply. This means that only you, the sender, must have OME to successfully send an encrypted message. With OME, you can send a protected email to recipients regardless of the email service they are using (Gmail, Yahoo mail, etc.). When a user in your organization sends a message that matches a transport rule, the message is automatically encrypted. You can create mail flow rules, also known as transport rules, to apply to specific messages or groups of users (depending on whether they are inside or outside your organization), etc. You can choose the Encrypt Only option to apply encryption to the message without any additional restrictions or the Do Not Forward option to restrict recipients from sharing the email message. To encrypt messages with OME, you can use rights management templates and/or mail flow rules. Given that it relies on Azure RMS, OME includes identity and authorization policies in addition to encryption options. This ciphertext can be decrypted by the target recipients, but a security breach by unauthorized parties will not lead to a data breach. OME works by transforming readable text into unintelligible cipher. Unlike other encryption approaches, OME does not use encryption certificates and public keys. For many plans, RMS is activated by default. The main prerequisite for OME is the activation of Azure RMS for the tenant.

These services combine email encryption with access controls to provide you with an advanced online encryption service. Office 365 message encryption (OME) relies on Azure Rights Management (Azure RMS), which is part of Azure Information Protection. Let’s start by taking a closer look at each encryption method and how they differ.
