8.1 Design and Implement Microsoft Purview Message Encryption
Key Takeaways
- Legacy Office 365 Message Encryption (OME) was deprecated on July 1, 2023 and is automatically replaced by Microsoft Purview Message Encryption, which is built on the Azure Rights Management service.
- Encrypt-Only authenticates recipients and grants all usage rights except Save As, Export, and Full Control; Do Not Forward dynamically authorizes only the sender's chosen recipients and blocks forward, print, and copy.
- Apply encryption from Outlook, sensitivity labels, Purview DLP, or Exchange mail flow rules using Apply Office 365 Message Encryption and rights protection; meeting invites require sensitivity labels, not mail flow rules.
- Microsoft 365 Outlook recipients read encrypted mail inline; Gmail, Yahoo, and other clients open a wrapper that leads to the encrypted message portal with social sign-in or a one-time passcode.
- Published licensing includes Microsoft 365 F3/E3/A3/G3/E5/A5/G5 and Business Premium plus listed Office 365 plans; each user who benefits needs a license, and encrypted messages including attachments are limited to 25 MB.
Microsoft Purview Message Encryption is the current Microsoft 365 service for sending encrypted email to people inside and outside the organization, regardless of whether the destination is another Microsoft 365 tenant, Outlook.com, Gmail, Yahoo, or another provider. Legacy Office 365 Message Encryption (OME) was deprecated on July 1, 2023 and is automatically replaced by Purview Message Encryption. SC-401 items that still say "OME" almost always mean this Purview service, not the retired HTML-attachment workflow that required a download or a mobile viewer app.
People use email for financial data, contracts, product plans, health information, and customer records. Message encryption exists so that only intended, authenticated recipients can view that content. Recipients do not need a Microsoft 365 subscription to read an encrypted message or send an encrypted reply.
Built on Azure Rights Management
Purview Message Encryption is an online service built on the Azure Rights Management service (Azure RMS), the encryption technology used by Microsoft Purview Information Protection. Azure RMS supplies encryption, identity, and authorization policies. You encrypt messages with rights-management templates, the Do Not Forward option, and the Encrypt-Only option (shown in clients and mail flow rules as Encrypt).
The only prerequisite Microsoft publishes is that Azure RMS must be activated in the tenant. For most eligible plans, Azure RMS activates automatically and Microsoft 365 then enables message encryption without a separate wizard. If you previously disabled Azure RMS, activate it before you test encryption.
If Exchange Online is still bound to on-premises Active Directory Rights Management Services (AD RMS), Purview Message Encryption will not work. Microsoft deprecated AD RMS support in Exchange Online on February 28, 2021. Migrate AD RMS to Azure RMS first. Bring your own key (BYOK) for the Azure RMS tenant key is supported; Microsoft recommends finishing BYOK before you enable message encryption if compliance requires you to hold the root key.
Verify configuration in Exchange Online PowerShell
Use a least-privilege role such as Compliance Administrator. Standing Global Administrator is not required.
- Connect to Exchange Online PowerShell.
- Run
Get-IRMConfiguration.AzureRMSLicensingEnabledshould be$True. If it is not, runSet-IRMConfiguration -AzureRMSLicensingEnabled $True. - Run
Test-IRMConfiguration -Sender user@contoso.com -Recipient user@contoso.comwith any mailbox in the tenant. A healthy result acquires RMS templates (typically including Do Not Forward and organization templates), then reports PASS for encryption, decryption, and IRM.
If the test fails with Failed to acquire RMS templates, Microsoft's documented recovery is to read the Azure RMS licensing URL from Get-AipServiceConfiguration and set Set-IRMConfiguration -LicensingLocation $LicenseUri plus -InternalLicensingEnabled $true, then retest.
To show or hide the Encrypt button in Outlook on the web, use Set-IRMConfiguration -SimplifiedClientAccessEnabled $true or $false.
Encrypt-Only, Do Not Forward, and templates
These three protection styles are the design decision the exam tests most often.
| Option | What it is | After the recipient authenticates | Typical use |
|---|---|---|---|
| Encrypt-Only (Encrypt) | Encrypts the message without extra collaboration restrictions | All usage rights except Save As, Export, and Full Control. Recipients can copy, print, and forward. They cannot remove encryption. | Secure delivery when the partner still needs to work with the content |
| Do Not Forward | Not a stored template. Dynamically authorizes only the sender's chosen recipients | Recipients cannot forward, print, or copy. Outlook hides Forward, Save As, and Print and blocks adding To, Cc, or Bcc recipients | Need-to-know threads where only the people on the original message should read it |
| Custom RMS / label templates | Administrator-defined static authorized users and rights | Whatever the template grants (for example View Only or a department group) | Repeatable departmental or regulatory restrictions independent of the To line |
Do Not Forward is not the same as a template that merely omits the Forward usage right. A Marketing-department template still lets anyone in Marketing open a copy that a recipient dropped on a share or USB drive. Do Not Forward binds access to the original recipient list plus the owner. Use Do Not Forward when only the people the sender picked should see the mail. Use a template when an administrator predefines a group that should be able to open the content even if those people were not on the original To line.
Encrypt-Only is available in Outlook on the web, as a mail-flow RMS option, as a Purview DLP action, and from Outlook desktop and mobile when a sensitivity label is configured for Let users assign permissions with Encrypt-Only, or via the Encrypt option on supported Windows and macOS Microsoft 365 Apps versions. Microsoft 365 users can create Encrypt-Only mail in Outlook for PC 2019 and Microsoft 365; those messages can be read in Outlook on the web, Outlook mobile, and Outlook for PC 2019 and Microsoft 365.
Unencrypted Office attachments inherit the same permissions as the message. For Encrypt-Only, an admin can change that inheritance with Set-IRMConfiguration -DecryptAttachmentForEncryptOnly $true so that after the recipient authenticates, downloaded Office attachments are no longer encrypted on disk. DecryptAttachmentFromPortal is deprecated.
How protection is applied: users, mail flow, DLP, and labels
Admins define Exchange mail flow rules (transport rules) so matching messages are encrypted before they leave Exchange Online. Combine conditions such as external recipients, recipient domain, keywords in the subject or body, or sensitive information types. Replies to encrypted messages are also encrypted.
In the Exchange admin center the current action is Modify the message security > Apply Office 365 Message Encryption and rights protection, then pick Encrypt, Do Not Forward, or another RMS template. If the RMS template list is empty, message encryption is not set up yet. Legacy rules that still use Apply the previous version of OME deliver the old HTML-attachment experience; Microsoft recommends updating them. Encryption can also be an action on a Purview DLP policy.
Users can encrypt from Outlook desktop, Outlook for Mac, and Outlook on the web. Sensitivity labels that apply encryption—including Let users assign permissions with Encrypt-Only or Do Not Forward—are the preferred path when protection must travel with the item across workloads. Two published gaps matter on the exam:
- Mail flow rules cannot encrypt or decrypt meeting invites and responses. Use sensitivity labels for calendar items.
- SharePoint and OneDrive cloud attachments are not supported. You can encrypt the message body, not the cloud attachment.
Admins can remove encryption on outgoing mail with a mail flow rule, and can remove encryption on incoming mail only when that mail originated in the same Exchange Online organization. Journal decryption uses Set-IRMConfiguration -JournalReportDecryptionEnabled $true so a decrypted copy lands in the journal mailbox for items that originated in the organization.
On-premises users in an Exchange hybrid deployment can send encrypted mail when that mail is routed through Exchange Online so a cloud mail flow rule can apply protection.
Recipient experience
Microsoft 365 recipients using Outlook desktop, Outlook for Mac, Outlook on the web, and Outlook mobile get a native inline reading experience, even across Microsoft 365 organizations (except the GCC High boundary cases below). Gmail and Yahoo recipients receive a wrapper message that points to the encrypted message portal and can authenticate with a Microsoft, Google, or Yahoo account. Other identities use a one-time passcode. The portal requires no separate download. It supports mail only, not calendar items or voice mail. Portal access lasts as long as the sender's organization is active and the message is not configured to expire (expiration is an Advanced Message Encryption control, covered in the next section).
GCC High is different: if either side is outside GCC High—including commercial Microsoft 365, Outlook.com, Gmail, or Yahoo—the recipient always gets wrapper mail and the portal. Two GCC High organizations still get the native Outlook experience.
Control portal authentication with Set-OMEConfiguration: SocialIdSignIn for Google, Yahoo, and Microsoft accounts, and OTPEnabled for one-time passcodes. First OTP messages often land in junk or quarantine because of DKIM and DMARC.
The iOS Mail app cannot decrypt RMS mail client-side. Set-ActiveSyncOrganizationSettings -AllowRMSSupportForUnenlightenedApps $true sends a decrypted copy to that app, with the usage-rights caveats Microsoft documents (the user may copy or print locally even if those rights were not granted, but server-side actions such as forward still enforce original rights). Attachments still cannot be viewed in iOS Mail. Individual OWA or ActiveSync mailbox policies with IRMEnabled $false override the organization setting.
Attachments, PDF, size, shared mailboxes, and eDiscovery
Supported Office Open XML attachments (docx, xlsx, pptx, and related formats Microsoft lists) stay protected after download when inheritance applies. Microsoft Purview Message Encryption does not support 97-2003 .doc, .xls, and .ppt for inherited protection. PDF encryption is optional: Set-IRMConfiguration -EnablePdfEncryption $true. Recipients can view encrypted PDFs in Microsoft Edge or in the encrypted message portal.
Microsoft publishes a 25 MB maximum for encrypted messages including attachments (Exchange Online message limits). When connectors are in play, Bcc recipients can be stripped before encryption; put recipients on To or Cc, or move fully to Exchange Online.
Shared mailboxes can open protected mail. Mail sent from the same organization opens in supported Outlook clients; mail from an external organization needs Outlook on the web. Delegated access to encrypted mail works in Outlook on the web, Outlook for Mac, Outlook for iOS, and Outlook for Android; Outlook for Windows does not support delegated access to encrypted mail.
Most messages protected by Purview Message Encryption are discoverable in eDiscovery. Mail you receive from another Microsoft 365 organization that has custom branding applied so the item is only a portal link, not in the user's mailbox, is not searchable in your tenant.
Licensing Microsoft publishes
The Microsoft Purview service description lists Message Encryption as Yes for Microsoft 365 F3/E3/A3/G3/E5/A5/G5 and Microsoft Business Premium, and for Office 365 A1/E3/A3/G3/E5/A5/G5. Azure Information Protection Plan 1 added to Exchange Online Kiosk, Exchange Online Plan 1 or 2, Office 365 F3, Microsoft 365 Business Basic or Standard, or Office 365 Enterprise E1 also provides rights. Each user who benefits from message encryption needs a license. Microsoft does not publish an SC-401-specific SKU count or a per-message encryption quota beyond the 25 MB size limit.
Exam traps
- Design around Purview Message Encryption on Azure RMS, not deprecated OME HTML attachments.
- An empty RMS template list means encryption is not configured (
AzureRMSLicensingEnabled/Test-IRMConfiguration). - Encrypt-Only still allows forward, print, and copy; Do Not Forward does not.
- Cloud attachments and meeting invites are not mail-flow encryption targets.
- AD RMS and Purview Message Encryption cannot run together in Exchange Online.
Which statement correctly describes Microsoft Purview Message Encryption relative to legacy Office 365 Message Encryption?
A finance analyst must send an encrypted contract to an external partner who, after authenticating, still needs to print, copy, and forward the message. Which protection option matches that requirement?
An admin is verifying that Microsoft Purview Message Encryption is ready in Exchange Online. Which PowerShell check confirms the tenant is configured?