Encryption in Office 365 Shobhit Sahay Technical Product Manager Asaf Kashi Group Program Manager
DLP Modules Introduction to Encryption in Office 365 Information Rights Management Office 365 Message Encryption S/MIME
Module 3: Office 365 Message Encryption
Office 365 Message Encryption Admin: Simple to provision and configure Policy driven via Transport Rules Customizable branding of encrypted emails and mail reading portal Allows for Enterprise content inspection and compliance Sender: Ability to send encrypted messages to any SMTP address regardless of recipient’s client or service provider Recipient: View encrypted messages on Office 365 Message Encryption portal after sign-in Office 365 Message Encryption portal has rich OWA controls for viewing and composing messages Replies from the portal are also encrypted
Office 365 Message Encryption – Admin Configuration New ETR actions configurable via UI or PowerShell New-TransportRule –Name EncryptRule <Condition for which to apply encryption> -ApplyOME $true New-TransportRule –Name DecryptRule <Condition for which to remove encryption> -RemoveOME $true
Office 365 Message Encryption – Admin Configuration Customize opening text in encrypted email and disclaimer statement Set-OMEConfiguration -Identity default -EmailText "Encrypted message from ContosoPharma secure messaging system" Set-OMEConfiguration -Identity default -DisclaimerText “This email message and its attachments are for the sole use of the …"
Office 365 Message Encryption – Admin Configuration Customize portal text and logo Set-OMEConfiguration -Identity default -PortalText "ContosoPharma secure e-mail portal" Set-OMEConfiguration -Identity default -Image (Get-Content "C:\Users\admin\Desktop\contoso.png” -Encoding byte)
Office 365 Message Encryption – Modern UI Modern O365 UI and rich OWA controls
Office 365 Message Encryption How do recipients sign-in to view messages? – 3 ways Microsoft account – used for sign-in to Microsoft services like OneDrive, XBOX Live, etc… Microsoft account for hotmail.com, outlook.com, live.com already exists User can create Microsoft account for any SMTP address, like gmail.com, mycustomdomain.com – address verification done as part of account creation process If recipient does not have a Microsoft account, recipients are navigated through the process of creating one For a given email address, a single Microsoft account is used to access all Microsoft services and view future encrypted emails Organizational Account – used for sign-in to workloads like Exchange Online, SharePoint Online, etc… One time Passcode As Office 365 embraces additional identity providers, so will Office 365 Message Encryption.
Office 365 Message encryption demo Office 365 Message encryption
Office 365 Message Encryption - Under the hood Exchange Online Policy detection and Enforcement Deliver O365 User Send Internet User Mail Reading Portal Tenant configuration Post Microsoft account/Organization Account/One time Passcode
Mobile Experiences Apps for iOS and Android Devices Windows Phone provides a Native support
Mobile Experiences
Mobile Experiences
Mobile Experiences
Mobile Experiences
Mobile Experiences
Purchasing Office 365 Message Encryption Office 365 Message Encryption is included with Azure RMS Plan Requires Price Office 365 E3, E4 Windows Azure Rights Management is included Included Office 365 E1, K1 Windows Azure Rights Management $2 PUPM Office 365 Exchange Online Plan 2, Plan 1, Kiosk Office 365 SharePoint Plan 2, Plan 1 Office 365 Midsize Business Exchange on-premises * On-premise customers need to route mails through Exchange Online ** Windows Azure Rights Management is not available for Office 365 Small Business plans