Overview
Email messages can be protected to help preserve content confidentiality. Microsoft 365 offers a service called Message Encryption which you can use to send protected messages. Messages sent via Message Encryption can only be read by the recipient and can be configured to disallow forwarding to other users.
This article covers how to send an encrypted message. See this article for instructions how a recipient would open an encrypted message:
Warning
Care should be taken when sending sensitive information in email. Message Encryption is best suited for one time or occasional sharing. You are still responsible for ensuring information is only shared with appropriate parties. If you routinely share sensitive information with an authorized external entity, Message Encryption may not be the best solution. Contact your local support or OIT Security for further guidance or if you have any questions.
When enabling encryption it is possible to select between the default "Encrypt-Only" and "Do Not Forward" options. Here is information on the two options:
Option |
Description |
Encrypt-Only |
If you choose "Encrypt-Only" the message is encrypted. Recipients can share the email and any attachments with any third parties without restriction. |
Do Not Forward |
If you choose "Do Not Forward" the message is encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.
Warning: the "Do Not Forward" option also blocks the ability to cut and paste content from the message. |
From the new message draft window, click the "Options" tab.
Next, click on the "Encrypt" button to enable encryption.
To select another encryption option, click on the drop down arrow on the Encrypt button. This allows select betweening "Encrypt-Only" (default) and "Do Not Forward".
Outlook indicates the message will be protected. Click Send as usual when you are ready to send the message.
The process to send an encrypted message in Outlook for Web differs depending on what you see when drafting a new message.
Overflow Menu
From the new message draft window, if you do not see a button labelled "Encrypt" in the menu bar, you need to navigate into the overflow menu. Click the 3 dot icon "...", select "Encrypt" and then choose "Encrypt" or "Do Not Forward".
If you choose "Encrypt" the message is encrypted. Recipients can share the email and any attachments with any third parties without restriction.
If you choose "Do Not Forward" the message is encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.
Exercise caution when sending sensitive file attachments with either option.
Encrypt Button
If you see an "Encrypt" button, you can click it to enable message encryption.
Step 1
Click "Encrypt".
Step 2
The message is marked for protection using Office Message Encryption. However, recipients can share the email and any attachments with any third parties without restriction.
To disallow recipient forwarding of the message in addition to encryption, click "Change permissions".
Step 3
Click the drop down in the pop-up window:
Select "Do Not Forward":
Click "OK":
Step 4
The message remains encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.The new message draft window indicates the protection status at the top.
Click send as usual when you are ready to send the message.
Step 1
From the new message draft window, click the "Options" tab.
Step 2
Click the down arrow next to the "Encrypt" lock icon. You can choose "Encrypt-Only" or "Do Not Forward".
If you choose "Encrypt-Only" the message is encrypted. Recipients can share the email and any attachments with any third parties without restriction.
If you choose "Do Not Forward" the message is encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.
Exercise caution when sending sensitive file attachments with either option.
Step 3
Outlook indicates the message will be protected. Click Send as usual when you are ready to send the message.