Jump to content

Recommended Posts

Posted (edited)

Hi - i've just setup office 365 mail encryption - all works fine sending out using #secure in the subject line and creating a rule to use the 'encrypt' template if the sender is inside the organisation and the recipient is outside the organisation. Recipients are able to open the email and read it - however when they reply i get an email that says it is encrypted with a message_v2.rpmsg attachment- i try to open this in OWA or Outlook 2016 - it won't allow me. I've verified my IRM Config in Powershell ( below )

edu1.png

 

the wierd thing is the reply is not encrypted as the user in question doesnt have it setup - they are just replying to my email yet it says i have received and protected message - below is the email i receive and the message i get when i try to open it. I thought it maybe that my rule was encrypting it as the cam e back in as the subject still had the #secure tag. I eliminated that by specifying in the rule that the sender is inside the organisation and the recipient is outside. i f tehy reply to the email without opening the encrypted message it comes through ok , but if they reply to the encrypted message - which is what most people will do it adds the attachment. Any clues anyone please ?

 

Capture.PNG

Capture1.PNG

Edited by vyperz
  • 4 weeks later...
Posted

I'm having a similar problem. I started looking at the Azure rights thing yesterday. I managed to activate it and set up a basic mail rule to encrypt anything going outside the organisation with "Encrypt:" in the subject heading.

 

Messages seem to go out fine. To a Hotmail/Outlook account, the message just opens and there is a message in the heading saying that the email is encrypted. With gmail they can open it by requesting a one time passcode. No problems here, but its the replies I'm struggling with. The replies all come through with that message_v2.rpmsg attachment and I can't open the reply no matter what. I click the link to read the message which opens my browser and says I need to install Outlook :-/ That's what I'm using!!!!

 

Did you manage to solve this? Is there a setting in Azure that needs changing? I need a complete numb-nuts idiot guide for this if anyone has one (that's up to date)?

Posted

OK I've managed to fix my own problem. I'd run one too many powershell commands yesterday and managed to switch something off to do with SocialID ??? I've also set my OME template to 'encrypt' rather than the default one to do with 'Confidential'.

 

My actual process was to get to this stage was:

 

 

1) Go into Office 365 Admin

2) Go to Settings --> Services & Add-ins

3) Click on Microsoft azure information protection

4) Click the link for Manage Microsoft azure information protection settings

5) On the page that opens, click the Activate button

 

6) Open Powershell as administrator (I’m assuming here that you have the necessary bits in place for connecting to Office 365 via powershell)

7) Connect up to Office 365 using your normal method

 

8) Enter the following command: Set-IRMConfiguration -RMSOnlineKeySharingLocation "https://sp-rms.eu.aadrm.com/TenantManagement/ServicePartner.svc"

 

9) Then this one: Import-RMSTrustedPublishingDomain -RMSOnline -name "RMS Online"

 

10) Run command: Test-IRMConfiguration -RMSOnline

 

11) It should give an overall result of PASS

 

12) Go into the Exchange admin centre

 

13) Go down to Mail flow and select “create new rule” using the button at the top

 

14) From the list of option when you click this, choose “Apply office 365 message encryption and rights protection to messages”

15) Set up the rule as follows:

 

Name the rule – “Encrypt outgoing messages test”

For the conditions, set Subject includes any of these words - Encrypt: (no quotes)

Add another condition - The recipient --> external/internal --> Outside the Organisation

Do the following --> Apply office 365 message encryption and rights protection to the message with... --> Encrypt

Audit severity = medium

Enforce = yes

Do not stop processing more rules

 

 

16) Leave it an hour for everything to replicate on Microsoft servers.

17) Create a new email to an external account. In the subject line enter Encrypt: This is a test

18) Add an attachment and a bogus message and send it. Hopefully it will now work.

  • Thanks 3
Posted

So I must have activated the Rights Management at some point in the past and disabled it again. From helping @jonnykewell1 it would appear my tenant is still using some legacy commands. For a brand new activation, some of those powershell commands come up as deprecated. From my instructions above, skip points 8 and 9 and replace point 10 with this:

 

Test-IRMConfiguration -sender [email protected]

 

But use your own email address. It should come back with PASS's

  • Thanks 1
Posted
Is this available on the Office 365 A1 plan and what is the difference between this and Office 365 Message Encryption (OME). I am getting conflicting info regarding email encryption :(
Posted (edited)

We are on the A1 plan, so yes it is available. The above basically is the OME system. If you are only just switching it on for the first time, it will default to using that - see my last post from 4:31pm yesterday for required adjustments to the procedure

 

 

EDIT:

 

I can see that there is a whole lot more available to it, setting up your own templates and 'label's within the Azure Rights Management stuff. But I can't make head nor tail of it at this stage. Baby steps...

Edited by themightymrp
Posted

Thank you for you help. I have now setup, but at the bottom of the rule it says "Rights Management Services (RMS) is a premium feature that requires an Enterprise Client Access License (CAL) or a RMS Online license for each user mailbox. Learn more"

 

Untitled.png ????

Posted
Yep, don't worry about that. I get the same thing - I think they just haven't updated their pages yet. If you go into the main Office Admin centre page, search for one of your users (or yourself). Have at look at your assigned license and expand it to see all the sections you have. About half way down there should be one called Azure Rights Management - it appeared on there a while ago, automatically switched on.
Posted
I have used this method to encrypt the emails but they do not work when using the office 365 web mail client but are fine in the outlook application
Posted
I have used this method to encrypt the emails but they do not work when using the office 365 web mail client but are fine in the outlook application

 

Hi i've just tested this from the web mail client and it seemed to work exactly the same for me. Are you sending it external or to another internal email account in your domain?

Posted
any idea how long before the rules apply? i test sent an email and its not encrypted.

 

Have you tried sending it to your personal account rather than a work one? Depending on how you have configured your rule, if it's Internal it won't encrypt.

Posted

Hi,

 

It maybe worth setting up a transport rule in Exchange Admin Centre to unencrypt any emails coming into the domain. That is the setup we are currently running at our site and its working with no issues.

Posted
Hi,

 

It maybe worth setting up a transport rule in Exchange Admin Centre to unencrypt any emails coming into the domain. That is the setup we are currently running at our site and its working with no issues.

 

If your encryption rule has been set up with the newer OME system, you can't create a decryption rule for return messages. I read this on one of the Microsoft sites yesterday after I kept getting an error. It only works with the older encryption type :(

 

 

As for how long it takes to apply the rules - I'd give it at least an hour or two. One site I read said to give it 8 hours?! I personally left it overnight

Posted (edited)

This is what I get when I try a decryption rule. The page I was reading is the link below. Obviously, if you have a method that works with the new stuff, I'd love to have it!

 

Decrypt error.jpg

 

 

https://support.office.com/en-us/article/define-mail-flow-rules-to-encrypt-email-messages-in-office-365-9b7daf19-d5f2-415b-bc43-a0f5f4a585e8

 

 

Obviously I want the sender to be external. But I'm not too fussed if there is some extra work involved. It's not like every email needs to be encrypted so lets make them have to work!

Edited by themightymrp
Posted
All set up as instructed, but still not encrypting any emails that i send out (externally) even though I have the word encrypt in the subject. Any help would be appreciated. Tried outlook and it gives me the options of "do not forward" etc... But nothing regarding encryption...
Have you tried sending it to your personal account rather than a work one? Depending on how you have configured your rule, if it's Internal it won't encrypt.
Posted

Not sure where you are looking for the options? If you have set things up the same as my method above, just putting "Encrypt:" or "Encrypt" (depending on if you used the colon) should be enough for the mail rule to catch it and send it encrypted. You shouldn't need to do anything else. If you are sending it to a Microsoft Outlook/Hotmail/Live account, you won't need to do anything to view it but it will show in the header that it has been sent encrypted - see picture.

 

Hotmail encryption.jpg

Posted
All set up as instructed, but still not encrypting any emails that i send out (externally) even though I have the word encrypt in the subject. Any help would be appreciated. Tried outlook and it gives me the options of "do not forward" etc... But nothing regarding encryption...

 

Can you screenshot your settings on step 14 please?

Posted

Thank you all for your help, i disabled Microsoft azure information protection and then enabled it again, ran the PS commands and all is working now. :)

Posted

I have now come across another issue, when sending an email externally without an attachment not a problem, but when when i add an attachment and then try opening it i get the following message...

 

t1.png

Asking to create a windows live ID to view the file/edit the file. Does anyone have this issue and what is the solution as we cant expect the recipient to have MS Office and a MS Live ID to open attachments..

Posted
I have now come across another issue, when sending an email externally without an attachment not a problem, but when when i add an attachment and then try opening it i get the following message...

 

[ATTACH=CONFIG]49217[/ATTACH]

Asking to create a windows live ID to view the file/edit the file. Does anyone have this issue and what is the solution as we cant expect the recipient to have MS Office and a MS Live ID to open attachments..

 

What version of Office is that? If it isn't 2013+ you're going to have problems.

Posted

Its Office 2010, my point is that if i send an attachment to someone it's not ideal for them to create an MS account to download it. I created a new Mail flow rule and instead of "Apply office 365 message encryption and rights protection to messages" I selected "Encrypt the messages with the previous version of OME" and i can now open the attachment without any further login or issues. I assume this is because the latter doesn't have "rights protection" what i want to know is what are others using?

Posted

good question @habz99 . I have had to do the same and wonder what everyone else does, I have to assume they're doing the same?!

 

and many thanks to @themightymrp for the process. Very easy and worked a treat. Now just to make it as painless as possible for parents etc to use.

Posted
Authentication is part of the design. I think you can create a AIP account using a work account even if your org doesn't use office 365. You can authenticate with Google accounts I believe

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...