Jump to content

Recommended Posts

Posted
Had a thought yesterday. We use our photocopiers sometimes to scan and email documents. I'm going to set a rule that catches anything from photocopiers@ email address and adds encryption to it. Just to cover my back!
  • 3 weeks later...
Posted (edited)

We too, have been using MS Office 365 OME (v1) for a while, but still get inundated by queries from staff stating that the encrypted emails they are sending out cannot be accessed (e.g. by parents, though mainly financial organisations) so I have been testing with OME (v2).

 

Initially, I thought 'great' the recipient receives a much nicer initial email, with simple process of authenticating (using gmail, hotmail etc) or a one-time passcode...

 

If your encryption rule has been set up with the newer OME system, you can't create a decryption rule for return messages. I read this on one of the Microsoft sites yesterday after I kept getting an error. It only works with the older encryption type :(

 

 

As for how long it takes to apply the rules - I'd give it at least an hour or two. One site I read said to give it 8 hours?! I personally left it overnight

 

This was the first thing I noted (and had confirmed by Microsoft) that if the recipient then replies to the encrypted email, it cannot be auto-decrypted, and even the originating sender has to be authenticated etc. to access. Of course, not an issue if just one-way secure communication!

 

Its Office 2010, my point is that if i send an attachment to someone it's not ideal for them to create an MS account to download it. I created a new Mail flow rule and instead of "Apply office 365 message encryption and rights protection to messages" I selected "Encrypt the messages with the previous version of OME" and i can now open the attachment without any further login or issues. I assume this is because the latter doesn't have "rights protection" what i want to know is what are others using?

 

The next issue is if you are not using MS Outlook 2016 (which I admit, my test rig is, but campus is still using MS Outlook 2010* UPDATE: Can access OK via MS Outlook 2010 or OWA) and that introduces issues of trying to access the reply; even with the OWA version which a lot of staff do.

 

good question @habz99 . I have had to do the same and wonder what everyone else does, I have to assume they're doing the same?!

 

and many thanks to @themightymrp for the process. Very easy and worked a treat. Now just to make it as painless as possible for parents etc to use.

 

So... OME (v1) kind-of works for both sender and external recipients, with auto-decrypt on replies - but still many external recipients have issue accessing the encrypted email

 

OME (v2) works 'better' for external recipients, but cannot auto-decrypt replies - though bigger issue with our non-Outlook 2016* (Update: MS Outlook 2010 OK) and OWA users...

 

Like @habz99 @leegcvcc I too wonder what, or how other school's are using MS Office Encryption options...

 

Thanks

 

Updated as per * issue appears to just be with OWA, which i suspect is a configuration problem? as "protect" option is greyed out for our tenancy

Edited by MYK-IT
Testing revealed that MS Outlook 2010 can handle OME v2 encrypted emails
  • Thanks 1
Posted (edited)

Interesting feedback @MYK-IT as I'm on v1 too and been wondering if it's worth changing to the newer version to get the nice "encrypt message" button in Outlook rather than relying on subject lines.

 

Sounds like it's not 100% at the moment though so will stick with v1 until that reply issue gets sorted.

 

Edit: that said we're running Office 2013 and upgrading to 2016 shortly so it may not be an issue?

 

We've had a few people have issues with opening OME v1 messages, ironically it's the most secure organisations who need the encryption the most that can't open the messages (!) Think most have got there in the end apart from one from what I remember.

Edited by gshaw
  • 3 weeks later...
Posted

Just an update, in case others are using OME v2 encryption...

 

Administrators can now control whether Office attachments are protected for recipients outside of Office 365 when the Encrypt-Only template is used. This was a key ask from Office 365 Message Encryption customers and is now available as a tenant-level setting. (https://techcommunity.microsoft.com/t5/Security-Privacy-and-Compliance/Admin-control-for-attachments-now-available-in-Office-365/ba-p/204007)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...