artfulmatt Posted June 6, 2018 Posted June 6, 2018 Hi, I've recently enabled the rule for office 365 encryption, but Suffolk and Norfolk are coming back saying they are unable to decrypt? I've had one explanation saying the encryption level is too high? Has anyone else had similar issues? Thanks, Matt.
djrscally Posted June 6, 2018 Posted June 6, 2018 We have to be honest had a lot of people with difficulty opening these. There seems to be two problems: 1) User issues. People just don't expect this kind of thing and we're getting a lot of people just lock up and say "I don't know how to open this". Generally when I've called and asked them to walk me through the problem, there is no actual problem. We're building a sort of "opening the email" crib sheet that people can just fire off when they get people saying they can't open it in the first instance. 2) Issues with network security deleting attachments or preventing them from being opened; this one has happened to recipients in banks and so on, the older style of O365 encryption sends the secure portal as a HTML attachment which their networks won't allow them to open. If you get it upgraded to the newer version, it uses a link instead of the attachment which I think has helped. EDIT: Do people who use Egress/GalaxKey have these problems too?
artfulmatt Posted June 6, 2018 Author Posted June 6, 2018 We use 365 which sends a rpmsg attachment, I've been testing with friends working for different companies and getting mixed responses. My Wife can open it fine, others seem to default to adobe acrobat when opening? there is defiantly an element of user problems. Matt.
Badaz52 Posted June 6, 2018 Posted June 6, 2018 We are having this trouble too. We are on the most up to date version of encryption. It works fine for 1:1 personal addresses (Yahoo, Outlook, Google) as they can just sign straight in. When it comes to people clicking one time code they seem either incapable of taking this step or reluctant I've not decided which it is yet. Emailing companies that use shared mailboxes seems to be troublesome because the code that it generates doesn't get to the right person. The older type with the html attachments was a nightmare as most company email servers delete the attachment so we ditched that. So long as they click on the read the message hyperlink rather than mess around with the attachment they should be fine I think most are just freaked out by it or think they need an outlook account (which they don't). The most trouble I have had is when emailing suppliers, not one has had any success but the feedback varies from "We can't open encrypted emails" to "We are not allowed to open encrypted emails" the latter excuse following the 25th May is laughable. Of course there are compatibility issues as well if they use an older version of Outlook (pre 2016) to open your email but I don't care about that.
djrscally Posted June 6, 2018 Posted June 6, 2018 We use 365 which sends a rpmsg attachment, I've been testing with friends working for different companies and getting mixed responses. My Wife can open it fine, others seem to default to adobe acrobat when opening? there is defiantly an element of user problems. Matt. Ah. I wonder if this explains our problem. I could never figure out why some recipients complained about the attachments when they were getting the version with a link; didn't know about the rpmsg attachment thingy.
artfulmatt Posted June 6, 2018 Author Posted June 6, 2018 They don't need to be opening the attachment, just follow the link within the email and sign in using their work email account. I think like badaz52 says, users are getting confused and trying to use an outlook account or opening the attachment. My testing was as follows :- Wife - open ok, they use office 365 with Outlook 2016 and it opened the link in OWA. Norfolk Police (friend) - opened the attachment within outlook, which tried to open in Adobe Acrobat, which she stopped and opened in word instead. (yet to find out what version of outlook they use) Thorpe School (friend) - use googlemail and opened fine. Suffolk CC - told their email client doesn't support encryption? Sent them instructions and not heard back since? I have heard from another Suffolk CC employee that Adobe acrobat was trying to open the attachment, same as Norfolk Police so guessing the version of outlook is pre 2016.
djrscally Posted June 6, 2018 Posted June 6, 2018 They don't need to be opening the attachment, just follow the link within the email and sign in using their work email account. I think like badaz52 says, users are getting confused and trying to use an outlook account or opening the attachment. My testing was as follows :- Wife - open ok, they use office 365 with Outlook 2016 and it opened the link in OWA. Norfolk Police (friend) - opened the attachment within outlook, which tried to open in Adobe Acrobat, which she stopped and opened in word instead. (yet to find out what version of outlook they use) Thorpe School (friend) - use googlemail and opened fine. Suffolk CC - told their email client doesn't support encryption? Sent them instructions and not heard back since? I have heard from another Suffolk CC employee that Adobe acrobat was trying to open the attachment, same as Norfolk Police so guessing the version of outlook is pre 2016. Yeah, I'm guessing people are seeing the bit that says "message.rpmsg" and just trying to open that without hitting the link
sigma Posted June 15, 2018 Posted June 15, 2018 They don't need to be opening the attachment, just follow the link within the email and sign in using their work email account. I think like badaz52 says, users are getting confused and trying to use an outlook account or opening the attachment. My testing was as follows :- Wife - open ok, they use office 365 with Outlook 2016 and it opened the link in OWA. Norfolk Police (friend) - opened the attachment within outlook, which tried to open in Adobe Acrobat, which she stopped and opened in word instead. (yet to find out what version of outlook they use) Thorpe School (friend) - use googlemail and opened fine. Suffolk CC - told their email client doesn't support encryption? Sent them instructions and not heard back since? I have heard from another Suffolk CC employee that Adobe acrobat was trying to open the attachment, same as Norfolk Police so guessing the version of outlook is pre 2016. I've had encrypted emails from SCC's Office365 with no problems.
Badaz52 Posted June 15, 2018 Posted June 15, 2018 (edited) Trouble is one size doesn't fit all and you can't help everyone. Biggest culprit of O365 encryption failing is the recipient using an old exchange or office version (when using the latest OME) but its a better bet as it doesn't need the attachment although it includes it to read it. Using the previous version of OME isn't a great idea either as it relies heavily on the attachment *.html and if this gets removed by spam protection etc then your pretty much screwed. You could buy something like Egress (as we considered) but recipients would still need to create an account to view the emails which brings another set of issues. In a nutshell its up to the recipient to sort it out, you know your email can be opened because you have tested it throughly (as we have) with a select number of personal staff email accounts with not one issue. We only have trouble with company based email addresses because their systems are out of date and well frankly their IT guys need to pull their finger out. Edited June 15, 2018 by Badaz52
artfulmatt Posted June 15, 2018 Author Posted June 15, 2018 I've had encrypted emails from SCC's Office365 with no problems. We receive them ok from suffolk, but they use the old method of message.html (the original method microsoft used for encryption) - we can open them fine. Problem is outlook 2010 or below cannot open the latest version of encryption (message_v2.pmsg)
artfulmatt Posted June 15, 2018 Author Posted June 15, 2018 Not sure if its link with the subscription you have? we never moved across to it? it was always there, we just needed to enable it.
RobFuller Posted June 15, 2018 Posted June 15, 2018 (edited) Not sure if its link with the subscription you have? we never moved across to it? it was always there, we just needed to enable it. IRMConfiguration AutomaticServiceUpdateEnabled was set to false for some reason now set to true. More information found here https://docs.microsoft.com/en-us/azure/information-protection/deploy-use/activate-service Edited June 15, 2018 by RobFuller
djrscally Posted June 15, 2018 Posted June 15, 2018 Interesting, mine are still sending .html attachments with no link in the email, which might be slightly easier for some remote users. Will do some more research. https://support.office.com/en-us/article/set-up-new-office-365-message-encryption-capabilities-7ff0c040-b25c-4378-9904-b1b50210d00e
supportman Posted June 15, 2018 Posted June 15, 2018 We've found this is simply not reliable enough due to everyone having different setups at the receiving end. Turned it off after a few tests.
tech-man Posted June 15, 2018 Posted June 15, 2018 Not sure if its link with the subscription you have? we never moved across to it? it was always there, we just needed to enable it. Matt - we had the same issue with SCC. We now have a enforced TLS link between us and them. PM me and I can put you in contact with the person you need to speak to.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now