Jump to content

Recommended Posts

Posted

Hi all,

 

So the Local Authority have shifted from Egress > Microsoft Message Encryption (OME), but viewing messages is somewhat problematic.

 

Opening the OME email, it displays a blue button. Clicking this then sends a onetime passcode and the email's then viewable as normal.

 

If the user then closes the email and retries the email at a later date, it displays an authentication error, despite it reading "accessible until December 2020" (so months ahead).

 

Is this typically normal behaviour or something the LA need to tweak their end?

 

Many thanks!

Posted

I assume your not using Office 365 on your site if your having that experience.

 

It should not give authentication errors, but it's something that is controlled by Microsoft and not the LA

Posted
I assume your not using Office 365 on your site if your having that experience.

 

It should not give authentication errors, but it's something that is controlled by Microsoft and not the LA

 

The school are using Office 365 and the LA are using Office 365 (performing an MX lookup).

 

Separate tenancies however (as you'd expect).

 

- - - Updated - - -

 

It sends the OTP via email? What's the point then? If someone's hacked your email they can get the OTP too

 

I've asked myself the same question!

Posted
It sends the OTP via email? What's the point then? If someone's hacked your email they can get the OTP too

 

If someone has delegated access to your mailbox though they won't be able to read the e-mail. Also the idea is to keep the data on your tenant as oppose to sending it to someone else that could easily forward it on with no restrictions.

Posted
So my question's still unexplained - why can they view the OME email once and not then view it thereafter if they close down their browser (for example)?
Posted
We use Office 365, so not sure as ours works natively. Though could it be the OTP mean you need to generate a password each time you wish to view the item, and they are just entering an old password which has since expired which would be an authentication error?
Posted
We use Office 365, so not sure as ours works natively. Though could it be the OTP mean you need to generate a password each time you wish to view the item, and they are just entering an old password which has since expired which would be an authentication error?

 

This is the behaviour I'd expect, but clicking the blue button a second time, the user's presented with an authentication error and can no longer view the email.

Posted

If your both on Office 365, regardless of different tenancies, it will show the e-mail without any additional prompts for a one time password

 

The message will show a little padlock next to the message, and you need to open the message and not just use the preview panel the first time. Subsequent times it will show until the e-mail expires on the LA's server

Posted
If your both on Office 365, regardless of different tenancies, it will show the e-mail without any additional prompts for a one time password

 

The message will show a little padlock next to the message, and you need to open the message and not just use the preview panel the first time. Subsequent times it will show until the e-mail expires on the LA's server

 

When clicking the blue button, it loads as a separate tab in the browser and a passcode is sent in a separate email.

 

I then retrieve the passcode and enter it as required. The email then pops up as a separate window altogether, so it's definitely not being just previewed.

 

The behaviour doesn't quite match, which is why I'm wondering whether it's something the LA need to tweak, given they're the source of the emails.

Posted

Well OME v1 was there first iteration of encryption in Office 365 and was mainly done via mail flow rules and everyone got the "click here to read" messages

OME v2 allowed users to set the encryption when composing the e-mail in Outlook, added extra templates so you can prevent forwarding as well as confidential, and the ability to read messages that were secured was moved into the mail client that supported it (For example sending to a gmail account gives you the ability to login with your gmail credentials without needing the OTP like you would if you were using Yahoo or BTMail for example)

 

Full list of comparisons can be seen here -> https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-version-comparison?view=o365-worldwide

  • Thanks 1
Posted

So I've had a response and in summary this is the expected behaviour.

 

The only solution is to close your browser, re-sign into O365 and then generate/request another one time passcode.

Posted
just copy and paste/screenshot/photograph the screen after first opening

 

As the member of staff stated though - little guidance from the LA and it would have been better to be told of the expected behaviour.

Posted
So I've had a response and in summary this is the expected behaviour.

 

The only solution is to close your browser, re-sign into O365 and then generate/request another one time passcode.

 

In that case it does sound like the LA have got it configured incorrectly in their Exchange Admin panel, as that is not how it is meant to work in OMEv2 within Office 365 tenancies.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...