Michael Posted September 21, 2020 Posted September 21, 2020 Hi all, So the Local Authority have shifted from Egress > Microsoft Message Encryption (OME), but viewing messages is somewhat problematic. Opening the OME email, it displays a blue button. Clicking this then sends a onetime passcode and the email's then viewable as normal. If the user then closes the email and retries the email at a later date, it displays an authentication error, despite it reading "accessible until December 2020" (so months ahead). Is this typically normal behaviour or something the LA need to tweak their end? Many thanks!
Boredguy Posted September 21, 2020 Posted September 21, 2020 I assume your not using Office 365 on your site if your having that experience. It should not give authentication errors, but it's something that is controlled by Microsoft and not the LA
mavhc Posted September 21, 2020 Posted September 21, 2020 It sends the OTP via email? What's the point then? If someone's hacked your email they can get the OTP too
Michael Posted September 21, 2020 Author Posted September 21, 2020 I assume your not using Office 365 on your site if your having that experience. It should not give authentication errors, but it's something that is controlled by Microsoft and not the LA The school are using Office 365 and the LA are using Office 365 (performing an MX lookup). Separate tenancies however (as you'd expect). - - - Updated - - - It sends the OTP via email? What's the point then? If someone's hacked your email they can get the OTP too I've asked myself the same question!
DJ-1701 Posted September 21, 2020 Posted September 21, 2020 It sends the OTP via email? What's the point then? If someone's hacked your email they can get the OTP too If someone has delegated access to your mailbox though they won't be able to read the e-mail. Also the idea is to keep the data on your tenant as oppose to sending it to someone else that could easily forward it on with no restrictions.
Michael Posted September 21, 2020 Author Posted September 21, 2020 So my question's still unexplained - why can they view the OME email once and not then view it thereafter if they close down their browser (for example)?
DJ-1701 Posted September 21, 2020 Posted September 21, 2020 We use Office 365, so not sure as ours works natively. Though could it be the OTP mean you need to generate a password each time you wish to view the item, and they are just entering an old password which has since expired which would be an authentication error?
Michael Posted September 21, 2020 Author Posted September 21, 2020 We use Office 365, so not sure as ours works natively. Though could it be the OTP mean you need to generate a password each time you wish to view the item, and they are just entering an old password which has since expired which would be an authentication error? This is the behaviour I'd expect, but clicking the blue button a second time, the user's presented with an authentication error and can no longer view the email.
Boredguy Posted September 21, 2020 Posted September 21, 2020 If your both on Office 365, regardless of different tenancies, it will show the e-mail without any additional prompts for a one time password The message will show a little padlock next to the message, and you need to open the message and not just use the preview panel the first time. Subsequent times it will show until the e-mail expires on the LA's server
Michael Posted September 21, 2020 Author Posted September 21, 2020 If your both on Office 365, regardless of different tenancies, it will show the e-mail without any additional prompts for a one time password The message will show a little padlock next to the message, and you need to open the message and not just use the preview panel the first time. Subsequent times it will show until the e-mail expires on the LA's server When clicking the blue button, it loads as a separate tab in the browser and a passcode is sent in a separate email. I then retrieve the passcode and enter it as required. The email then pops up as a separate window altogether, so it's definitely not being just previewed. The behaviour doesn't quite match, which is why I'm wondering whether it's something the LA need to tweak, given they're the source of the emails.
Boredguy Posted September 21, 2020 Posted September 21, 2020 It's sounding almost like they are still using version 1 of OME and not version 2 that has been out for a while =/
Michael Posted September 21, 2020 Author Posted September 21, 2020 What are the differences between OME1 and OME2?
Boredguy Posted September 21, 2020 Posted September 21, 2020 Well OME v1 was there first iteration of encryption in Office 365 and was mainly done via mail flow rules and everyone got the "click here to read" messages OME v2 allowed users to set the encryption when composing the e-mail in Outlook, added extra templates so you can prevent forwarding as well as confidential, and the ability to read messages that were secured was moved into the mail client that supported it (For example sending to a gmail account gives you the ability to login with your gmail credentials without needing the OTP like you would if you were using Yahoo or BTMail for example) Full list of comparisons can be seen here -> https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-version-comparison?view=o365-worldwide 1
Michael Posted September 22, 2020 Author Posted September 22, 2020 So I've had a response and in summary this is the expected behaviour. The only solution is to close your browser, re-sign into O365 and then generate/request another one time passcode.
mavhc Posted September 22, 2020 Posted September 22, 2020 just copy and paste/screenshot/photograph the screen after first opening
Michael Posted September 22, 2020 Author Posted September 22, 2020 just copy and paste/screenshot/photograph the screen after first opening As the member of staff stated though - little guidance from the LA and it would have been better to be told of the expected behaviour.
Boredguy Posted September 22, 2020 Posted September 22, 2020 So I've had a response and in summary this is the expected behaviour. The only solution is to close your browser, re-sign into O365 and then generate/request another one time passcode. In that case it does sound like the LA have got it configured incorrectly in their Exchange Admin panel, as that is not how it is meant to work in OMEv2 within Office 365 tenancies.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now