Microsoft Office 365
Administrator Guide – Enable Microsoft 365 Message Encryption
Overview
This document explains how administrators can enable Microsoft 365 Message Encryption (OME) so users can send encrypted email from Outlook.
Prerequisites
Users must have one of the following licenses:
- Microsoft 365 Business Premium
- Microsoft 365 E3
- Microsoft 365 E5
- Exchange Online with Azure Rights Management
Step 1: Enable Azure Rights Management (IRM)
Using Microsoft 365 Admin Center
- Log in to Microsoft 365 Admin Center.
- Go to Settings → Org settings → Services.
- Select Rights Management.
- Activate Azure Rights Management.
Using PowerShell
1Connect-ExchangeOnline
2Set-IRMConfiguration -AzureRMSLicensingEnabled $trueStep 2: Verify Encryption Availability
- Open Outlook as a user.
- Create a new email.
- Go to Options.
- Confirm the Encrypt button is visible.
Step 3: Create Mail Flow Rules (Optional)
To automatically apply encryption:
- Open Exchange Admin Center.
- Go to Mail flow → Rules.
- Create a new rule.
- Define conditions (e.g., subject contains "Confidential").
- Apply message encryption action.
Testing
- Send a test encrypted email to an external account.
- Verify recipient access through secure portal or passcode.
Reference
For detailed Microsoft guidance:
Microsoft Learn – Message Encryption Documentation https://learn.microsoft.com/microsoft-365/compliance/message-encryption