Microsoft Office 365

Administrator Guide – Installing and Configuring S/MIME in Outlook

Overview

S/MIME provides certificate-based email encryption and digital signatures. This guide explains how to install and configure S/MIME in Outlook.


Step 1: Obtain an S/MIME Certificate

Purchase or obtain an S/MIME certificate from a trusted Certificate Authority (CA), such as:

  • DigiCert
  • GlobalSign
  • Sectigo

The certificate must include:

  • Email address
  • Public and private key pair

Certificate format typically: .pfx or .p12


Step 2: Install Certificate in Windows

  1. Double-click the certificate file.
  2. Select Install Certificate.
  3. Choose Current User.
  4. Enter the certificate password.
  5. Store in Personal Certificate Store.
  6. Complete the installation wizard.

Step 3: Configure Outlook for S/MIME

  1. Open Outlook.
  2. Go to File → Options → Trust Center.
  3. Click Trust Center Settings.
  4. Select Email Security.
  5. Under Encrypted email, click Settings.
  6. Select your installed certificate.
  7. Enable:
    • Encrypt contents and attachments
    • Add digital signature (optional)

Save settings.


Step 4: Exchange Certificates with Recipient

For S/MIME encryption to work:

  1. Send a digitally signed email first.
  2. The recipient must also have S/MIME configured.
  3. Both parties must exchange public certificates.

Testing S/MIME

  1. Compose a new email.
  2. Click Options.
  3. Select Encrypt (S/MIME).
  4. Send to recipient with certificate installed.

Reference

Microsoft Learn – Configure S/MIME in Exchange Online https://learn.microsoft.com/exchange/security-and-compliance/smime-exo/smime-exo