Albert Hoitingh
Encryption in Microsoft 365
Start 7:45
Encryption in Microsoft 365
Principal consultant
Microsoft Security MVP
Albert
Hoitingh
(1) Encryption
for Microsoft
365
workloads
(2) Customer
Key and
Double Key
(3) Microsoft
Information
Protection
(4) Microsoft
Purview
Message
Encryption
(5) Things to
keep in mind
Today’s agenda
Encryption in Microsoft 365 and Purview
1.At rest In transit Specific
functions
Different scopes
Short side note…
Short side note…
1.Basic
functions
eDiscovery
(Premium)
Customer Key
Double Key
Encryption
Advanced
Managed
Encryption
Licensing considerations
Data at rest
Per-file encryption (SPO)
BitLocker – on many levels
Data Encryption Policies (DEPs)
SharePoint Online and OneDrive
Exchange Online
All other Microsoft 365 services, incl. Microsoft Purview
Information Protection
Data in transit
Secure Real-Time Transport Protocol (SRTP)
(Mutual) Transport Layer Security (MTLS/TLS)
Exchange IRM – s/MIME – OME
https://www.adaptivedigital.com/secure-rtp/
Key management
1.Microsoft
managed
Customer key Double Key
Encryption
(MPIP)
Key management
Microsoft managed
SharePoint Online, OneDrive
Exchange Online
Customer key
Access by Microsoft
Organization in control
Different DEPs, including multi-geo
Azure Key Vault
Hardware Security Modules
Customer Key
SharePoint Online, OneDrive
Exchange Online
Customer Key per DEP
Two Azure Subscriptions
Create and
configure
(Premium) Azure
Key Vault and keys
Onboard to
Customer Key
https://learn.microsoft.com/en-us/purview/customer-key-set-up
Customer Key per DEP
https://learn.microsoft.com/en-us/purview/customer-key-set-up
Customer Key status
Double Key Encryption
Tenant key and organizational key
Office Apps | Sensitivity labels
Impairs specific functions
Software DKE
service, GitHub
Deploy
service,
publish key
Create labels
with DKE
Double Key Encryption
Sensitivity labels
Items and labels
Encryption |
Visual markings |
Offline availability
Label stays with item
Hierarchy is important
1.Content key
Symmetric
AES256-CBC
(Cypher Block
Chaining)
Key protection
Asymmetric
RSA 2048 bit
Certificate
signing
SHA-256
Encryption standards
How it works
Filetypes are important
Microsoft Purview Information
Protection Viewer client
Native clients | Microsoft Edge
Watch out for the file extension | some
types only support classification
Identities are important
Microsoft Live | Guest | RMS
Entra ID accounts
Set-SPOTenant -
EnableAzureADB2BIntegration
Identities are important
Microsoft Live | Guest | RMS
Entra ID accounts
Set-SPOTenant -
EnableAzureADB2BIntegration
Consequences
eDiscovery | content search
Co-authoring | auto-save
Microsoft 365 Copilot
Consequences
eDiscovery | content search
Co-authoring | auto-save
Microsoft 365 Copilot
Consequences
eDiscovery | content search
Co-authoring | auto-save
Microsoft 365 Copilot
Microsoft Purview Message Encryption
Secure e-mail in Microsoft 365
Any recipient
and e-mail
client
Secure web-
portal
Do not forward
Encrypt only
Microsoft Purview Message Encryption
Advanced message encryption
Mail rules using sensitive
information types
Revocation and expiration
Information
Protection and
Governance
Compliance E5
Microsoft 365
Encapsulated e-mail message
Outlook: opens natively
.pmsg file
MPIP viewer does not work
Secure web-portal
E-mail attachments
Do not forward | Encrypt only
Non-protected
Office document
Protected
Office document
Mind the Entra ID account
Set-IRMConfiguration - DecryptAttachmentForEncryptOnly <$true|$false>
Run-through Message Encryption
Things to think about
Tips and tricks
Sharing encrypted files
Older metadata model (MPIP_)
Decrypt documents from SPO:
Unlock-SensitivityLabelEncryptedFile
Super User role
eDiscovery (Premium)
Encrypted/Signed PDFs
Guaranteed SharePoint
Permissions
What about migrating?
https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-to-tenant-
migrations?view=o365-worldwide
THANK YOU
Are there any questions?
Please evaluate this session in the App.
Next session 10:10 – 11:00
The Graph API StarterKit for AVD and W365 automation

Encryption in Microsoft 365 - ExpertsLive Netherlands 2024