Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
The document outlines encryption methods in Microsoft 365, including features like customer key, double key encryption, and Microsoft Purview message encryption. It provides information on data protection strategies such as encryption for data at rest and in transit, as well as key management protocols and compliance considerations. Additionally, it highlights the significance of eDiscovery, sensitivity labels, and implications for co-authoring and data sharing within the Microsoft 365 environment.
(1) Encryption
for Microsoft
365
workloads
(2)Customer
Key and
Double Key
(3) Microsoft
Information
Protection
(4) Microsoft
Purview
Message
Encryption
(5) Things to
keep in mind
Today’s agenda
Data at rest
Per-fileencryption (SPO)
BitLocker – on many levels
Data Encryption Policies (DEPs)
SharePoint Online and OneDrive
Exchange Online
All other Microsoft 365 services, incl. Microsoft Purview
Information Protection
11.
Data in transit
SecureReal-Time Transport Protocol (SRTP)
(Mutual) Transport Layer Security (MTLS/TLS)
Exchange IRM – s/MIME – OME
https://www.adaptivedigital.com/secure-rtp/
Customer Key perDEP
Two Azure Subscriptions
Create and
configure
(Premium) Azure
Key Vault and keys
Onboard to
Customer Key
https://learn.microsoft.com/en-us/purview/customer-key-set-up
Filetypes are important
MicrosoftPurview Information
Protection Viewer client
Native clients | Microsoft Edge
Watch out for the file extension | some
types only support classification
Advanced message encryption
Mailrules using sensitive
information types
Revocation and expiration
Information
Protection and
Governance
Compliance E5
Microsoft 365
E-mail attachments
Do notforward | Encrypt only
Non-protected
Office document
Protected
Office document
Mind the Entra ID account
Set-IRMConfiguration - DecryptAttachmentForEncryptOnly <$true|$false>
Tips and tricks
Sharingencrypted files
Older metadata model (MPIP_)
Decrypt documents from SPO:
Unlock-SensitivityLabelEncryptedFile
Super User role
eDiscovery (Premium)
Encrypted/Signed PDFs
Guaranteed SharePoint
Permissions