For the purposes of completion regarding the subject to not being able to view encrypted emails from Outlook, MS Tech support got back to me and requested that I apply a PS command "Set-AadrmOnboardingControlPolicy" (see attached).
I was advised to wait 60 minutes after applying the change to our tenant to view the result. I did this end of play on a Friday and didn't test until next Monday. The result = no change! Oddly enough, another 24hrs later and I was able to view the encrypted email via message presented by O365 in the body of the email requesting to click a link which opened it's own IE session and the body of the actual encrypted email from the third party. In essence, click the link and we'll open the content via a standalone OWA session. This was on software running version 1806 that was earlier than the one stated below.
The client advised that the behaviour I was seeing is how they are able to view encrypted emails, until they upgraded to 1806 (Build 10228.20080 C2R), after which the email body and content opens inside the Outlook UI and not an OWA session.
I though, great, all I have to do now is upgrade to the latest version, so now I'm running 1807 (Build 1035.20082 C2R) and.........back to square one again. Not access to encrypted content and back to the user rights management messages as described in a post above.
I know that MS are working in the background on this, but it doesn't inspire much confidence, as they provide bandaid's then break everything again??? Some of us don't have weeks to be guinea pigs for MS's product testing!
Appaling and Irresponsible behaviour!