Forum Discussion
josecachairo
Aug 06, 2021Copper Contributor
Outlook message encryption - avoid delegate access
Dear community, we have following challenge. We would like to use the message encryption option (OME) It´s simple to implement and fits for most of our needs. However we have one scenario w...
Aug 06, 2021
Hello, if you can restrict the assistant to use Outlook for Windows only it's possible.
https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-faq?view=o365-worldwide#is-delegated-access-supported-with-opening-encrypted-messages--even-if-a-delegate-has-full-access-to-another-user-s-mailbox-
https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-faq?view=o365-worldwide#is-delegated-access-supported-with-opening-encrypted-messages--even-if-a-delegate-has-full-access-to-another-user-s-mailbox-
- josecachairoAug 06, 2021Copper Contributor
ChristianJBergstrom thanks for your quick answer.
If I understand you well, OME don´t have a solution for this use case, right?
To somehow block all except Outlook Windows dont think it is a good idea.
It will be challeging to assure never get access..
Maybe there is a way via Powershell?
Question is if it is possible...
Thanks a lot anyway 🙂
- TonyRedmondOct 17, 2021MVPOME isn't really designed to handle complex access situations. If I were you. I'd consider using a sensitivity label that restricts access to a limited set of reciipients.
- Oct 17, 2021
Agreed, but if going down that road it needs some structure and planning incl. people from your business (to classify and protect). I.e. the very opposite from the easy to use built-in encryption with OME josecachairo
- Aug 06, 2021You’re correct. OME cannot accomplish what you’re looking for. There used to be a MIP UserVoice request for this scenario, but as Microsoft has closed down UV for this and other products I don’t know what has happened to it. Sorry..
- BHartNLOct 15, 2021Copper Contributor
iOS and Android allow opening an encrypted message of a delegated mailbox. Any way to disable this similar to disabling access to OWA?