Forum Discussion
Azure Information Protection affected by efail
Hello everyone,
does anyone know if there is an official statement from Microsoft if the email encryption in AIP is affected by the new security issue efail?
5 Replies
- Losercore
Microsoft
Hello, I have not seen an official announcement, but AIP is not affected by efail. Efail is a S/MIME/PGP vulnerability has nothing to do with AIP. AIP encrypts at the document level using Rights Management.
EDIT:Typo
- Frederik LentjesCopper Contributor
Thanks for your answer.
Just to be sure that we are talking about the same things.
I am just searching for a confirmation that Office 365 Message Encryption (part of AIP) is not affected by efail. In my opinion it is just not affected because it is not based on S/MIME or openPGP.
Am i right?
- Losercore
Microsoft
Sorry for the delay. Our terminology makes this confusing. Office 365 Message Encryption (OME) uses RMS. S/MIME is another way of encrypting messages in Exchange Online using certificates and creates digital signatures. The vulnerability described does not apply to RMS (AIP) thus, it does not apply to OME.
I hope that helps.
Thanks