Forum Discussion
Integration of IronPort Edge devices with AIP
Hi all
Does anyone have any knowledge or insight on how to intregrate IronPort devices with AIP. The scenario is a as follows:
1.) I can send a DNF protected e-mail to a 3rd party no problem. They are able to open it and read it without any issues.
2.) Howwever their replies are coming into my mailbox as what appears to be OMEV2 protected content. However I can't open these mails in either Outlook or OWA. The e-mail arrives as a .rpmsg protected file but I can't open it.
3.) Looking at the headers I have a suspicion that the Ironport devices are unable to succesfully open the file and are messing with it to the point where it's signature. Something is applying a warning in the message body indicating that the e-mail is from an external source nd I think this breaking the message sealing to the point where I can't open it...
Anyone got any ideas??
5 Replies
- Nir Hendler
Microsoft
PeterJNGL I don't know if this is related specifically to IronPort but it seems like your Exchange server is not enabled for AIP (Information Rights Management). Please review this document to see how to enable it and control the features:
https://docs.microsoft.com/en-us/office365/securitycompliance/manage-office-365-message-encryption
- PeterJNGLCopper Contributor
Hi Nir
It appears to have been something else but the question does still arise, if you wanted to allow a 3rd party edge device to inspect outbound and inbound mail that was protected with AIP it would need to have an ability to login into Azure AD as a superuser right and I'm talking in theory here 🙂
The same would apply to some 3rd party service that was stamping signatures on outbound e-mail correct?
- Nir Hendler
Microsoft
To integrate encryption and decryption capabilities by 3rd party apps and devices you can leverage the MIP SDK which provides you the required tools to achieve that.