Forum Discussion
Deleted
Aug 14, 2019End to end encryption with Microsoft Teams?
I am aware that Microsoft Teams has data encryption at rest and in transit. But is there a way to use E2EE? If not is metadata at least encrypted? Thanks - Hayden
- Nov 18, 2019
Jleebiker The mobile client supports App Protection Policies from InTune that would ensure that it's content is encrypted and users are authenticated on the end point device.
E2EE means something different. It means that the messages are encrypted on the senders device and can only be decrypted on the recipients device. All of the infrastructure in the middle is irrelevant as it can not decrypt the content at all. This is not how Teams works, while every stage of the journey is encrypted the service in the middle can decrypt content if it needs, for example to store data within the retention records or if you add a new person to the conversation. E2EE is only really relevant in apps which don't have any central services.
alexwall
Feb 12, 2020Copper Contributor
Are there any plans for a service like EKM (Enterprise Key Management)? Enterprise-side keys allow businesses to be 100% assured of confidentiality and can enable direct control and data portability. Otherwise, customers may have to limit their usage of the platform.
StevenC365
Feb 13, 2020MVP
alexwall Already exists ...
https://docs.microsoft.com/en-us/microsoft-365/compliance/customer-key-overview
- alexwallFeb 13, 2020Copper Contributor
Thanks, I wasn't aware that this level of encryption was available!
It says "Office 365 provides baseline, volume-level encryption enabled through BitLocker and Distributed Key Manager (DKM). Office 365 offers an added layer of encryption at the application level for your content. This content includes data from Exchange Online, Skype for Business, SharePoint Online, OneDrive for Business, and Teams files. This added layer of encryption is called service encryption."
Also, although this is a robust system of end to end encryption, Microsoft retains an availability key, which means that Microsoft could access all customer data (https://docs.microsoft.com/en-us/microsoft-365/compliance/customer-key-availability-key-understand)
The lack of encryption of Teams messages as well as the existence of an availability key for all services would be a concern for a customer that wants 100% security.
It would be nice if Teams messages were also encrypted and if there were a tier of service that could provide that only the customer had the key to access (even though if the customer loses the key/password, they would be out of luck).