Forum Discussion
External users cannot open encrypted email
- Jun 04, 2020
Hi, I received your test message and whilst I was unable to access it via the Gmail web interface, I was able to open it via Outlook using the AIP viewer. This is going to be the only way that the Gmail users will be able to do this.
As ChristianBergstrom pointed out, the options you are using for encryption are the built-in OME / and older default AIP templates. I would recommend taking a look at updating your labels and policies. Could be a good time to start looking to migrate to Sensitivity Labels from the Security and Compliance Center, as Microsoft are planning to "sunset" the older AIP method in 2021 as per https://techcommunity.microsoft.com/t5/azure-information-protection/announcing-timelines-for-sunsetting-label-management-in-the/ba-p/1226179
But, for the meantime, if you want Gmail accounts to access the encrypted emails, then Outlook and the. AIP viewer is going to be the way.
ashmelburnian Hey! There's really no need to look for third-party solutions when you have them built-in with your subscriptions. Not only in Office Message Encryption but you mentioned AIP as well. If you don't want to update your AIP settings or migrate to the unified labeling experience you could at least configure OME (for the end-users to choose as an option or as mail flow rule) as it should solve the particular external encryption issue.
"All Microsoft 365 end-users that use Outlook clients to read mail receive native, first-class reading experiences for encrypted and rights-protected mail even if they're not in the same organization as the sender. Supported Outlook clients include Outlook desktop, Outlook Mac, Outlook mobile on iOS and Android, and Outlook on the web (formerly known as Outlook Web App)."
Recipients of encrypted messages who receive encrypted or rights-protected mail sent to their Outlook.com, Gmail, and Yahoo accounts receive a wrapper mail that directs them to the OME Portal where they can easily authenticate using a Microsoft account, Gmail, or Yahoo credentials.
End-users that read encrypted or rights-protected mail on clients other than Outlook also use the OME portal to view encrypted and rights-protected messages that they receive."
OME FAQ
https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-faq?view=o365-worldwide
- ChristianBergstromJun 11, 2020Silver ContributorThat is great news! Well done!
- ashmelburnianJun 10, 2020Brass ContributorThanks for all the help! Those 2 articles got me across the line.
- ChristianBergstromJun 09, 2020Silver Contributor
ashmelburnian Hello! See if this can help you out (I'm having a busy day!)
https://davidatkin.com/blog/no-rms-templates-are-available-in-your-organization/
Look at the last reply here as well https://techcommunity.microsoft.com/t5/azure/email-encryption-in-office-365-with-azure/m-p/142164
- ashmelburnianJun 09, 2020Brass Contributor
ChristianBergstrom Thanks for your help. I'm beginning to understand the process now.
I'm currently working through https://docs.microsoft.com/en-us/microsoft-365/compliance/set-up-new-message-encryption-capabilities?view=o365-worldwide and have run into the following PowerShell warning & failure:Test-IRMConfiguration -sender user@domain.comResults : Checking Exchange Server ...- PASS: Exchange Server is running in Datacenter.Loading IRM configuration ...- PASS: IRM configuration loaded successfully.Retrieving RMS Certification Uri ...- WARNING: Failed to retrieve RMS Certification Uri.OVERALL RESULT: PASS with warnings on disabled featuresTest-IRMConfiguration -RMSOnlineResults : Checking organization context ...- PASS: Organization context checked; running as tenant administrator.Loading IRM configuration ...- PASS: IRM configuration loaded successfully.Checking RMS Online tenant prerequisites ...- PASS: RMS Online tenant prerequisites passed.Checking RMS Online authentication certificate ...- PASS: The RMS Online authentication certificate is valid.Checking that a Trusted Publishing Domain can be obtained from RMS Online ...- FAIL: Failed to obtain a Trusted Publishing Domain from RMS Online.----------------------------------------RMS Online error code: TenantIdNotFoundMicrosoft.Exchange.Management.RightsManagement.RmsOnlineImportTpdException: RMS Online returned an error fortenant with external directory organization ID 123456-789-abcd-b882-fdfef4302be3at Microsoft.Exchange.Management.RightsManagement.RmsUtil.ThrowIfErrorInfoObjectReturned(TenantInfotenantInfo, Guid externalDirectoryOrgId)at Microsoft.Exchange.Management.RightsManagement.RmsOnlineTpdImporter.Import(Guid externalDirectoryOrgId)at Microsoft.Exchange.Management.RightsManagement.RMSOnlineValidator.ValidateTPDCanBeObtainedFromRMSOnline(RmsOnlineTpdImporter tpdImporter, TrustedDocDomain& tpd)----------------------------------------OVERALL RESULT: FAILThere are no default RMS templates to select under Exchange mail flow rules:Can you please assist further? - PeterRisingJun 07, 2020MVP
Completely agree with this!
If you go third party I think you will ultimately end up with further frustrations. It's all there for you with Microsoft. It's just a matter of finding the right settings that work for you.