Forum Discussion
End to end encryption with Microsoft Teams?
- Nov 18, 2019
Jleebiker The mobile client supports App Protection Policies from InTune that would ensure that it's content is encrypted and users are authenticated on the end point device.
E2EE means something different. It means that the messages are encrypted on the senders device and can only be decrypted on the recipients device. All of the infrastructure in the middle is irrelevant as it can not decrypt the content at all. This is not how Teams works, while every stage of the journey is encrypted the service in the middle can decrypt content if it needs, for example to store data within the retention records or if you add a new person to the conversation. E2EE is only really relevant in apps which don't have any central services.
StevenC365 Ecnryption in a teams context would look like this:
- end users would have keys that could be used to decrypt data
- data would live encrypted in sharepoint
- users would decrypt at the time of reading/opening/viewing data
- content scanning, monitoring, indexing would be done on the endpoint, at the time of content creation/editing
- certain features may not be available for content encrypted this way
I think the lack of sound custody is probably the #1 reason organizations choose not to use cloud services in general, Teams included. E2E encryption would go a long way toward alleviating that.
cto-erik for your theoretical search index to work every client would need to download every message in every channel. Also not really sure how any web UI would work.