Outlook message encryption - avoid delegate access

%3CLINGO-SUB%20id%3D%22lingo-sub-2621196%22%20slang%3D%22en-US%22%3EOutlook%20message%20encryption%20-%20avoid%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2621196%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewe%20have%20following%20challenge.%3C%2FP%3E%3CP%3EWe%20would%20like%20to%20use%20the%20message%20encryption%20option%20(OME)%3C%2FP%3E%3CP%3EIt%C2%B4s%20simple%20to%20implement%20and%20fits%20for%20most%20of%20our%20needs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20we%20have%20one%20scenario%20where%20it%20doesnt%20fits%20or%20at%20least%20I%20couldnt%20find%20a%20solution%20in%20this%20community%20or%20in%20Internet.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20director%20wants%20to%20delegate%20access%20to%20his%20assistant%20including%20inbox%20but%20shouldnt%20be%20able%20read%20encrypted%20emails%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20a%20solution%20for%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20your%20support...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2621196%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%20Message%20Encryption%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2621494%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20message%20encryption%20-%20avoid%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2621494%22%20slang%3D%22en-US%22%3EHello%2C%20if%20you%20can%20restrict%20the%20assistant%20to%20use%20Outlook%20for%20Windows%20only%20it's%20possible.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fome-faq%3Fview%3Do365-worldwide%23is-delegated-access-supported-with-opening-encrypted-messages--even-if-a-delegate-has-full-access-to-another-user-s-mailbox-%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fome-faq%3Fview%3Do365-worldwide%23is-delegated-access-supported-with-opening-encrypted-messages--even-if-a-delegate-has-full-access-to-another-user-s-mailbox-%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2621637%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20message%20encryption%20-%20avoid%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2621637%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F588790%22%20target%3D%22_blank%22%3E%40ChristianJBergstrom%3C%2FA%3E%26nbsp%3Bthanks%20for%20your%20quick%20answer.%3C%2FP%3E%3CP%3EIf%20I%20understand%20you%20well%2C%20OME%20don%C2%B4t%20have%20a%20solution%20for%20this%20use%20case%2C%20right%3F%3C%2FP%3E%3CP%3ETo%20somehow%20block%20all%20except%20Outlook%20Windows%20dont%20think%20it%20is%20a%20good%20idea.%3C%2FP%3E%3CP%3EIt%20will%20be%20challeging%20to%20assure%20never%20get%20access..%3C%2FP%3E%3CP%3EMaybe%20there%20is%20a%20way%20via%20Powershell%3F%3C%2FP%3E%3CP%3EQuestion%20is%20if%20it%20is%20possible...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20a%20lot%20anyway%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2621823%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20message%20encryption%20-%20avoid%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2621823%22%20slang%3D%22en-US%22%3EYou%E2%80%99re%20correct.%20OME%20cannot%20accomplish%20what%20you%E2%80%99re%20looking%20for.%20There%20used%20to%20be%20a%20MIP%20UserVoice%20request%20for%20this%20scenario%2C%20but%20as%20Microsoft%20has%20closed%20down%20UV%20for%20this%20and%20other%20products%20I%20don%E2%80%99t%20know%20what%20has%20happened%20to%20it.%20Sorry..%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2850705%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20message%20encryption%20-%20avoid%20delegate%20access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2850705%22%20slang%3D%22en-US%22%3E%3CP%3EiOS%20and%20Android%20allow%20opening%20an%20encrypted%20message%20of%20a%20delegated%20mailbox.%20Any%20way%20to%20disable%20this%20similar%20to%20disabling%20access%20to%20OWA%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Dear community,

 

we have following challenge.

We would like to use the message encryption option (OME)

It´s simple to implement and fits for most of our needs.

 

However we have one scenario where it doesnt fits or at least I couldnt find a solution in this community or in Internet.

 

Our director wants to delegate access to his assistant including inbox but shouldnt be able read encrypted emails 

Is there a solution for this?

 

Thanks for your support...

 

11 Replies
Hello, if you can restrict the assistant to use Outlook for Windows only it's possible.

https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-faq?view=o365-worldwide#is-delegated-a...

@ChristianJBergstrom thanks for your quick answer.

If I understand you well, OME don´t have a solution for this use case, right?

To somehow block all except Outlook Windows dont think it is a good idea.

It will be challeging to assure never get access..

Maybe there is a way via Powershell?

Question is if it is possible...

 

Thanks a lot anyway :)

 

 

You’re correct. OME cannot accomplish what you’re looking for. There used to be a MIP UserVoice request for this scenario, but as Microsoft has closed down UV for this and other products I don’t know what has happened to it. Sorry..

iOS and Android allow opening an encrypted message of a delegated mailbox. Any way to disable this similar to disabling access to OWA?

Don't know really, not within my field so to speak.

"Is delegated access supported with opening encrypted messages? Even if a delegate has full access to another user's mailbox?

- Delegated access of encrypted mail is supported in Outlook on the web, Outlook for Mac, Outlook for iOS, and Outlook for Android. Outlook for Windows does not support delegated access."

https://docs.microsoft.com/en-us/microsoft-365/compliance/ome-faq?view=o365-worldwide#is-delegated-a...

OME isn't really designed to handle complex access situations. If I were you. I'd consider using a sensitivity label that restricts access to a limited set of reciipients.

Agreed, but if going down that road it needs some structure and planning incl. people from your business (to classify and protect). I.e. the very opposite from the easy to use built-in encryption with OME @josecachairo 

@ChristianJBergstrom 

hi all,

meanwhile we tested and indeed delegates CAN´T read encrypted emails. So it is working as we expected and Microsoft information is confusing (not clear enough) to this matter.

So if you use OME, delegate can´t not read those emails (encrypt only).

I recommend you to test it also in iOS, Android to be sure.

See below.

Thanks @ChristianJBergstrom  and @josecachairo. This is helpful.

@BHartNL @josecachairo Hello again, simply writing to update and correct my previous reply. It didn't seem consistent (logical) so thought it might had to be because all of my cached credentials doing all my testing. So I set it up again, from scratch and this time with a new W10 profile as well.

 

1. The delegate cannot see the encrypted email (just the wrapper). If clicking it will direct to error.

2. The delegate can see it using Outlook on the web.