SlideShare a Scribd company logo
1 of 47
BLETCHLEY
PARK 2022
A Microsoft 365 Community
COLLABORATION CONFERENCE
Wednesday, 23rd February 2022
Encryption in Microsoft 365
Albert Hoitingh
BLETCHLEY
PARK 2022
Thank you to all our Sponsors
Silver
Platinum
Gold
Silver
Community
Sponsor
Lunch
Sponsor
InSpark
Albert Hoitingh
@Alberthoitingh
https://linkedin.com/in/appieh
https://alberthoitingh.com
Sr. Consultant Microsoft 365 security, compliance & risk
@InSpark
Today’s
session
Microsoft 365 Encryption
Microsoft Information
Protection
Office 365 Message
Encryption
Heads up
…the FBI recovered a blue 16GB SanDisk SD card…
…the SD card was wrapped in plastic and placed between two
slices of bread on half of a peanut butter sandwich….
Picture and information curtesy of: How a Navy veteran
allegedly stole classified submarine docs (taskandpurpose.com)
Microsoft 365
encryption
Encryption for
Microsoft 365
• Data at rest
• Data in transit
• Specific functions:
• Microsoft Information Protection
• Information Rights Management
• Office 365 Message Encryption
Licensing considerations
• Office/Microsoft 365 E3
• Microsoft 365 E5 Compliance
• E5 eDiscovery & Audit:
• Advanced eDiscovery
• E5 Information Protection & Governance:
• Customer Key
• Double Key Encryption
• Advanced Message Encryption
Notes
• Auto-classification is included in E5
Information Protection & Governance
Microsoft 365
Data at rest
• Bitlocker (many levels)
• Per-file encryption (every file and file-
update uses a unique encryption key)
• Data encryption policies (DEP)
• SharePoint Online and OneDrive for
Business
• Exchange Online
• All other Microsoft 365 services and
Microsoft Information Protection
Microsoft 365
Data in transit
• (Mutual) Transport Layer Security
(MTLS/TLS)
• Secure Real-Time Transport Protocol
(SRTP)
• Exchange IRM – s/MIME – OME
Encryption keys for
Microsoft 365
• Microsoft managed
• Customer Key / Bring Your Own Key (BYOK)
• Double Key (Microsoft Information
Protection)
Customer Key for
Microsoft 365
• Organization provides and controls
encryption keys
• Does not prevent access to data from
Microsoft personnel
• Can be set for different DEP’s
• Uses Azure Key Vault and Hardware
Security Modules (HSM) – requires at
least 1024 bits for MIP.
Double Key for
Microsoft Information
Protection
• For specific compliance reasons
• Can be set on the label
• Complex to implement and maintain
• Content is encrypted using the tenant key
and your own key
Notes
• Only works for Office apps and the
labeling client
• Restricts transport | Microsoft Delve |
eDiscovery | Content search/indexing |
Office Web Apps & co-authoring
SharePoint
Information
Rights
Management
Information Rights
Management (IRM)
• Only works for Office and PDF documents
• Works for documents in library and lists
• Requires AD RMS
• Somewhat limited (introduced in SP2010!)
• Use sensitivity labels instead
Notes
• Does not allow for co-authoring in the
Office apps
• Does not support Office Online
• https://<SPADMIN>.sharepoint.com/_layouts
/15/online/TenantSettings.aspx
Demo time!
Where to find the
IRM settings
Sensitivity
labels
Documents and e-mails
• Label applied to document/e-mail
• Label added as metadata, stays with document
• Can be configured to:
- Apply visual markings
- Encrypt the document
- Allow offline access
- Work within DLP policies
• Works with a hierarchy, parents and sublabels
• Does not provide retention!
Encryption and labels
• Uses Azure Rights Management and Azure AD accounts
• RMS Connector for Exchange on-premises
Microsoft Managed (Azure) key details
• Symmetric AES 128/256 bit
• Key protection: Asymmetric RSA 2048 bit
• Certificate signing: SHA-256
Notes
• Licensing requirements
• Limitations (Double Key: only Office apps)
• Azure AD accounts and B2B (OTP/guest account)
• Co-authoring and auto-save for Office
Encryption and labels
File-types are important
• Some types only support labeling (no
encryption)
• Office and PDF files: native clients
• Office and PDF files: Microsoft Edge
• Other supported files: AIP Viewer client
• Watch out for the file extension
Accounts are important
• Azure AD account is required
• Can also be a guest account | Microsoft
Live account | free RMS account
• One Time Passcode will not work
Notes
• Note the Azure AD B2B settings
• Note the All authenticated label setting
Set-SPOTenant -
EnableAzureADB2BIntegration
Co-authoring and auto-save
• No possible in Office apps when
encryption is enabled
• Can be enabled using GUI or PowerShell
• Changes labeling metadata
Beware of the integrated client…
It does not support
• Label inheritance from e-mail
• On-premises scanner
• Custom permissions independently from label
• Bar in Office
• File explorer integration
• PPDF support
• Powershell labeling cmdlets
Client V2.x Integrated client
Build into Office Apps
Unified Labeling client
• BYOK/Double Key encryption
• Usage logging event viewer
• Do not forward button Outlook
• Document tracking/revoking
• Protection only mode
Demo time!
Configuring encryption
settings in labels
Office 365
Message
Encryption
Secure e-mail
• Exchange IRM or s/MIME (not for today)
• Sensitivity labels
• Encryption options Outlook - Do-not-forward
and Encrypt only (Options | Encrypt) or as
part of a label
Notes
• Known as Office 365 Message Encryption
• Mind working with attachments
• Encrypt only using a label is only
available in integrated client
Office 365 Message
Encryption (OME)
• Works with any email client
• Does not require a specific account for
the recipient (or does it?)
• Works with native Office functions and a
secure portal
• Standard options: Do-not-forward and
Encrypt only
Notes
• Does not offer any MFa-related options
(SMS for example)
• No easy “revoke” option
• Take encryption of attachments into
account!
Advanced Office 365 Message
Encryption
• Licensing: Microsoft/Office 365 E5 |
Microsoft 365 E5 Compliance | Microsoft
365 E5 Information Protection and
Governance
• Use mailrules based on sensitive
information types/keywords
• Message revocation and expiration
Notes
• For revocation and expiration to work,
you must restrict (force!) recipients to
work with the secure portal.
Encapsulated email message
• A protected e-mail becomes a .rpmsg file
• Outlook Apps (Windows, Mac, iOS/Android
and web) open natively
• Other (web) clients are redirected to the
secure portal
• File itself is always presented
Notes
• You cannot use the AIP Viewer to open
these files
• There’s a 25 MB limit per message
Office 365 Message Encryption -
Working with attachments
• Unprotected MS Office documents
• Protection is applied to the document
• Permissions differ between Do-not-forward and Encrypt
only (first is more restrictive)
• Mind the Azure AD (guest) account!
• Alternative: decrypt on download (PowerShell)
Demo time!
Office 365 Message Encryption
An example - Office 365 – Outlook web
An example – Gmail - webbrowser
An example – OME Secure Portal – including attachment
An example – Outlook client – preview screen
An example – Outlook – after opening
An example – Permissions on Word document
What about an e-mail with a
label?
• Email message and attachments are
protected
• Based on settings for the label
• If recipient is not part of the protection
– email will not be opened
• Emails can inherit the label of the
attachment, when higher
What about an e-mail with a
label?
• Email message and attachments are
protected
• Based on settings for the label
• If recipient is not part of the protection
– email will not be opened
• Emails can inherit the label of the
attachment, when higher
To think
about…
Advanced configurations PowerShell
Set-LabelPolicy -Identity “policyname” -AdvancedSettings
@{EnableCustomPermissions="False"}
Disable the custom permissions option in the Windows File Explorer
Set-LabelPolicy -Identity “Policyname” -AdvancedSettings
@{OutlookWarnUntrustedCollaborationLabel=“Labelid"}
Warn, justify or block labeled messages or messages with specific labeled
attachments using a default message
Set-LabelPolicy -Identity “policyname” -AdvancedSettings
@{OutlookJustifyTrustedDomains="contoso.com,fabrikam.com,litware.com"}
Disregard the warn, justify or block action for specific (trusted) domains
Set-IRMConfiguration -DecryptAttachmentForEncryptOnly $true
Remove the encryption from email attachments when downloaded using the browser
Keep in mind
• Sharing an encrypted file | working with
guests
• Label/encrypt using DLP rules
• Decrypt file in SPO: Unlock-
SensitivityLabelEncryptedFile
• Metadata change, MSIP_ cannot be used
anymore
Keep in mind
• eDiscovery and encryption
• Advanced eDiscovery supports all
• Content search and core eDiscovery only
support previewing and exporting
encrypted attachments
• Super User role
• Encrypted PDF’s (Adobe Acrobat | Microsoft
Edge) & Digitally signed PDF’s
Keep in mind
• Migrating content can be difficult
• Keep in mind your encrypted content
BLETCHLEY
PARK 2022
Thank You!
InSpark
Thank you!
@Alberthoitingh
https://linkedin.com/in/appieh
https://alberthoitingh.com
Many more info:
https://docs.microsoft.com/en-us/microsoft-
365/compliance/encryption?WT.mc_id=EM-MVP-
5003084

More Related Content

What's hot

Securing SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity LabelsSecuring SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity LabelsDrew Madelung
 
Azure Information Protection
Azure Information ProtectionAzure Information Protection
Azure Information ProtectionRobert Crane
 
An introduction to Office 365 Advanced Threat Protection (ATP)
An introduction to Office 365 Advanced Threat Protection (ATP)An introduction to Office 365 Advanced Threat Protection (ATP)
An introduction to Office 365 Advanced Threat Protection (ATP)Robert Crane
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonJoel Oleson
 
Microsoft Office 365 Security and Compliance
Microsoft Office 365 Security and ComplianceMicrosoft Office 365 Security and Compliance
Microsoft Office 365 Security and ComplianceDavid J Rosenthal
 
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?Albert Hoitingh
 
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...Nikki Chapple
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityDrew Madelung
 
Microsoft Information Protection.pptx
Microsoft Information Protection.pptxMicrosoft Information Protection.pptx
Microsoft Information Protection.pptxChrisaldyChandra
 
Azure information protection and SharePoint
Azure information protection and SharePoint Azure information protection and SharePoint
Azure information protection and SharePoint Albert Hoitingh
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365Joanne Klein
 
Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and ComplianceDavid J Rosenthal
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active DirectoryDavid J Rosenthal
 
Microsoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelMicrosoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelDavid J Rosenthal
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewDavid J Rosenthal
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityDrew Madelung
 
SC-900+2022.pdf
SC-900+2022.pdfSC-900+2022.pdf
SC-900+2022.pdfRitish H
 
Microsoft Azure Information Protection
Microsoft Azure Information Protection Microsoft Azure Information Protection
Microsoft Azure Information Protection Syed Sabhi Haider
 
May 2023 CIAOPS Need to Know Webinar
May 2023 CIAOPS Need to Know WebinarMay 2023 CIAOPS Need to Know Webinar
May 2023 CIAOPS Need to Know WebinarRobert Crane
 

What's hot (20)

Securing SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity LabelsSecuring SharePoint, OneDrive, & Teams with Sensitivity Labels
Securing SharePoint, OneDrive, & Teams with Sensitivity Labels
 
Azure Information Protection
Azure Information ProtectionAzure Information Protection
Azure Information Protection
 
An introduction to Office 365 Advanced Threat Protection (ATP)
An introduction to Office 365 Advanced Threat Protection (ATP)An introduction to Office 365 Advanced Threat Protection (ATP)
An introduction to Office 365 Advanced Threat Protection (ATP)
 
Microsoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel OlesonMicrosoft Teams Governance and Security Best Practices - Joel Oleson
Microsoft Teams Governance and Security Best Practices - Joel Oleson
 
Microsoft Office 365 Security and Compliance
Microsoft Office 365 Security and ComplianceMicrosoft Office 365 Security and Compliance
Microsoft Office 365 Security and Compliance
 
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
ExpertsLive NL 2022 - Microsoft Purview - What's in it for my organization?
 
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
Microsoft Information Protection.pptx
Microsoft Information Protection.pptxMicrosoft Information Protection.pptx
Microsoft Information Protection.pptx
 
Azure information protection and SharePoint
Azure information protection and SharePoint Azure information protection and SharePoint
Azure information protection and SharePoint
 
IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365IRMS UG Principles of Retention in Microsoft 365
IRMS UG Principles of Retention in Microsoft 365
 
Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and Compliance
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active Directory
 
Microsoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelMicrosoft Defender and Azure Sentinel
Microsoft Defender and Azure Sentinel
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security Overview
 
Labelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & SensitivityLabelling in Microsoft 365 - Retention & Sensitivity
Labelling in Microsoft 365 - Retention & Sensitivity
 
SC-900+2022.pdf
SC-900+2022.pdfSC-900+2022.pdf
SC-900+2022.pdf
 
Microsoft 365 Compliance
Microsoft 365 ComplianceMicrosoft 365 Compliance
Microsoft 365 Compliance
 
Microsoft Azure Information Protection
Microsoft Azure Information Protection Microsoft Azure Information Protection
Microsoft Azure Information Protection
 
May 2023 CIAOPS Need to Know Webinar
May 2023 CIAOPS Need to Know WebinarMay 2023 CIAOPS Need to Know Webinar
May 2023 CIAOPS Need to Know Webinar
 

Similar to Encryption in Microsoft 365 - session for CollabDays UK - Bletchley Park

Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...
Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...
Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...Albert Hoitingh
 
Scottish Summit 2022 - Microsoft Information Protection de-mystified
Scottish Summit 2022 - Microsoft Information Protection de-mystifiedScottish Summit 2022 - Microsoft Information Protection de-mystified
Scottish Summit 2022 - Microsoft Information Protection de-mystifiedAlbert Hoitingh
 
Scottish Summit - Sensitivity labels deep dive
Scottish Summit - Sensitivity labels deep diveScottish Summit - Sensitivity labels deep dive
Scottish Summit - Sensitivity labels deep diveAlbert Hoitingh
 
Scottish Summit - Azure Information Protection and SharePoint 2020
Scottish Summit - Azure Information Protection and SharePoint 2020Scottish Summit - Azure Information Protection and SharePoint 2020
Scottish Summit - Azure Information Protection and SharePoint 2020Albert Hoitingh
 
Intelligent Security, Compliance and Privacy in Office 365
Intelligent Security, Compliance and Privacy in Office 365Intelligent Security, Compliance and Privacy in Office 365
Intelligent Security, Compliance and Privacy in Office 365Miguel Isidoro
 
May 2020 Microsoft 365 Need to Know Webinar
May 2020 Microsoft 365 Need to Know WebinarMay 2020 Microsoft 365 Need to Know Webinar
May 2020 Microsoft 365 Need to Know WebinarRobert Crane
 
Solving the security & compliance puzzle for Office 365 and Microsoft 365
Solving the security & compliance puzzle for Office 365 and Microsoft 365Solving the security & compliance puzzle for Office 365 and Microsoft 365
Solving the security & compliance puzzle for Office 365 and Microsoft 365Albert Hoitingh
 
Office 365 Best Practices That You Are Not Thinking About
Office 365 Best Practices That You Are Not Thinking AboutOffice 365 Best Practices That You Are Not Thinking About
Office 365 Best Practices That You Are Not Thinking AboutQuest
 
What's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and TeamsWhat's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and TeamsDrew Madelung
 
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLaboraDK
 
Azure Information Protection at the Cybercrime and Security Forum 2018
Azure Information Protection at the Cybercrime and Security Forum 2018Azure Information Protection at the Cybercrime and Security Forum 2018
Azure Information Protection at the Cybercrime and Security Forum 2018Albert Hoitingh
 
CSF18 Azure Information Protection - Albert Hoitingh
CSF18   Azure Information Protection - Albert HoitinghCSF18   Azure Information Protection - Albert Hoitingh
CSF18 Azure Information Protection - Albert HoitinghNCCOMMS
 
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...Sébastien Paulet
 
SPS Geneva - Azure information protection
SPS Geneva - Azure information protectionSPS Geneva - Azure information protection
SPS Geneva - Azure information protectionAlbert Hoitingh
 
SMB Security Product Overview.pptx
SMB Security Product Overview.pptxSMB Security Product Overview.pptx
SMB Security Product Overview.pptxkovec2684
 
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptx
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptxCommsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptx
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptxAlbert Hoitingh
 

Similar to Encryption in Microsoft 365 - session for CollabDays UK - Bletchley Park (20)

Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...
Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...
Modern Workplace Conference 2022 - Paris Microsoft Information Protection Dem...
 
Scottish Summit 2022 - Microsoft Information Protection de-mystified
Scottish Summit 2022 - Microsoft Information Protection de-mystifiedScottish Summit 2022 - Microsoft Information Protection de-mystified
Scottish Summit 2022 - Microsoft Information Protection de-mystified
 
Scottish Summit - Sensitivity labels deep dive
Scottish Summit - Sensitivity labels deep diveScottish Summit - Sensitivity labels deep dive
Scottish Summit - Sensitivity labels deep dive
 
Scottish Summit - Azure Information Protection and SharePoint 2020
Scottish Summit - Azure Information Protection and SharePoint 2020Scottish Summit - Azure Information Protection and SharePoint 2020
Scottish Summit - Azure Information Protection and SharePoint 2020
 
Intelligent Security, Compliance and Privacy in Office 365
Intelligent Security, Compliance and Privacy in Office 365Intelligent Security, Compliance and Privacy in Office 365
Intelligent Security, Compliance and Privacy in Office 365
 
Real world rm in share point 2013
Real world rm in share point 2013Real world rm in share point 2013
Real world rm in share point 2013
 
May 2020 Microsoft 365 Need to Know Webinar
May 2020 Microsoft 365 Need to Know WebinarMay 2020 Microsoft 365 Need to Know Webinar
May 2020 Microsoft 365 Need to Know Webinar
 
Solving the security & compliance puzzle for Office 365 and Microsoft 365
Solving the security & compliance puzzle for Office 365 and Microsoft 365Solving the security & compliance puzzle for Office 365 and Microsoft 365
Solving the security & compliance puzzle for Office 365 and Microsoft 365
 
Information Governance in office 365 records management and retention
Information Governance in office 365 records management and retentionInformation Governance in office 365 records management and retention
Information Governance in office 365 records management and retention
 
Office 365 Best Practices That You Are Not Thinking About
Office 365 Best Practices That You Are Not Thinking AboutOffice 365 Best Practices That You Are Not Thinking About
Office 365 Best Practices That You Are Not Thinking About
 
What's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and TeamsWhat's new with Security & Compliance for SharePoint, OneDrive, and Teams
What's new with Security & Compliance for SharePoint, OneDrive, and Teams
 
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
 
Azure Information Protection at the Cybercrime and Security Forum 2018
Azure Information Protection at the Cybercrime and Security Forum 2018Azure Information Protection at the Cybercrime and Security Forum 2018
Azure Information Protection at the Cybercrime and Security Forum 2018
 
CSF18 Azure Information Protection - Albert Hoitingh
CSF18   Azure Information Protection - Albert HoitinghCSF18   Azure Information Protection - Albert Hoitingh
CSF18 Azure Information Protection - Albert Hoitingh
 
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
 
SPS Geneva - Azure information protection
SPS Geneva - Azure information protectionSPS Geneva - Azure information protection
SPS Geneva - Azure information protection
 
SMB Security Product Overview.pptx
SMB Security Product Overview.pptxSMB Security Product Overview.pptx
SMB Security Product Overview.pptx
 
Real world records management in SharePoint 2013
Real world records management in SharePoint 2013Real world records management in SharePoint 2013
Real world records management in SharePoint 2013
 
Real world records management in share point 2013
Real world records management in share point 2013Real world records management in share point 2013
Real world records management in share point 2013
 
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptx
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptxCommsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptx
Commsverse 2022 eDiscovery and Microsoft Teams - SlideShare.pptx
 

More from Albert Hoitingh

Meetup DIWUG Januari 2024 - Data Loss Prevention
Meetup DIWUG Januari 2024 - Data Loss PreventionMeetup DIWUG Januari 2024 - Data Loss Prevention
Meetup DIWUG Januari 2024 - Data Loss PreventionAlbert Hoitingh
 
Global Security and Compliance Conference - Cologne
Global Security and Compliance Conference - CologneGlobal Security and Compliance Conference - Cologne
Global Security and Compliance Conference - CologneAlbert Hoitingh
 
Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Albert Hoitingh
 
Teams Day Online V - Information Barriers - Communication Compliance and Micr...
Teams Day Online V - Information Barriers - Communication Compliance and Micr...Teams Day Online V - Information Barriers - Communication Compliance and Micr...
Teams Day Online V - Information Barriers - Communication Compliance and Micr...Albert Hoitingh
 
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...Albert Hoitingh
 
Microsoft 365 Chicago - eDiscovery and Microsoft Teams
Microsoft 365 Chicago - eDiscovery and Microsoft TeamsMicrosoft 365 Chicago - eDiscovery and Microsoft Teams
Microsoft 365 Chicago - eDiscovery and Microsoft TeamsAlbert Hoitingh
 
eDiscovery and Microsoft Teams
eDiscovery and Microsoft TeamseDiscovery and Microsoft Teams
eDiscovery and Microsoft TeamsAlbert Hoitingh
 
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionaMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionAlbert Hoitingh
 
Microsoft 365 and Microsoft Cloud App Security
Microsoft 365 and Microsoft Cloud App SecurityMicrosoft 365 and Microsoft Cloud App Security
Microsoft 365 and Microsoft Cloud App SecurityAlbert Hoitingh
 
Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021Albert Hoitingh
 
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance Albert Hoitingh
 
Global Security and Compliance Community conference 2021
Global Security and Compliance Community conference 2021Global Security and Compliance Community conference 2021
Global Security and Compliance Community conference 2021Albert Hoitingh
 
Teams Nation December 2020 - Teams Compliance
Teams Nation December 2020 - Teams ComplianceTeams Nation December 2020 - Teams Compliance
Teams Nation December 2020 - Teams ComplianceAlbert Hoitingh
 
CollabDays BeNeLux Sensitivity labels: what's new
CollabDays BeNeLux Sensitivity labels: what's newCollabDays BeNeLux Sensitivity labels: what's new
CollabDays BeNeLux Sensitivity labels: what's newAlbert Hoitingh
 
Teams Day Online - Microsoft Teams Governance
Teams Day Online - Microsoft Teams GovernanceTeams Day Online - Microsoft Teams Governance
Teams Day Online - Microsoft Teams GovernanceAlbert Hoitingh
 
Microsoft 365 UK Usergroup 2020 Sensitivity labels
Microsoft 365 UK Usergroup 2020 Sensitivity labelsMicrosoft 365 UK Usergroup 2020 Sensitivity labels
Microsoft 365 UK Usergroup 2020 Sensitivity labelsAlbert Hoitingh
 
Dutch Microsoft Security Meetup Windows Information Protection
Dutch Microsoft Security Meetup Windows Information ProtectionDutch Microsoft Security Meetup Windows Information Protection
Dutch Microsoft Security Meetup Windows Information ProtectionAlbert Hoitingh
 
Office 365 and SharePoint Connect 2019 - Dispose with care
Office 365 and SharePoint Connect 2019 - Dispose with careOffice 365 and SharePoint Connect 2019 - Dispose with care
Office 365 and SharePoint Connect 2019 - Dispose with careAlbert Hoitingh
 
SharePoint Saturday Netherlands 2019 - Citizen dev. and the admin
SharePoint Saturday Netherlands 2019 - Citizen dev. and the adminSharePoint Saturday Netherlands 2019 - Citizen dev. and the admin
SharePoint Saturday Netherlands 2019 - Citizen dev. and the adminAlbert Hoitingh
 
Expertslive NL 2019 Unified Labeling
Expertslive NL 2019 Unified LabelingExpertslive NL 2019 Unified Labeling
Expertslive NL 2019 Unified LabelingAlbert Hoitingh
 

More from Albert Hoitingh (20)

Meetup DIWUG Januari 2024 - Data Loss Prevention
Meetup DIWUG Januari 2024 - Data Loss PreventionMeetup DIWUG Januari 2024 - Data Loss Prevention
Meetup DIWUG Januari 2024 - Data Loss Prevention
 
Global Security and Compliance Conference - Cologne
Global Security and Compliance Conference - CologneGlobal Security and Compliance Conference - Cologne
Global Security and Compliance Conference - Cologne
 
Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...Microsoft Purview Information Barriers and Communication Compliance and Micro...
Microsoft Purview Information Barriers and Communication Compliance and Micro...
 
Teams Day Online V - Information Barriers - Communication Compliance and Micr...
Teams Day Online V - Information Barriers - Communication Compliance and Micr...Teams Day Online V - Information Barriers - Communication Compliance and Micr...
Teams Day Online V - Information Barriers - Communication Compliance and Micr...
 
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
Dutch Information Worker User Group - January 2022 - eDiscovery and Microsoft...
 
Microsoft 365 Chicago - eDiscovery and Microsoft Teams
Microsoft 365 Chicago - eDiscovery and Microsoft TeamsMicrosoft 365 Chicago - eDiscovery and Microsoft Teams
Microsoft 365 Chicago - eDiscovery and Microsoft Teams
 
eDiscovery and Microsoft Teams
eDiscovery and Microsoft TeamseDiscovery and Microsoft Teams
eDiscovery and Microsoft Teams
 
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionaMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
 
Microsoft 365 and Microsoft Cloud App Security
Microsoft 365 and Microsoft Cloud App SecurityMicrosoft 365 and Microsoft Cloud App Security
Microsoft 365 and Microsoft Cloud App Security
 
Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021Working securely with Microsoft Teams - Techorama 2021
Working securely with Microsoft Teams - Techorama 2021
 
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance
Microsoft 365 Security & Compliance User Group - Microsoft Teams compliance
 
Global Security and Compliance Community conference 2021
Global Security and Compliance Community conference 2021Global Security and Compliance Community conference 2021
Global Security and Compliance Community conference 2021
 
Teams Nation December 2020 - Teams Compliance
Teams Nation December 2020 - Teams ComplianceTeams Nation December 2020 - Teams Compliance
Teams Nation December 2020 - Teams Compliance
 
CollabDays BeNeLux Sensitivity labels: what's new
CollabDays BeNeLux Sensitivity labels: what's newCollabDays BeNeLux Sensitivity labels: what's new
CollabDays BeNeLux Sensitivity labels: what's new
 
Teams Day Online - Microsoft Teams Governance
Teams Day Online - Microsoft Teams GovernanceTeams Day Online - Microsoft Teams Governance
Teams Day Online - Microsoft Teams Governance
 
Microsoft 365 UK Usergroup 2020 Sensitivity labels
Microsoft 365 UK Usergroup 2020 Sensitivity labelsMicrosoft 365 UK Usergroup 2020 Sensitivity labels
Microsoft 365 UK Usergroup 2020 Sensitivity labels
 
Dutch Microsoft Security Meetup Windows Information Protection
Dutch Microsoft Security Meetup Windows Information ProtectionDutch Microsoft Security Meetup Windows Information Protection
Dutch Microsoft Security Meetup Windows Information Protection
 
Office 365 and SharePoint Connect 2019 - Dispose with care
Office 365 and SharePoint Connect 2019 - Dispose with careOffice 365 and SharePoint Connect 2019 - Dispose with care
Office 365 and SharePoint Connect 2019 - Dispose with care
 
SharePoint Saturday Netherlands 2019 - Citizen dev. and the admin
SharePoint Saturday Netherlands 2019 - Citizen dev. and the adminSharePoint Saturday Netherlands 2019 - Citizen dev. and the admin
SharePoint Saturday Netherlands 2019 - Citizen dev. and the admin
 
Expertslive NL 2019 Unified Labeling
Expertslive NL 2019 Unified LabelingExpertslive NL 2019 Unified Labeling
Expertslive NL 2019 Unified Labeling
 

Recently uploaded

Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 

Recently uploaded (20)

Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 

Encryption in Microsoft 365 - session for CollabDays UK - Bletchley Park

  • 1. BLETCHLEY PARK 2022 A Microsoft 365 Community COLLABORATION CONFERENCE Wednesday, 23rd February 2022 Encryption in Microsoft 365 Albert Hoitingh
  • 2. BLETCHLEY PARK 2022 Thank you to all our Sponsors Silver Platinum Gold Silver Community Sponsor Lunch Sponsor
  • 4. Today’s session Microsoft 365 Encryption Microsoft Information Protection Office 365 Message Encryption Heads up
  • 5. …the FBI recovered a blue 16GB SanDisk SD card… …the SD card was wrapped in plastic and placed between two slices of bread on half of a peanut butter sandwich…. Picture and information curtesy of: How a Navy veteran allegedly stole classified submarine docs (taskandpurpose.com)
  • 7. Encryption for Microsoft 365 • Data at rest • Data in transit • Specific functions: • Microsoft Information Protection • Information Rights Management • Office 365 Message Encryption
  • 8. Licensing considerations • Office/Microsoft 365 E3 • Microsoft 365 E5 Compliance • E5 eDiscovery & Audit: • Advanced eDiscovery • E5 Information Protection & Governance: • Customer Key • Double Key Encryption • Advanced Message Encryption Notes • Auto-classification is included in E5 Information Protection & Governance
  • 9. Microsoft 365 Data at rest • Bitlocker (many levels) • Per-file encryption (every file and file- update uses a unique encryption key) • Data encryption policies (DEP) • SharePoint Online and OneDrive for Business • Exchange Online • All other Microsoft 365 services and Microsoft Information Protection
  • 10. Microsoft 365 Data in transit • (Mutual) Transport Layer Security (MTLS/TLS) • Secure Real-Time Transport Protocol (SRTP) • Exchange IRM – s/MIME – OME
  • 11. Encryption keys for Microsoft 365 • Microsoft managed • Customer Key / Bring Your Own Key (BYOK) • Double Key (Microsoft Information Protection)
  • 12. Customer Key for Microsoft 365 • Organization provides and controls encryption keys • Does not prevent access to data from Microsoft personnel • Can be set for different DEP’s • Uses Azure Key Vault and Hardware Security Modules (HSM) – requires at least 1024 bits for MIP.
  • 13. Double Key for Microsoft Information Protection • For specific compliance reasons • Can be set on the label • Complex to implement and maintain • Content is encrypted using the tenant key and your own key Notes • Only works for Office apps and the labeling client • Restricts transport | Microsoft Delve | eDiscovery | Content search/indexing | Office Web Apps & co-authoring
  • 15. Information Rights Management (IRM) • Only works for Office and PDF documents • Works for documents in library and lists • Requires AD RMS • Somewhat limited (introduced in SP2010!) • Use sensitivity labels instead Notes • Does not allow for co-authoring in the Office apps • Does not support Office Online • https://<SPADMIN>.sharepoint.com/_layouts /15/online/TenantSettings.aspx
  • 16. Demo time! Where to find the IRM settings
  • 18. Documents and e-mails • Label applied to document/e-mail • Label added as metadata, stays with document • Can be configured to: - Apply visual markings - Encrypt the document - Allow offline access - Work within DLP policies • Works with a hierarchy, parents and sublabels • Does not provide retention!
  • 19. Encryption and labels • Uses Azure Rights Management and Azure AD accounts • RMS Connector for Exchange on-premises Microsoft Managed (Azure) key details • Symmetric AES 128/256 bit • Key protection: Asymmetric RSA 2048 bit • Certificate signing: SHA-256 Notes • Licensing requirements • Limitations (Double Key: only Office apps) • Azure AD accounts and B2B (OTP/guest account) • Co-authoring and auto-save for Office
  • 21. File-types are important • Some types only support labeling (no encryption) • Office and PDF files: native clients • Office and PDF files: Microsoft Edge • Other supported files: AIP Viewer client • Watch out for the file extension
  • 22. Accounts are important • Azure AD account is required • Can also be a guest account | Microsoft Live account | free RMS account • One Time Passcode will not work Notes • Note the Azure AD B2B settings • Note the All authenticated label setting Set-SPOTenant - EnableAzureADB2BIntegration
  • 23. Co-authoring and auto-save • No possible in Office apps when encryption is enabled • Can be enabled using GUI or PowerShell • Changes labeling metadata
  • 24. Beware of the integrated client… It does not support • Label inheritance from e-mail • On-premises scanner • Custom permissions independently from label • Bar in Office • File explorer integration • PPDF support • Powershell labeling cmdlets Client V2.x Integrated client Build into Office Apps Unified Labeling client • BYOK/Double Key encryption • Usage logging event viewer • Do not forward button Outlook • Document tracking/revoking • Protection only mode
  • 27. Secure e-mail • Exchange IRM or s/MIME (not for today) • Sensitivity labels • Encryption options Outlook - Do-not-forward and Encrypt only (Options | Encrypt) or as part of a label Notes • Known as Office 365 Message Encryption • Mind working with attachments • Encrypt only using a label is only available in integrated client
  • 28. Office 365 Message Encryption (OME) • Works with any email client • Does not require a specific account for the recipient (or does it?) • Works with native Office functions and a secure portal • Standard options: Do-not-forward and Encrypt only Notes • Does not offer any MFa-related options (SMS for example) • No easy “revoke” option • Take encryption of attachments into account!
  • 29. Advanced Office 365 Message Encryption • Licensing: Microsoft/Office 365 E5 | Microsoft 365 E5 Compliance | Microsoft 365 E5 Information Protection and Governance • Use mailrules based on sensitive information types/keywords • Message revocation and expiration Notes • For revocation and expiration to work, you must restrict (force!) recipients to work with the secure portal.
  • 30. Encapsulated email message • A protected e-mail becomes a .rpmsg file • Outlook Apps (Windows, Mac, iOS/Android and web) open natively • Other (web) clients are redirected to the secure portal • File itself is always presented Notes • You cannot use the AIP Viewer to open these files • There’s a 25 MB limit per message
  • 31. Office 365 Message Encryption - Working with attachments • Unprotected MS Office documents • Protection is applied to the document • Permissions differ between Do-not-forward and Encrypt only (first is more restrictive) • Mind the Azure AD (guest) account! • Alternative: decrypt on download (PowerShell)
  • 32. Demo time! Office 365 Message Encryption
  • 33. An example - Office 365 – Outlook web
  • 34. An example – Gmail - webbrowser
  • 35. An example – OME Secure Portal – including attachment
  • 36. An example – Outlook client – preview screen
  • 37. An example – Outlook – after opening
  • 38. An example – Permissions on Word document
  • 39. What about an e-mail with a label? • Email message and attachments are protected • Based on settings for the label • If recipient is not part of the protection – email will not be opened • Emails can inherit the label of the attachment, when higher
  • 40. What about an e-mail with a label? • Email message and attachments are protected • Based on settings for the label • If recipient is not part of the protection – email will not be opened • Emails can inherit the label of the attachment, when higher
  • 42. Advanced configurations PowerShell Set-LabelPolicy -Identity “policyname” -AdvancedSettings @{EnableCustomPermissions="False"} Disable the custom permissions option in the Windows File Explorer Set-LabelPolicy -Identity “Policyname” -AdvancedSettings @{OutlookWarnUntrustedCollaborationLabel=“Labelid"} Warn, justify or block labeled messages or messages with specific labeled attachments using a default message Set-LabelPolicy -Identity “policyname” -AdvancedSettings @{OutlookJustifyTrustedDomains="contoso.com,fabrikam.com,litware.com"} Disregard the warn, justify or block action for specific (trusted) domains Set-IRMConfiguration -DecryptAttachmentForEncryptOnly $true Remove the encryption from email attachments when downloaded using the browser
  • 43. Keep in mind • Sharing an encrypted file | working with guests • Label/encrypt using DLP rules • Decrypt file in SPO: Unlock- SensitivityLabelEncryptedFile • Metadata change, MSIP_ cannot be used anymore
  • 44. Keep in mind • eDiscovery and encryption • Advanced eDiscovery supports all • Content search and core eDiscovery only support previewing and exporting encrypted attachments • Super User role • Encrypted PDF’s (Adobe Acrobat | Microsoft Edge) & Digitally signed PDF’s
  • 45. Keep in mind • Migrating content can be difficult • Keep in mind your encrypted content
  • 47. InSpark Thank you! @Alberthoitingh https://linkedin.com/in/appieh https://alberthoitingh.com Many more info: https://docs.microsoft.com/en-us/microsoft- 365/compliance/encryption?WT.mc_id=EM-MVP- 5003084