Resolve Microsoft Purview Message Encryption issues - Microsoft 365 (2024)

  • Article
  • Applies to:
    Microsoft Purview, Outlook for Microsoft 365, Outlook 2021, Outlook 2019, Outlook 2016, Outlook for Mac for Microsoft 365, Outlook 2021 for Mac, Outlook 2019 for Mac

Symptoms

Users in your organization experience one or more of the following issues:

  • They can't open encrypted email messages in Microsoft Outlook or Outlook on the web.
  • They can't send encrypted email messages.
  • The Encrypt button is missing in both Outlook and Outlook on the web.

Cause

These issues can occur for several reasons, such as:

  • Your organization's Microsoft 365 subscription doesn't support Microsoft Purview Message Encryption.
  • The tenant that's used by your organization is misconfigured.
  • The account that's used by the affected users to sign in to Outlook or Outlook on the web isn't assigned a valid license to use the Microsoft Purview Message Encryption (Office 365 Message Encryption) feature.

Resolution

To resolve the issues, follow these steps in the given order. After you complete each step, check whether the issue persists.

Step 1: Run the diagnostic for Microsoft Purview Message Encryption

Follow these steps to run the diagnostic:

  1. Select the following button to open the diagnostic in the Microsoft 365 admin center.

  2. SelectRun Tests.

If you ran the diagnostic but its findings didn't help resolve your issue, go to Step 2.

Step 2: Verify the Microsoft 365 subscription

To use Microsoft Purview Message Encryption, your organization must have a subscription that supports this feature. For information about the subscription requirements, see What subscriptions do I need to use Microsoft Purview Message Encryption.

Step 3: Verify the tenant configuration

  1. Use Exchange Online PowerShell to verify that your tenant is configured correctly for Microsoft Purview Message Encryption.

  2. Run the following cmdlet to check whether Information Rights Management (IRM) features are enabled in Outlook on the web:

    Get-OwaMailboxPolicy | FL *IRMEnabled*

    If the value of IRMEnabled is False, run the following cmdlet:

    Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -IRMEnabled $true
  3. If the Encrypt button is missing in Outlook on the web, run the following cmdlet:

    Set-IRMConfiguration -SimplifiedClientAccessEnabled $true

Step 4: Verify the affected users' account licenses

The affected users must make sure that the account that they use to sign in to Outlook or Outlook on the web is assigned the appropriate license to use the Microsoft Purview Message Encryption feature. If they can't determine this, users should follow these steps on their device:

  1. Sign out of Office.

  2. Remove cached credentials from Windows Credential Manager:

    1. Open Control Panel > User Accounts > Credential Manager.
    2. Select Windows Credentials.
    3. Remove all Outlook or Office credentials by expanding each credential and then selecting Remove.
  3. If the device isn't Microsoft Entra joined, remove the unlicensed account from the device:

    1. Select Start > Settings > Accounts > Access work or school.
    2. Select the account to be removed, and then select Disconnect.
  4. Sign in to Office by using a user account that's licensed to use the Microsoft Purview Message Encryption feature.

Step 5: Verify connection to the Azure Rights Management service

To determine whether the affected user's mail client can connect to the Azure Rights Management service, run the following PowerShell commands:

$request = [System.Net.HttpWebRequest]::Create("https://admin.na.aadrm.com/admin/admin.svc")$request.GetResponse()$request.ServicePoint.Certificate.Issuer

The output should show that the issuing Certificate Authority (CA) is a Microsoft CA. For example:

CN=Microsoft Secure Server CA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US.

If you see a CA that isn't from Microsoft, your secure client-to-service connection was probably terminated and has to be reconfigured on your firewall. For more information, see Firewalls and network infrastructure.

Step 6: Check for sensitivity labels

If sensitivity labels are applied to email messages, permissions must be assigned correctly so that recipients can access the messages. For more information, see Restrict access to content by using sensitivity labels.

If the issue persists after you complete all these steps, contact Microsoft Support for further troubleshooting.

More information

  • If users in your organization experience issues when they send encrypted messages to or receive encrypted messages from people outside your organization, check the Conditional Access policies and guest account configuration in both organizations. For more information, see External recipient can't open encrypted email, Microsoft Entra configuration for encrypted content, and Conditional Access policies for Azure Information Protection.
  • Users can open encrypted email messages that are sent to a shared mailbox. If the message is sent from the same organization, users can open it when they're signed in to a supported Outlook client. If the message is sent from an external organization, users must use Outlook on the web. For more information, see Message encryption FAQ.
Resolve Microsoft Purview Message Encryption issues - Microsoft 365 (2024)
Top Articles
What is Wealth Building & How to Get Started | FortuneBuilders
50 Inspirational Real Estate Investment Quotes To Keep You Motivated
Jack Doherty Lpsg
Riverrun Rv Park Middletown Photos
Www.politicser.com Pepperboy News
Grange Display Calculator
Santa Clara College Confidential
Academic Integrity
Encore Atlanta Cheer Competition
Meg 2: The Trench Showtimes Near Phoenix Theatres Laurel Park
City Of Spokane Code Enforcement
Daniela Antury Telegram
Ave Bradley, Global SVP of design and creative director at Kimpton Hotels & Restaurants | Hospitality Interiors
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
How to find cash from balance sheet?
Mani Pedi Walk Ins Near Me
Define Percosivism
Star Wars: Héros de la Galaxie - le guide des meilleurs personnages en 2024 - Le Blog Allo Paradise
Georgetown 10 Day Weather
St Clair County Mi Mugshots
What Time Does Walmart Auto Center Open
48 Oz Equals How Many Quarts
What Individuals Need to Know When Raising Money for a Charitable Cause
15 Primewire Alternatives for Viewing Free Streams (2024)
3569 Vineyard Ave NE, Grand Rapids, MI 49525 - MLS 24048144 - Coldwell Banker
Bj타리
Play It Again Sports Forsyth Photos
Our Leadership
Courtney Roberson Rob Dyrdek
Sf Bay Area Craigslist Com
Old Peterbilt For Sale Craigslist
Uhaul Park Merced
Jennifer Reimold Ex Husband Scott Porter
Synchrony Manage Account
Edict Of Force Poe
Craigslist Mount Pocono
Viewfinder Mangabuddy
Admissions - New York Conservatory for Dramatic Arts
Myql Loan Login
Elisabeth Shue breaks silence about her top-secret 'Cobra Kai' appearance
Bella Thorne Bikini Uncensored
Mvnt Merchant Services
Levothyroxine Ati Template
Keir Starmer looks to Italy on how to stop migrant boats
Reese Witherspoon Wiki
Walmart Front Door Wreaths
Smoke From Street Outlaws Net Worth
Makemkv Key April 2023
Ssss Steakhouse Menu
The Love Life Of Kelsey Asbille: A Comprehensive Guide To Her Relationships
Island Vibes Cafe Exeter Nh
Latest Posts
Article information

Author: Arline Emard IV

Last Updated:

Views: 6117

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Arline Emard IV

Birthday: 1996-07-10

Address: 8912 Hintz Shore, West Louie, AZ 69363-0747

Phone: +13454700762376

Job: Administration Technician

Hobby: Paintball, Horseback riding, Cycling, Running, Macrame, Playing musical instruments, Soapmaking

Introduction: My name is Arline Emard IV, I am a cheerful, gorgeous, colorful, joyous, excited, super, inquisitive person who loves writing and wants to share my knowledge and understanding with you.