First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft partner since 2006 1,100+ organizations under management
Home/Blog/How to open a Microsoft Purview encrypted email …

How to open a Microsoft Purview encrypted email from Gmail or another external email account

2026-06-16·IT PartnerMicrosoft 365Cloud Securitymodern security

Received a secure email from a Microsoft 365 user but you use Gmail, Yahoo, iCloud, or another non-Microsoft mailbox? In most cases, you can open it by signing in with a supported account or by requesting a one-time passcode. Here is the current 2026 recipient experience and what to do if something does not work.

What a Microsoft 365 encrypted email is

Microsoft 365 organizations can protect email with Microsoft Purview Message Encryption, sensitivity labels, and permissions such as Encrypt-Only or Do Not Forward. Instead of receiving a normal unprotected message, an external recipient may receive a notification that says the sender has sent a protected message, with a link such as Read the message or Open message.

Depending on the sender's configuration, your identity, and your email client, you may be able to read the message directly in a supported client or you may be taken to Microsoft's secure message portal in a browser. The encrypted content is protected by Microsoft 365 controls, and access is granted only after you prove that you own or can sign in to the recipient address.

Before you start

Use the same mailbox that received the encrypted message. Do not forward the notification to another address and expect it to work; permissions are normally tied to the original recipient.

You will need a current web browser, access to your mailbox, and the ability to receive a verification email if you choose the one-time passcode option. If your organization uses strict link filtering, browser isolation, or quarantine tools, you may need your IT team to allow Microsoft's protected message links.

Open the encrypted message with a Google account or Gmail

  1. Open the notification email in Gmail.
  2. Select Read the message or Open message.
  3. If prompted, choose the sign-in option for Google, or choose to use a one-time passcode if Google sign-in is not available in your experience.
  4. If you sign in with Google, complete the normal Google authentication prompts. If you use a passcode, keep the message portal page open.
  5. Check the same Gmail inbox for a passcode email from Microsoft. If you do not see it, check Spam, Promotions, quarantine, or any mail security digest your organization uses.
  6. Copy the passcode into the Microsoft message portal before it expires.
  7. After verification, the encrypted email opens in the browser. If the sender allowed encrypted replies, you can reply from the secure portal.

Open the message with Outlook.com, a Microsoft account, or a work or school account

If the encrypted email was sent to an Outlook.com, Hotmail, Live, or Microsoft account address, you may be prompted to sign in with that Microsoft account. If the message was sent to a business or school mailbox, you may be prompted to sign in with your organization's Microsoft Entra ID account.

After you authenticate, Microsoft checks whether that signed-in identity matches the recipient. If it does, the protected message opens. If you are signed in with the wrong account, sign out, open a private or InPrivate browser window, and try again with the account that received the message.

Open the message with Yahoo, iCloud, ISP mail, or another provider

For many third-party mailboxes, the most common option is a one-time passcode.

  1. Open the encrypted message notification.
  2. Select Read the message or Open message.
  3. Choose Sign in with a one-time passcode if prompted.
  4. Leave the browser tab open.
  5. Return to the recipient mailbox and find the passcode email from Microsoft.
  6. Enter the passcode in the message portal.
  7. Read the secure message in the browser.

Passcodes are time-limited. If the code expires, request a new one from the portal. Use the newest code if you requested more than one.

What you may and may not be able to do

The sender's protection settings control what actions are allowed. With Encrypt-Only, you can typically read the message and reply securely, but the exact experience depends on the sender's tenant settings. With Do Not Forward or a restrictive sensitivity label, forwarding may be blocked, and copying, printing, or downloading attachments may be limited.

If you cannot forward, print, download, or copy content, that is usually intentional and not a browser problem. Ask the sender to adjust the permissions only if there is a legitimate business need.

Troubleshooting common problems

Passcode not received: Confirm you are checking the same address that received the encrypted email. Look in Junk, Spam, Clutter, Promotions, quarantine, and security gateway digests. If your company filters automated mail, ask IT to check whether the passcode email was blocked.

Passcode expired or does not work: Request a new code and use the latest email. Avoid copying extra spaces before or after the code.

Link opens but shows an error: Try a current version of Microsoft Edge, Chrome, Safari, or Firefox. Disable aggressive script blockers for the Microsoft portal, or use a private browsing window to avoid cached sign-in conflicts.

Wrong account signed in: Sign out of other Microsoft, Google, or work accounts in the browser, or use an InPrivate/private window and sign in as the original recipient.

Message appears unavailable: The sender may have revoked access, the message may have expired based on policy, or the recipient address may not match the account you used. Contact the sender.

Problems on mobile: Use the latest Outlook, Gmail, or browser app. If the link loops between apps, copy the open-message link and paste it into a mobile browser, or try from a desktop browser.

Forwarding does not work: Protected messages are normally intended for named recipients. Ask the sender to resend the message to the additional recipient instead of forwarding it.

Security and phishing guidance

Encrypted-message notifications are sometimes imitated by phishing campaigns. Before opening a link, confirm that you expected the message, check the sender, and be cautious with urgent requests for payment, password changes, or document access. The sign-in or passcode page should be a legitimate Microsoft page, and you should never enter your Microsoft 365, Google, or company password into a suspicious site.

If anything looks unusual, contact the sender through a known phone number or separate trusted channel. For business users, report suspicious messages to your IT or security team.

Admin note for Microsoft 365 organizations

The recipient experience depends on Microsoft 365 configuration, licensing, and policy design. Administrators can use Microsoft Purview sensitivity labels, Exchange Online mail flow rules, data loss prevention policies, and encryption templates to apply protection automatically or let users select it in Outlook.

In current Microsoft cloud environments, identity and access are handled through Microsoft Entra ID. Licensing varies by plan and add-on; for example, Microsoft 365 Business Premium includes many security and compliance capabilities suitable for small and midsize businesses, while larger or more regulated environments may require additional Microsoft Purview licensing. If you buy Microsoft cloud subscriptions through the Cloud Solution Provider program, commercial licensing is generally transacted under the New Commerce Experience, so confirm the exact subscription and add-on requirements before rollout.

Key takeaways

  • External recipients can usually open Microsoft Purview encrypted email by signing in with a supported account or by using a one-time passcode.
  • Use the same email address that received the protected message; forwarding the notification often will not grant access to someone else.
  • Passcodes expire, so request a new code if needed and use the most recent one.
  • Restrictions such as Do Not Forward, blocked printing, or limited downloads are controlled by the sender's Microsoft 365 protection policy.
  • Admins should review Microsoft Purview, Exchange Online, Microsoft Entra ID, sensitivity labels, and licensing before deploying encryption at scale.

Need help configuring secure email for your organization? IT Partner can help design and deploy Microsoft Purview Message Encryption, sensitivity labels, Exchange Online mail flow rules, and Microsoft 365 security policies so employees can protect sensitive information without slowing down business communication.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.