Microsoft 365 Encrypted Email (OME) Implementation
Microsoft 365 Encrypted Email (OME) Implementation enables Microsoft Purview Message Encryption — the current Microsoft service that replaced Office 365 Message Encryption (OME) — in your Microsoft 365 tenant. IT Partner validates tenant readiness, configures the encryption capabilities, creates the Exchange Online mail flow rules that define the conditions for encryption, and verifies that internal and external recipients can read and reply to protected messages. The service is $525 per project, is delivered in about 3 hours of scheduled implementation work, and is managed by Mike Mackey.
What this engagement is
Microsoft 365 uses encryption in two ways: encryption in the service, which is on by default, and encryption as a customer control. This service implements the customer-control layer for email: Microsoft Purview Message Encryption, the successor to Office 365 Message Encryption (OME), which uses the rights-management protection in Microsoft Purview so your organization can share protected email with anyone, on any device. Users can send and receive protected messages with other Microsoft 365 organizations and with recipients on Outlook.com, Gmail, and other email services. The objective is to enable Microsoft Purview Message Encryption in your Microsoft 365 tenant and provide the instruments to control sensitive data with flexible policies or ad hoc customer controls built into Microsoft 365. The expected result is working message encryption with Exchange Online mail flow rules that define the conditions for encryption; your recipients can receive and reply to secure emails on any device, with any email client, without installing client software.
Success criteria
What you receive
How the work unfolds
Confirm business objectives, encryption scenarios, tenant access, licensing assumptions, test users, external recipient test addresses, and acceptance criteria for the OME implementation.
Validate Microsoft 365 and Exchange Online readiness, including admin access, licensed users, accepted domains, existing mail flow rules, connectors, transport configuration, and relevant protection settings needed for OME.
Enable or validate the required Microsoft Purview Message Encryption capabilities and related Microsoft 365 protection services. Configure the agreed encryption behavior, tenant-level settings, and basic supporting options needed for the approved use case.
Create the agreed Exchange Online mail flow rules that apply encryption based on approved conditions. Review rule priority and avoid conflicts with existing rules where practical.
Test encrypted message delivery and access using agreed internal and external test recipients. Confirm that messages matching the configured rules are encrypted, that recipients can open and reply to protected messages, and that the tested scenarios meet the acceptance criteria.
Review results with the client point of contact, provide a summary of configured rules and validation evidence, identify any outstanding items or recommended follow-up work, and complete the Project Closeout Report.
Prerequisites
Who does what
IT Partner
- Set up Microsoft Purview Message Encryption in Microsoft 365
- Create mail flow rules that define the conditions for encryption
- Bring your own key (BYOK) settings, if needed
Your team
- Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules, if needed
- Configure all networking equipment, such as load balancers, routers, firewalls, and switches
- If Microsoft Outlook or other desktop email clients are to be used for connectivity to Microsoft 365, tuning email software on client workstations
What's not included
Limitations & technical notes
Frequently asked questions
What is Microsoft 365 Encrypted Email (OME) Implementation?
It is a fixed-scope IT Partner implementation service that enables Microsoft Purview Message Encryption — the current Microsoft service that replaced Office 365 Message Encryption (OME) — in your Microsoft 365 tenant and configures the Exchange Online mail flow rules that define the conditions for encryption. The service is $525 per project.
What is included in this Microsoft 365 encrypted email setup service?
The service includes enabling and validating Microsoft Purview Message Encryption in Microsoft 365, creating mail flow rules that define the conditions for encryption, configuring customer-managed key (BYOK) settings if needed, verifying email encryption with internal and external test recipients, and providing a Project Closeout Report with final status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget.
How long does the encrypted email implementation take?
The implementation is delivered in about 3 hours of scheduled work. It follows a defined plan: kickoff, a pre-implementation system health check, configuration of the message encryption capabilities, Exchange Online mail flow rule setup, encryption verification, and closeout.
What is Microsoft Purview Message Encryption, and what happened to OME?
Microsoft Purview Message Encryption is the current Microsoft 365 email encryption service; it replaced Office 365 Message Encryption (OME), which Microsoft deprecated. It uses the rights-management protection in Microsoft Purview, so users can send and receive protected messages with other Microsoft 365 organizations and with recipients using Outlook.com, Gmail, and other email services.
Can encrypted messages be sent to external recipients?
Yes. Users can send and receive protected messages with other Microsoft 365 organizations as well as with recipients on Outlook.com, Gmail, and other email services. Recipients can read and reply to protected messages on any device without installing client software.
How are emails encrypted after setup?
IT Partner creates Exchange Online mail flow rules that define the conditions for encryption. Messages that meet the configured conditions — for example, a keyword, a sensitive-content match, or a specific recipient domain — are automatically protected according to those rules. Users can also apply encryption ad hoc where the agreed configuration allows it.
What licenses are required for Microsoft Purview Message Encryption?
Microsoft Purview Message Encryption is included in plans such as Office 365 E3 and E5, Microsoft 365 E3 and E5, Microsoft 365 Business Premium, Office 365 A1, A3, and A5, and Office 365 G3 and G5; some other plans can add the capability through Microsoft Purview add-on licensing. Each user protected by message encryption must be licensed — confirm entitlements against Microsoft's current Exchange Online service description.
What access does IT Partner need to perform the setup?
Global Administrator or equivalent delegated administrative access to your Microsoft 365 tenant, with Exchange Online licenses in place for in-scope users. The exact access model is confirmed with IT Partner before work begins.
What are the client's responsibilities during the engagement?
The client provides a dedicated point of contact and coordinates outside vendor resources and schedules if needed. The client is also responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, and for tuning email software on client workstations if Microsoft Outlook or other desktop email clients are used for connectivity to Microsoft 365.
Is mail migration, Active Directory, or Group Policy work included?
No. Mail migration services to Microsoft 365 and AD and Group Policy settings are outside the scope of this project and would be additional cost items if needed.
Will this service cause downtime or interrupt email delivery?
No planned downtime is required — the work configures Microsoft Purview Message Encryption and Exchange Online mail flow rules alongside normal mail flow. Rule conditions are reviewed against existing transport rules, and encryption behavior is verified with test recipients before closeout.
What happens at the end of the engagement?
IT Partner reviews the results with your point of contact, summarizes the configured rules and validation evidence, and provides a Project Closeout Report indicating final project status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget. More extensive documentation can be provided for an additional fee.