Apply IRM Protection to Email — Secure Sensitive Messages
Apply IRM Protection to Email configures Information Rights Management (IRM) protection for your organization's email so that only authorized recipients can access and use protected content. IT Partner plans the protection rules with you, implements them with the tools built into Microsoft 365 today — Microsoft Purview Message Encryption, sensitivity labels, and Exchange Online mail flow rules — adds usage restrictions such as blocking copying or allowing printing, and verifies protected sending with your recipients. The service is $700 per project, runs 5 days, and is managed by Roman Sotnik.
What this engagement is
Information Rights Management (IRM) lets your organization control who can access, forward, print, or copy sensitive email. In Microsoft 365 today this protection is delivered through Microsoft Purview: encryption and usage rights are applied with Microsoft Purview Message Encryption and sensitivity labels built into Outlook and the Microsoft 365 apps, and Exchange Online mail flow rules can apply protection automatically when a message matches defined conditions. Applying rights protection to email is useful when messages contain financial data, legal documents, or personal data; when teams collaborate on sensitive projects; when communicating with vendors, customers, or partners; or when email content is subject to regulatory requirements such as GDPR, HIPAA, or PCI-DSS.
Success criteria
What you receive
How the work unfolds
Create rules that will search messages for specified conditions and apply IRM accordingly.
Specify the recipients who will have access to the protected information.
Add any additional controls or restrictions, such as allowing printing or blocking copying.
Test and verify that the specified sender can send IRM-protected messages.
Communicate to the client that protected email content should only be shared with authorized individuals who have been granted access.
Prerequisites
Who does what
IT Partner
- Plan IRM rules and policies together with Client.
- Deploy IRM rules to apply them manually and automatically and meet business governance and compliance needs each time a user creates a new message.
- Check that the IRM protection is compatible with the recipients’ email systems and that they have the necessary setup and permissions to view the protected content.
Your team
- Provide access to the tenant.
- Provide sufficient permissions.
- Collaborate with IT Partner to define the scope and requirements.
What's not included
Frequently asked questions
What does the Apply IRM Protection to Email service do?
It configures Information Rights Management protection for your organization's email so that only authorized individuals can access and use protected information. In Microsoft 365 this protection is delivered through Microsoft Purview — message encryption, sensitivity labels, and rights management — with Exchange Online mail flow rules applying protection automatically where conditions match.
What is included in this IRM email protection service?
The service includes planning IRM rules and policies with the client, deploying rules that apply protection manually and automatically, creating rules that search messages for specified conditions, specifying authorized recipients, adding controls such as allowing printing or blocking copying, testing IRM-protected sending, checking recipient email system compatibility, and providing protection guidance to the client.
What kinds of email should be protected with IRM?
Emails containing sensitive or confidential information such as financial data, legal documents, personal data, or sensitive project communications; communications with external parties such as vendors, customers, or partners; and email content subject to compliance requirements such as GDPR, HIPAA, or PCI-DSS.
Can IRM protection be applied automatically to emails?
Yes. IT Partner deploys Exchange Online mail flow rules that apply protection automatically when a message matches specified conditions. The rules are planned with the client so they align with business governance and compliance needs.
Can users also apply IRM protection manually?
Yes. Users can apply protection themselves — for example with sensitivity labels or encryption options built into Outlook — alongside the automatic rules, according to the client's defined governance and business requirements.
What types of restrictions can be applied to IRM-protected emails?
Additional controls or restrictions can be applied to protected emails, such as allowing printing or blocking copying and forwarding. The specific controls are defined during planning with the client based on the organization's requirements.
Does this service support protecting emails sent to external recipients?
Yes. Rights-protected messages can be shared with external parties such as vendors, customers, and partners. Because external access depends on the recipients' email systems and permissions, the service includes compatibility checks and verification that recipients can open the protected content.
What prerequisites are required before the IRM email protection work can begin?
The client provides tenant access and sufficient administrative permissions, confirms Microsoft 365 licensing that includes Microsoft Purview Message Encryption / rights management for in-scope users (included in plans such as Microsoft 365 E3/E5 and Business Premium), and collaborates with IT Partner to define the scope, rules, recipients, and controls.
What are the IT Partner's responsibilities during the engagement?
IT Partner plans the IRM rules and policies with the client, deploys rules for manual and automatic protection, verifies that the specified sender can send IRM-protected messages, and checks that recipients have the setup and permissions needed to view protected content.
How long does the Apply IRM Protection to Email service take?
The service runs 5 days. The exact schedule depends on timely tenant access, sufficient permissions, scope confirmation, and client collaboration with IT Partner.
How is pricing determined for this IRM email protection service?
The service is $700 per project, quoted fixed-price in writing before work begins. Work outside the agreed IRM email protection scope is confirmed and priced separately with IT Partner.
What is not included in this IRM email protection service?
Licensing costs, broader Microsoft Purview or compliance program design, DLP or retention configuration, remediation of external recipients' systems, end-user training programs, legal or regulatory advice, ongoing managed support, custom development, and remediation of pre-existing tenant issues are not included unless separately scoped.