First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Apply IRM Protection to Email
Security and Protection

Apply IRM Protection to Email — Secure Sensitive Messages

Apply IRM Protection to Email configures Information Rights Management (IRM) protection for your organization's email so that only authorized recipients can access and use protected content. IT Partner plans the protection rules with you, implements them with the tools built into Microsoft 365 today — Microsoft Purview Message Encryption, sensitivity labels, and Exchange Online mail flow rules — adds usage restrictions such as blocking copying or allowing printing, and verifies protected sending with your recipients. The service is $700 per project, runs 5 days, and is managed by Roman Sotnik.

Timeline 5 daysService owner Roman SotnikManaged Services

What this engagement is

Information Rights Management (IRM) lets your organization control who can access, forward, print, or copy sensitive email. In Microsoft 365 today this protection is delivered through Microsoft Purview: encryption and usage rights are applied with Microsoft Purview Message Encryption and sensitivity labels built into Outlook and the Microsoft 365 apps, and Exchange Online mail flow rules can apply protection automatically when a message matches defined conditions. Applying rights protection to email is useful when messages contain financial data, legal documents, or personal data; when teams collaborate on sensitive projects; when communicating with vendors, customers, or partners; or when email content is subject to regulatory requirements such as GDPR, HIPAA, or PCI-DSS.

Success criteria

01IRM protection is successfully applied to emails, and the information is protected from unauthorized access or disclosure.

What you receive

IRM rules and policies planned together with Client.
IRM rules deployed to apply protection manually and automatically and meet business governance and compliance needs each time a user creates a new message.
Rules created to search messages for specified conditions and apply IRM accordingly.
Recipients specified for access to the protected information.
Additional controls or restrictions added, such as allowing printing or blocking copying.
Testing and verification completed to confirm that the specified sender can send IRM-protected messages.
Compatibility checked for recipients’ email systems, including whether recipients have the necessary setup and permissions to view the protected content.
Guidance provided to the client that IRM-protected email should only be shared with authorized individuals who have been granted access.

How the work unfolds

Create IRM rules

Create rules that will search messages for specified conditions and apply IRM accordingly.

Specify authorized recipients

Specify the recipients who will have access to the protected information.

Add controls or restrictions

Add any additional controls or restrictions, such as allowing printing or blocking copying.

Test IRM-protected sending

Test and verify that the specified sender can send IRM-protected messages.

Communicate protection guidance

Communicate to the client that protected email content should only be shared with authorized individuals who have been granted access.

Prerequisites

Access to the Microsoft 365 tenant.
Sufficient administrative permissions for Exchange Online and the Microsoft Purview portal.
Microsoft 365 licensing that includes Microsoft Purview Message Encryption / rights management for the users in scope (included in plans such as Microsoft 365 E3/E5 and Microsoft 365 Business Premium).
Client collaboration with IT Partner to define the scope and requirements.

Who does what

IT Partner

  • Plan IRM rules and policies together with Client.
  • Deploy IRM rules to apply them manually and automatically and meet business governance and compliance needs each time a user creates a new message.
  • Check that the IRM protection is compatible with the recipients’ email systems and that they have the necessary setup and permissions to view the protected content.

Your team

  • Provide access to the tenant.
  • Provide sufficient permissions.
  • Collaborate with IT Partner to define the scope and requirements.

What's not included

Microsoft 365, Exchange Online, Microsoft Purview, or other licensing costs are not included.
Broad Microsoft Purview Information Protection strategy, sensitivity label taxonomy design, data classification program design, or organization-wide compliance policy design beyond the agreed IRM email scope is not included.
Data Loss Prevention, retention, eDiscovery, audit, insider risk, conditional access, or broader tenant security configuration is not included unless separately scoped.
Remediation or configuration of external recipients’ email platforms, devices, identities, or third-party systems is not included.
End-user training, change management campaigns, communications planning, and user adoption services are not included beyond basic service completion guidance unless separately scoped.
Legal, regulatory, or compliance advice, including interpretation of GDPR, HIPAA, PCI-DSS, or other regulatory obligations, is not included.
Ongoing managed monitoring, support, incident response, rule tuning after project closure, or help desk support for protected-message access issues is not included unless covered by a separate support agreement.
Custom development, custom integrations, scripting outside the agreed configuration scope, or application modernization to support IRM-protected content is not included.
Remediation of pre-existing tenant misconfiguration, mail flow issues, identity synchronization issues, or licensing gaps that prevent IRM from functioning is not included and may require separate work.

Frequently asked questions

What does the Apply IRM Protection to Email service do?

It configures Information Rights Management protection for your organization's email so that only authorized individuals can access and use protected information. In Microsoft 365 this protection is delivered through Microsoft Purview — message encryption, sensitivity labels, and rights management — with Exchange Online mail flow rules applying protection automatically where conditions match.

What is included in this IRM email protection service?

The service includes planning IRM rules and policies with the client, deploying rules that apply protection manually and automatically, creating rules that search messages for specified conditions, specifying authorized recipients, adding controls such as allowing printing or blocking copying, testing IRM-protected sending, checking recipient email system compatibility, and providing protection guidance to the client.

What kinds of email should be protected with IRM?

Emails containing sensitive or confidential information such as financial data, legal documents, personal data, or sensitive project communications; communications with external parties such as vendors, customers, or partners; and email content subject to compliance requirements such as GDPR, HIPAA, or PCI-DSS.

Can IRM protection be applied automatically to emails?

Yes. IT Partner deploys Exchange Online mail flow rules that apply protection automatically when a message matches specified conditions. The rules are planned with the client so they align with business governance and compliance needs.

Can users also apply IRM protection manually?

Yes. Users can apply protection themselves — for example with sensitivity labels or encryption options built into Outlook — alongside the automatic rules, according to the client's defined governance and business requirements.

What types of restrictions can be applied to IRM-protected emails?

Additional controls or restrictions can be applied to protected emails, such as allowing printing or blocking copying and forwarding. The specific controls are defined during planning with the client based on the organization's requirements.

Does this service support protecting emails sent to external recipients?

Yes. Rights-protected messages can be shared with external parties such as vendors, customers, and partners. Because external access depends on the recipients' email systems and permissions, the service includes compatibility checks and verification that recipients can open the protected content.

What prerequisites are required before the IRM email protection work can begin?

The client provides tenant access and sufficient administrative permissions, confirms Microsoft 365 licensing that includes Microsoft Purview Message Encryption / rights management for in-scope users (included in plans such as Microsoft 365 E3/E5 and Business Premium), and collaborates with IT Partner to define the scope, rules, recipients, and controls.

What are the IT Partner's responsibilities during the engagement?

IT Partner plans the IRM rules and policies with the client, deploys rules for manual and automatic protection, verifies that the specified sender can send IRM-protected messages, and checks that recipients have the setup and permissions needed to view protected content.

How long does the Apply IRM Protection to Email service take?

The service runs 5 days. The exact schedule depends on timely tenant access, sufficient permissions, scope confirmation, and client collaboration with IT Partner.

How is pricing determined for this IRM email protection service?

The service is $700 per project, quoted fixed-price in writing before work begins. Work outside the agreed IRM email protection scope is confirmed and priced separately with IT Partner.

What is not included in this IRM email protection service?

Licensing costs, broader Microsoft Purview or compliance program design, DLP or retention configuration, remediation of external recipients' systems, end-user training programs, legal or regulatory advice, ongoing managed support, custom development, and remediation of pre-existing tenant issues are not included unless separately scoped.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$700 per project
5 days
Book a meeting