First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Apply IRM Protection to Email
Security and Protection

Apply IRM Protection to Email — Secure Sensitive Messages

This service helps the client apply Information Rights Management (IRM) protection to email so that only authorized individuals can access and use protected information. It is intended for organizations that need to protect sensitive, confidential, project-related, external-party, or regulated information from unauthorized access or disclosure.

Timeline 5 daysService owner Roman SotnikManaged Services

What this engagement is

Information Rights Management (IRM) lets the creator of a document or email control who can access, modify, and share the content. Applying IRM protection to email is useful when messages contain sensitive or confidential information, such as financial data, legal documents, or personal data; when teams collaborate on sensitive projects; when communicating with external parties such as vendors, customers, or partners; or when email content is subject to regulatory compliance requirements such as GDPR, HIPAA, or PCI-DSS.

Success criteria

01IRM protection is successfully applied to emails, and the information is protected from unauthorized access or disclosure.

What you receive

IRM rules and policies planned together with Client.
IRM rules deployed to apply protection manually and automatically and meet business governance and compliance needs each time a user creates a new message.
Rules created to search messages for specified conditions and apply IRM accordingly.
Recipients specified for access to the protected information.
Additional controls or restrictions added, such as allowing printing or blocking copying.
Testing and verification completed to confirm that the specified sender can send IRM-protected messages.
Compatibility checked for recipients’ email systems, including whether recipients have the necessary setup and permissions to view the protected content.
Client communication completed that the email service description is protected by IRM and should only be shared with authorized individuals who have been granted access.

How the work unfolds

Create IRM rules

Create rules that will search messages for specified conditions and apply IRM accordingly.

Specify authorized recipients

Specify the recipients who will have access to the protected information.

Add controls or restrictions

Add any additional controls or restrictions, such as allowing printing or blocking copying.

Test IRM-protected sending

Test and verify that the specified sender can send IRM-protected messages.

Communicate protection guidance

Communicate to the client that the email service description is protected by IRM and that they should only share it with authorized individuals who have been granted access.

Prerequisites

Access to the tenant.
Sufficient permissions.
Client collaboration with IT Partner to define the scope and requirements.

Who does what

IT Partner

  • Plan IRM rules and policies together with Client.
  • Deploy IRM rules to apply them manually and automatically and meet business governance and compliance needs each time a user creates a new message.
  • Check that the IRM protection is compatible with the recipients’ email systems and that they have the necessary setup and permissions to view the protected content.

Your team

  • Provide access to the tenant.
  • Provide sufficient permissions.
  • Collaborate with IT Partner to define the scope and requirements.

What's not included

Microsoft 365, Exchange Online, Microsoft Purview, Azure Information Protection, or other licensing costs are not included.
Broad Microsoft Purview Information Protection strategy, sensitivity label taxonomy design, data classification program design, or organization-wide compliance policy design beyond the agreed IRM email scope is not included.
Data Loss Prevention, retention, eDiscovery, audit, insider risk, conditional access, or broader tenant security configuration is not included unless separately scoped.
Remediation or configuration of external recipients’ email platforms, devices, identities, or third-party systems is not included.
End-user training, change management campaigns, communications planning, and user adoption services are not included beyond basic service completion guidance unless separately scoped.
Legal, regulatory, or compliance advice, including interpretation of GDPR, HIPAA, PCI-DSS, or other regulatory obligations, is not included.
Ongoing managed monitoring, support, incident response, rule tuning after project closure, or help desk support for protected-message access issues is not included unless covered by a separate support agreement.
Custom development, custom integrations, scripting outside the agreed configuration scope, or application modernization to support IRM-protected content is not included.
Remediation of pre-existing tenant misconfiguration, mail flow issues, identity synchronization issues, or licensing gaps that prevent IRM from functioning is not included and may require separate work.

Frequently asked questions

What does the Apply IRM Protection to Email service do?

The Apply IRM Protection to Email service helps an organization apply Information Rights Management protection to email so that only authorized individuals can access and use protected information. It is intended for email that contains sensitive, confidential, project-related, external-party, or regulated information that needs protection from unauthorized access or disclosure.

What is included in this IRM email protection service?

This service includes planning IRM rules and policies with the client, deploying rules that apply protection manually and automatically, and creating rules that search messages for specified conditions. It also includes specifying authorized recipients, adding controls such as allowing printing or blocking copying, testing IRM-protected sending, checking recipient email system compatibility, and communicating protection guidance to the client.

What kinds of email should be protected with IRM?

IRM protection is useful for emails containing sensitive or confidential information, such as financial data, legal documents, personal data, or sensitive project communications. It is also relevant when communicating with external parties such as vendors, customers, or partners, or when email content is subject to compliance requirements such as GDPR, HIPAA, or PCI-DSS.

Can IRM protection be applied automatically to emails?

Yes, the service includes deploying IRM rules that can apply protection automatically based on specified message conditions. The rules are planned with the client so they align with business governance and compliance needs each time a user creates a new message.

Can users also apply IRM protection manually?

Yes, the service includes deploying IRM rules to support both manual and automatic application of protection. This allows protection to be used according to the client’s defined governance and business requirements.

What types of restrictions can be applied to IRM-protected emails?

The service can include additional controls or restrictions for protected emails, such as allowing printing or blocking copying. The specific controls are defined during planning with the client based on the organization’s requirements.

Who can access IRM-protected emails after this service is completed?

Only recipients who have been specified and granted access to the protected information are intended to access IRM-protected emails. The service includes defining authorized recipients and checking whether recipients have the necessary setup and permissions to view protected content.

Does this service support protecting emails sent to external recipients?

Yes, the service is relevant for communications with external parties such as vendors, customers, and partners. Because external access depends on the recipients’ email systems, setup, and permissions, the service includes compatibility checks for recipients’ email systems.

What prerequisites are required before the IRM email protection work can begin?

The client must provide access to the tenant and sufficient permissions for the IT Partner to perform the work. The client also needs to collaborate with the IT Partner to define the scope and requirements for IRM rules, policies, recipients, and controls.

What are the client’s responsibilities during the engagement?

The client is responsible for providing tenant access, granting sufficient permissions, and collaborating with the IT Partner to define the scope and requirements. This collaboration is important because IRM rules, authorized recipients, and restrictions must reflect the client’s business governance and compliance needs.

What are the IT Partner’s responsibilities during the engagement?

The IT Partner plans IRM rules and policies with the client, deploys rules to apply protection manually and automatically, and creates rules that apply IRM based on specified message conditions. The IT Partner also checks compatibility with recipients’ email systems and verifies that recipients have the necessary setup and permissions to view protected content.

What happens during the implementation of IRM protection for email?

The implementation typically includes creating IRM rules, specifying authorized recipients, adding controls or restrictions, testing IRM-protected sending, and communicating protection guidance. The service also verifies that the specified sender can send IRM-protected messages and that recipient compatibility has been checked.

Will applying IRM protection to email cause downtime?

The service description does not specify any planned downtime. Because the engagement focuses on configuring rules, permissions, controls, and testing IRM-protected sending, any expected user impact or change window should be confirmed with the IT Partner before implementation.

How long does the Apply IRM Protection to Email service take?

The exact schedule may still depend on timely tenant access, sufficient permissions, scope confirmation, and client collaboration with IT Partner.

How is pricing determined for this IRM email protection service?

Any work outside the agreed IRM email protection scope should be confirmed separately with IT Partner.

What is the success criterion for this service?

The success criterion is that IRM protection is successfully applied to emails and the information is protected from unauthorized access or disclosure. The service also includes testing and verification to confirm that the specified sender can send IRM-protected messages.

What is not included in this IRM email protection service?

This service does not include licensing costs, broader Microsoft Purview or compliance program design, DLP or retention configuration, remediation of external recipients’ systems, end-user training programs, legal or regulatory advice, ongoing managed support, custom development, or remediation of pre-existing tenant issues unless separately scoped.

What happens after the IRM email protection configuration is completed?

After completion, the configured IRM rules and policies are in place to protect applicable emails, authorized recipients are defined, and testing has verified that the specified sender can send protected messages. The client is also informed that protected email content should only be shared with authorized individuals who have been granted access.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$700 per project
5 days
Book a meeting