First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Encrypted Email (OME) Implementation
Implementation

Microsoft 365 Encrypted Email (OME) Implementation

Microsoft 365 Encrypted Email (OME) Implementation is a 1-day implementation service for organizations that want to enable Microsoft 365 Message Encryption in their Microsoft 365 tenant and use built-in customer controls to protect sensitive email with policies or ad hoc controls. IT Partner sets up Office Message Encryption (OME), creates mail flow rules that define the conditions for encryption, and configures Bring Your Own Key (BYOK) settings if needed. Service details: SKU ITPWW280IMPOT; price $450; duration 1 day; manager Mike Mackey.

Timeline 1 dayService owner Mike MackeyOffice 365microsoft 365

What this engagement is

Published date: 2018-08-06. Products: Office 365, microsoft 365. Type: Implementation. Microsoft 365 uses encryption in two ways: encryption in the service, which is used in Microsoft 365 by default, and encryption as a customer control. This service is for customers who want to increase the security level of messaging and protect extremely sensitive data by implementing email encryption and rights protection capabilities. With the Microsoft 365 Message Encryption (OME) capabilities, which leverage the protection features in Azure Information Protection, your organization can share protected email with anyone, on any device. Users can send and receive protected messages with other Microsoft 365 organizations as well as non-Microsoft 365 customers using Outlook.com, Gmail, and other email services. The objective is to enable OME -- Microsoft 365 Message Encryption -- in your Microsoft 365 tenant and provide instruments to control sensitive data with flexible policies or ad hoc customer controls that are built into Microsoft 365. The expected result is the ability to use Microsoft 365 Message Encryption (OME) capabilities that protect your mails and mail flow rules that define the conditions for encryption. Your email recipients should be able to receive and reply to your secure emails using any device, with any email client.

Success criteria

01start to send encrypted email from any device
02easily navigate through encrypted messages
03deliver encrypted email directly to recipients' inboxes
04decrypt and read encrypted email with confidence, without installing client software
05enjoy simplified user management that eliminates the need for certificate maintenance

What you receive

Office Message Encryption (OME) set up in Microsoft 365
Mail flow rules that define the conditions for encryption
Bring your own key (BYOK) settings if needed
OME and additional tools configured
Exchange Online Transport Rules set up
Email encryption verified
Project Closeout Report indicating final project status, including evidence of meeting acceptance criteria, outstanding issues, if any, and final budget

How the work unfolds

Kickoff meeting

Confirm business objectives, encryption scenarios, tenant access, licensing assumptions, test users, external recipient test addresses, and acceptance criteria for the OME implementation.

Pre-implementation system health check

Validate Microsoft 365 and Exchange Online readiness, including admin access, licensed users, accepted domains, existing mail flow rules, connectors, transport configuration, and relevant protection settings needed for OME.

Configuring OME and additional tools

Enable or validate the required Microsoft 365 Message Encryption capabilities and related Microsoft 365 protection services. Configure the agreed encryption behavior, tenant-level settings, and basic supporting options needed for the approved use case.

Setting up Exchange Online Transport Rules

Create the agreed Exchange Online mail flow rules that apply encryption based on approved conditions. Review rule priority and avoid conflicts with existing rules where practical.

Verifying email encryption

Test encrypted message delivery and access using agreed internal and external test recipients. Confirm that messages matching the configured rules are encrypted, that recipients can open and reply to protected messages, and that the tested scenarios meet the acceptance criteria.

Posting implementation tasks

Review results with the client point of contact, provide a summary of configured rules and validation evidence, identify any outstanding items or recommended follow-up work, and complete the Project Closeout Report.

Prerequisites

You must have global admin level access to the source Microsoft 365 tenant
You must have global admin level access to the destination Microsoft 365 tenant, with Exchange Online licenses available
To use the new OME capabilities, you need one of the following plans:
Microsoft 365 Message Encryption is offered as part of Office 365 E3 and E5, Microsoft E3 and E5, Office 365 A1, A3, and A5, and Office 365 G3 and G5. Customers do not need additional licenses to receive the new protection capabilities powered by Azure Information Protection
You can also add Azure Information Protection Plan 1 to the following plans to receive the new Microsoft 365 Message Encryption capabilities: Exchange Online Plan 1, Exchange Online Plan 2, Microsoft 365 F1, Microsoft 365 Business Basic, Microsoft 365 Business Standard, or Office 365 Enterprise E1
Each user benefiting from Microsoft 365 Message Encryption needs to be licensed to be covered by the feature
For the full list, see the Exchange Online service descriptions for Microsoft 365 Message Encryption: https://docs.microsoft.com/en-us/office365/servicedescriptions/exchange-online-service-description/exchange-online-service-description

Who does what

IT Partner

  • Set up Office Message Encryption (OME) in Microsoft 365
  • Create mail flow rules that define the conditions for encryption
  • Bring your own key (BYOK) settings, if needed

Your team

  • Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules, if needed
  • Configure all networking equipment, such as load balancers, routers, firewalls, and switches
  • If Microsoft Outlook or other desktop email clients are to be used for connectivity to Microsoft 365, tuning email software on client workstations

What's not included

Mail migration services to Microsoft 365
AD & group policy settings

Limitations & technical notes

!Plan may vary depending on your needs.
!The published $450, 1-day fixed-scope offer should be treated as an OME-focused implementation aligned to the stated plan and results. Complex BYOK requirements, broader information protection design, mail migration, Active Directory changes, or group policy work should be confirmed separately and may require separate scoping.
!The source prerequisites reference both source and destination Microsoft 365 tenants. Confirm the exact tenant access model for the customer environment before scheduling implementation.
!If Microsoft Outlook or other desktop email clients are used for connectivity to Microsoft 365, client workstation email software tuning is a client responsibility under the stated scope.
!If you want more extensive documentation than the Project Closeout Report, it can be provided for an additional fee.
!Relevant articles listed in the source: Microsoft 365 Message Encryption FAQ: https://support.office.com/en-us/article/office-365-message-encryption-faq-0432dce9-d9b6-4e73-8a13-4a932eb0081e; Microsoft 365 Message Encryption: https://products.office.com/en-us/exchange/office-365-message-encryption; Email encryption in Microsoft 365: https://support.office.com/en-us/article/email-encryption-in-office-365-c0d87cbe-6d65-4c03-88ad-5216ea5564e8

Frequently asked questions

What is Microsoft 365 Encrypted Email (OME) Implementation?

Microsoft 365 Encrypted Email (OME) Implementation is a 1-day IT Partner implementation service that enables Microsoft 365 Message Encryption in your Microsoft 365 tenant and configures mail flow rules that define the conditions for encryption.

What is included in this Microsoft 365 encrypted email setup service?

The service includes setting up Office Message Encryption (OME) in Microsoft 365, creating mail flow rules that define the conditions for encryption, configuring BYOK settings if needed, verifying email encryption, and providing a Project Closeout Report. The closeout report indicates final project status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget.

How much does the Microsoft 365 Encrypted Email (OME) Implementation service cost?

The listed price for the Microsoft 365 Encrypted Email (OME) Implementation service is $450. The service is associated with SKU ITPWW280IMPOT and is listed as a 1-day engagement, but the plan may vary depending on your needs.

How long does the encrypted email implementation take?

The stated duration for this service is 1 day. The implementation plan includes a kickoff meeting, a pre-implementation system health check, configuring OME and additional tools, setting up Exchange Online Transport Rules, verifying email encryption, and posting implementation tasks.

What is Microsoft 365 Message Encryption (OME)?

Microsoft 365 Message Encryption, or OME, provides Microsoft 365 message protection capabilities that leverage Azure Information Protection. It allows users to send and receive protected messages with other Microsoft 365 organizations and with non-Microsoft 365 recipients using Outlook.com, Gmail, and other email services.

Can encrypted messages be sent to external recipients?

Yes. The source states that users can send and receive protected messages with other Microsoft 365 organizations as well as non-Microsoft 365 customers using Outlook.com, Gmail, and other email services.

Do recipients need to install special software to read encrypted email?

One of the stated success criteria is that recipients can decrypt and read encrypted email with confidence without installing client software.

Can users send encrypted email from any device?

Yes. One of the service success criteria is the ability to start sending encrypted email from any device. The expected result is that recipients should be able to receive and reply to secure emails using any device, with any email client.

How are emails encrypted after setup?

IT Partner creates mail flow rules, also known as Exchange Online Transport Rules, that define the conditions for encryption. Messages that meet the configured conditions are handled according to those encryption rules.

Can encryption be controlled with policies or ad hoc controls?

Yes. The stated objective is to enable OME in the Microsoft 365 tenant and provide instruments to control sensitive data with flexible policies or ad hoc customer controls that are built into Microsoft 365.

What licenses are required for Microsoft 365 Message Encryption?

Microsoft 365 Message Encryption is offered as part of Office 365 E3 and E5, Microsoft E3 and E5, Office 365 A1, A3, and A5, and Office 365 G3 and G5. Azure Information Protection Plan 1 can also be added to Exchange Online Plan 1, Exchange Online Plan 2, Microsoft 365 F1, Microsoft 365 Business Basic, Microsoft 365 Business Standard, or Office 365 Enterprise E1 to receive the new Microsoft 365 Message Encryption capabilities. Each user benefiting from Microsoft 365 Message Encryption needs to be licensed.

What access does IT Partner need to perform the setup?

The prerequisites state that global admin level access is required to the source Microsoft 365 tenant and to the destination Microsoft 365 tenant, with Exchange Online licenses available. Because this is an OME implementation service, the exact tenant access model should be confirmed with IT Partner before work begins.

What are the client's responsibilities during the engagement?

The client must provide a dedicated point of contact responsible for working with IT Partner and coordinating outside vendor resources and schedules if needed. The client is also responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, and for tuning email software on client workstations if Microsoft Outlook or other desktop email clients are used for connectivity to Microsoft 365.

What is IT Partner responsible for in this service?

IT Partner is responsible for setting up Office Message Encryption (OME) in Microsoft 365, creating mail flow rules that define the conditions for encryption, and configuring Bring Your Own Key (BYOK) settings if needed.

Is mail migration to Microsoft 365 included?

No. Mail migration services to Microsoft 365 are explicitly outside the scope of this project and would be an additional cost item.

Are Active Directory and Group Policy settings included?

No. AD and group policy settings are explicitly listed as outside the scope of this project and would be additional cost items if needed.

Will this service cause downtime or interrupt email delivery?

The source does not specify a planned downtime window or a downtime guarantee. Because the work focuses on configuring Microsoft 365 Message Encryption and Exchange Online mail flow rules, business impact should be discussed during kickoff and verified during testing.

Does this service include extensive documentation?

The included documentation is a Project Closeout Report indicating final project status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget. More extensive documentation can be provided for an additional fee.

What happens at the end of the engagement?

Upon completion, IT Partner provides a Project Closeout Report. This document indicates final project status, including evidence of meeting acceptance criteria, outstanding issues if any, and final budget.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with