Microsoft 365 Encrypted Email (OME) Implementation
Microsoft 365 Encrypted Email (OME) Implementation is a 1-day implementation service for organizations that want to enable Microsoft 365 Message Encryption in their Microsoft 365 tenant and use built-in customer controls to protect sensitive email with policies or ad hoc controls. IT Partner sets up Office Message Encryption (OME), creates mail flow rules that define the conditions for encryption, and configures Bring Your Own Key (BYOK) settings if needed. Service details: SKU ITPWW280IMPOT; price $450; duration 1 day; manager Mike Mackey.
What this engagement is
Published date: 2018-08-06. Products: Office 365, microsoft 365. Type: Implementation. Microsoft 365 uses encryption in two ways: encryption in the service, which is used in Microsoft 365 by default, and encryption as a customer control. This service is for customers who want to increase the security level of messaging and protect extremely sensitive data by implementing email encryption and rights protection capabilities. With the Microsoft 365 Message Encryption (OME) capabilities, which leverage the protection features in Azure Information Protection, your organization can share protected email with anyone, on any device. Users can send and receive protected messages with other Microsoft 365 organizations as well as non-Microsoft 365 customers using Outlook.com, Gmail, and other email services. The objective is to enable OME -- Microsoft 365 Message Encryption -- in your Microsoft 365 tenant and provide instruments to control sensitive data with flexible policies or ad hoc customer controls that are built into Microsoft 365. The expected result is the ability to use Microsoft 365 Message Encryption (OME) capabilities that protect your mails and mail flow rules that define the conditions for encryption. Your email recipients should be able to receive and reply to your secure emails using any device, with any email client.
Success criteria
What you receive
How the work unfolds
Confirm business objectives, encryption scenarios, tenant access, licensing assumptions, test users, external recipient test addresses, and acceptance criteria for the OME implementation.
Validate Microsoft 365 and Exchange Online readiness, including admin access, licensed users, accepted domains, existing mail flow rules, connectors, transport configuration, and relevant protection settings needed for OME.
Enable or validate the required Microsoft 365 Message Encryption capabilities and related Microsoft 365 protection services. Configure the agreed encryption behavior, tenant-level settings, and basic supporting options needed for the approved use case.
Create the agreed Exchange Online mail flow rules that apply encryption based on approved conditions. Review rule priority and avoid conflicts with existing rules where practical.
Test encrypted message delivery and access using agreed internal and external test recipients. Confirm that messages matching the configured rules are encrypted, that recipients can open and reply to protected messages, and that the tested scenarios meet the acceptance criteria.
Review results with the client point of contact, provide a summary of configured rules and validation evidence, identify any outstanding items or recommended follow-up work, and complete the Project Closeout Report.
Prerequisites
Who does what
IT Partner
- Set up Office Message Encryption (OME) in Microsoft 365
- Create mail flow rules that define the conditions for encryption
- Bring your own key (BYOK) settings, if needed
Your team
- Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules, if needed
- Configure all networking equipment, such as load balancers, routers, firewalls, and switches
- If Microsoft Outlook or other desktop email clients are to be used for connectivity to Microsoft 365, tuning email software on client workstations
What's not included
Limitations & technical notes
Frequently asked questions
What is Microsoft 365 Encrypted Email (OME) Implementation?
Microsoft 365 Encrypted Email (OME) Implementation is a 1-day IT Partner implementation service that enables Microsoft 365 Message Encryption in your Microsoft 365 tenant and configures mail flow rules that define the conditions for encryption.
What is included in this Microsoft 365 encrypted email setup service?
The service includes setting up Office Message Encryption (OME) in Microsoft 365, creating mail flow rules that define the conditions for encryption, configuring BYOK settings if needed, verifying email encryption, and providing a Project Closeout Report. The closeout report indicates final project status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget.
How much does the Microsoft 365 Encrypted Email (OME) Implementation service cost?
The listed price for the Microsoft 365 Encrypted Email (OME) Implementation service is $450. The service is associated with SKU ITPWW280IMPOT and is listed as a 1-day engagement, but the plan may vary depending on your needs.
How long does the encrypted email implementation take?
The stated duration for this service is 1 day. The implementation plan includes a kickoff meeting, a pre-implementation system health check, configuring OME and additional tools, setting up Exchange Online Transport Rules, verifying email encryption, and posting implementation tasks.
What is Microsoft 365 Message Encryption (OME)?
Microsoft 365 Message Encryption, or OME, provides Microsoft 365 message protection capabilities that leverage Azure Information Protection. It allows users to send and receive protected messages with other Microsoft 365 organizations and with non-Microsoft 365 recipients using Outlook.com, Gmail, and other email services.
Can encrypted messages be sent to external recipients?
Yes. The source states that users can send and receive protected messages with other Microsoft 365 organizations as well as non-Microsoft 365 customers using Outlook.com, Gmail, and other email services.
Do recipients need to install special software to read encrypted email?
One of the stated success criteria is that recipients can decrypt and read encrypted email with confidence without installing client software.
Can users send encrypted email from any device?
Yes. One of the service success criteria is the ability to start sending encrypted email from any device. The expected result is that recipients should be able to receive and reply to secure emails using any device, with any email client.
How are emails encrypted after setup?
IT Partner creates mail flow rules, also known as Exchange Online Transport Rules, that define the conditions for encryption. Messages that meet the configured conditions are handled according to those encryption rules.
Can encryption be controlled with policies or ad hoc controls?
Yes. The stated objective is to enable OME in the Microsoft 365 tenant and provide instruments to control sensitive data with flexible policies or ad hoc customer controls that are built into Microsoft 365.
What licenses are required for Microsoft 365 Message Encryption?
Microsoft 365 Message Encryption is offered as part of Office 365 E3 and E5, Microsoft E3 and E5, Office 365 A1, A3, and A5, and Office 365 G3 and G5. Azure Information Protection Plan 1 can also be added to Exchange Online Plan 1, Exchange Online Plan 2, Microsoft 365 F1, Microsoft 365 Business Basic, Microsoft 365 Business Standard, or Office 365 Enterprise E1 to receive the new Microsoft 365 Message Encryption capabilities. Each user benefiting from Microsoft 365 Message Encryption needs to be licensed.
What access does IT Partner need to perform the setup?
The prerequisites state that global admin level access is required to the source Microsoft 365 tenant and to the destination Microsoft 365 tenant, with Exchange Online licenses available. Because this is an OME implementation service, the exact tenant access model should be confirmed with IT Partner before work begins.
What are the client's responsibilities during the engagement?
The client must provide a dedicated point of contact responsible for working with IT Partner and coordinating outside vendor resources and schedules if needed. The client is also responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, and for tuning email software on client workstations if Microsoft Outlook or other desktop email clients are used for connectivity to Microsoft 365.
What is IT Partner responsible for in this service?
IT Partner is responsible for setting up Office Message Encryption (OME) in Microsoft 365, creating mail flow rules that define the conditions for encryption, and configuring Bring Your Own Key (BYOK) settings if needed.
Is mail migration to Microsoft 365 included?
No. Mail migration services to Microsoft 365 are explicitly outside the scope of this project and would be an additional cost item.
Are Active Directory and Group Policy settings included?
No. AD and group policy settings are explicitly listed as outside the scope of this project and would be additional cost items if needed.
Will this service cause downtime or interrupt email delivery?
The source does not specify a planned downtime window or a downtime guarantee. Because the work focuses on configuring Microsoft 365 Message Encryption and Exchange Online mail flow rules, business impact should be discussed during kickoff and verified during testing.
Does this service include extensive documentation?
The included documentation is a Project Closeout Report indicating final project status, evidence of meeting acceptance criteria, outstanding issues if any, and final budget. More extensive documentation can be provided for an additional fee.
What happens at the end of the engagement?
Upon completion, IT Partner provides a Project Closeout Report. This document indicates final project status, including evidence of meeting acceptance criteria, outstanding issues if any, and final budget.