Built on Azure Rights Management, it encrypts mail sent to people both within and beyond the organisation. Senders can pick Do Not Forward or Encrypt-Only, organisations can brand messages, and supported Outlook clients show them in-line; legacy OME, now deprecated, gave way to it.
Also called formerly Office 365 Message Encryption, OME, Office 365 Message Encryption.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Purview Message Encryption in context, with comparison tables and the common traps.
Terms in this definition
- Azure Rights Management
The service that does the actual encrypting behind sensitivity labels, message encryption and DKE in Purview Information Protection, attaching usage rights to protected content. Newer tenants get it switched on automatically; older ones turn it on with PowerShell.
- Do Not Forward
Applies usage rights to an email so the people it is sent to cannot print, copy or pass it on. Users, DLP and mail flow rules can all apply it, and strictly speaking it is not a template.
- Encrypt-Only
Called simply Encrypt in Outlook, this protects an email and makes recipients sign in, yet still lets them print, copy and forward it. They receive every usage right apart from Save As, Export and Full Control, so the protection cannot be taken off.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
Related terms
- Microsoft Purview Advanced Message Encryption
An add-on that extends Microsoft Purview Message Encryption for mail read by external recipients in the encrypted message portal. It brings revocation, expiry dates, several branding templates and logs of portal activity.
- One-time passcode
If a recipient lacks a work, school or social account, Microsoft Purview Message Encryption can email them a code to open the encrypted message portal instead. Admins switch this off through Set-OMEConfiguration's -OTPEnabled parameter.
- Set-OMEConfiguration
Changes the branding template for Microsoft Purview Message Encryption from Exchange Online PowerShell: its logo and wording, whether recipients can sign in with a social ID, and one-time passcode use.
- Wrapper message
Recipients not on Outlook, Gmail users for example, get this email from Microsoft Purview Message Encryption. It links to the encrypted message portal, where signing in reveals the message.
See Microsoft Purview Message Encryption in the full glossary