Encrypt Inbound and Outbound Emails Containing SIT

jpcapone 1,776 Reputation points
2023-07-15T13:33:50.09+00:00

I am looking to determine the best way to automatically encrypt inbound and outbound emails that contain ssn and cc numbers. I have created an auto labeling policy and only select the Exchange service but I am getting mixed results and none close to fulfilling the requirement. I would like to ensure that both emails containing text instances of the ssn and cc as well as attached documents with the same information triggers encryption for the specific inbound or outbound email message. Any assistance would be appreciated..

Exchange Online
Exchange Online
A Microsoft email and calendaring hosted service.
6,182 questions
Exchange | Exchange Server | Management
Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

Accepted answer
  1. Konstantinos Passadis 19,591 Reputation points MVP
    2023-07-15T14:09:37.6133333+00:00

    Hello @jpcapone !

    This is an action with planning and trial and error

    For your reference i suggest have a good look here :

    https://learn.microsoft.com/en-us/microsoft-365/compliance/ome-sensitive-info-types?view=o365-worldwide

    https://learn.microsoft.com/en-us/microsoft-365/compliance/ome-advanced-message-encryption?view=o365-worldwide

    https://learn.microsoft.com/en-us/microsoft-365/compliance/manage-office-365-message-encryption?view=o365-worldwide

    https://practical365.com/custom-sensitive-information-types/

    Work with Custom Sensitie Info types and when you are ready to Test give some time to the engine to make the config

    What i suggest is to create the Policy from Exchange Online :

    https://learn.microsoft.com/en-us/microsoft-365/compliance/ome-sensitive-info-types?view=o365-worldwide

    I hope this helps!

    Kindly mark the answer as Accepted and Upvote in case it helped!

    Regards


1 additional answer

Sort by: Most helpful
  1. Konstantinos Passadis 19,591 Reputation points MVP
    2023-07-15T14:42:52.6566667+00:00

    Hello @jpcapone !

    For Inbound Emails , it is true. Only the sender has this ability . Other solutions: you can make the Email delivered into a Shared Mailbox , apply encrytpion before forward it to the respective recipients .

    This of course has some work and i can only imagine that it could work if you have for example 1-2 specific domains/partners hat you would like to have encrypted inbound emails , It is quite a config to make it work for EVERY incoming mail! Also an External Gateway could do this for you, but we are getting out of scope , and looking into costs and budgets !

    Thank you for updating !

    Kindly mark the answer as Accepted and Upvote in case it helped!

    Regards

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.