Share via

Encrypted email issue from shared mailbox.

Sanjay Bhakuni 25 Reputation points
2026-04-16T17:31:59.5633333+00:00

We have a scenario where a user is sending an email from a shared mailbox using “Send As” permission. The email is encrypted with the “Do Not Forward” protection level and sent to a distribution list (DL).

The issue is that some users are able to open the email without any problems, while others are unable to open it and receive an error indicating that it is an encrypted email. All members of the DL are internal user mailboxes.

What could be the possible reason for this behavior?

Microsoft Security | Microsoft Purview
0 comments No comments

2 answers

Sort by: Most helpful
  1. Sanjay Bhakuni 25 Reputation points
    2026-04-17T08:29:15.18+00:00

    Hello @Smaran Thoomu , I’d like to clarify the scenario to avoid any confusion.

    We are sending emails from a shared mailbox using Send As permission to a Distribution List (DL). The emails are successfully delivered to the DL members, who are regular user mailboxes. In this case, there is no requirement for those users to have any permission (such as delegate access) on the shared mailbox just to receive the email.

    The earlier reference to delegate access applies only when a user needs to access or open the shared mailbox itself, not when they are simply recipients of an email sent from it.

    Given this, the current behavior does not appear to require any additional permissions on the shared mailbox for DL members. If there are any inconsistencies or unexpected behavior observed beyond this, we can review those separately.
    Please let me know if you’d still recommend raising a Microsoft support ticket to confirm whether this scenario is fully supported,

    Was this answer helpful?


  2. Smaran Thoomu 35,045 Reputation points Microsoft External Staff Moderator
    2026-04-16T19:44:22.3933333+00:00

    Hey Sanjay, it sounds like you’re sending a “Do Not Forward”–protected message from a shared mailbox to a DL and only some DL members can open it. Here are the most common reasons for that behavior:

    1. Client support for delegated decryption
      • Only Outlook on the web, Outlook for Mac, Outlook for iOS/Android support opening “Do Not Forward”–protected mail in a shared mailbox via delegated access.
      • Outlook for Windows does not support delegated decryption of protected content. If the users who can’t open are on Outlook Windows, that’s likely the culprit.
    2. Permissions on the shared mailbox
      • Recipients must have FullAccess on the shared mailbox or be part of a mail-enabled security group assigned full access.
      • If your DL is a standard distribution group (not mail-enabled security) or users weren’t individually granted FullAccess via Add-MailboxPermission, they won’t be able to decrypt.
    3. Mailbox and licensing requirements
      • Every recipient needs an Exchange Online mailbox and an Azure Information Protection/OME license.
      • If a user has no personal mailbox (e.g., only an external contact or unlicensed account), they can’t complete decryption.

    What to try next:

    • Have one of the affected users open the same encrypted DL message in Outlook on the web.

    • Verify that each user has FullAccess (or is in a mail-enabled security group) on the shared mailbox.

    • Confirm all recipients have an Azure Information Protection/OME license assigned.

    Follow-up questions:

    1. Which Outlook clients (and versions) are the users who can’t open the message using?
    2. How did you grant permissions on the shared mailbox (FullAccess vs. security group)?
    3. Do these users all have an Exchange Online mailbox and an OME/AIP license?

    Hope that helps! Let us know what you find.

    Reference list

    1. Fix Microsoft Purview Message Encryption issues https://learn.microsoft.com/troubleshoot/microsoft-365/office-message-encryption/fix-message-encryption-issue-microsoft-purview
    2. Message encryption FAQ (shared mailbox section) https://learn.microsoft.com/purview/ome-faq#can-i-open-encrypted-messages-sent-to-a-shared-mailbox
    3. Troubleshoot delegated mailbox permissions in a hybrid deployment https://learn.microsoft.com/exchange/hybrid-deployment/set-up-delegated-mailbox-permissions

    Note: This content was drafted with the help of an AI system. Please verify the information before relying on it for decision-making.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.