Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Pillar name: Protect networks
Pattern name: Apply Layered Encryption for Sensitive Collaboration
Modern collaboration platforms like Microsoft Teams are central to enterprise productivity, handling sensitive communications across chats, calls, meetings, and shared content. While encryption is broadly implemented, inconsistent application and ungoverned use of end-to-end encryption (E2EE) introduces governance gaps, reduces visibility for security controls, and limits compliance capabilities.
This pattern outlines how Microsoft applies a layered encryption model that balances strong data protection with operational visibility, enabling organizations to secure collaboration workloads by default while selectively isolating high-sensitivity scenarios.
Context and problem
Enterprise collaboration platforms handle sensitive communications across chats, calls, meetings, and shared content. Teams applies standard encryption by default, but external or legacy communication segments require separate assessment. In particular, overuse of end-to-end encryption (E2EE) can reduce visibility, break compliance controls, and introduce governance gaps.
Challenges for using encryption on these platforms include:
Attackers exploiting weak or legacy communication paths (for example, public switched telephone networks (PSTN) or short message service (SMS) without encryption)
End-to-end encryption limits service-side inspection of protected audio, video, and video-based screen sharing in supported calls and meetings. E2EE doesn't cover chat messages or shared files.
Lack of centralized policy leading to inconsistent encryption usage across workloads
Lack of monitoring of E2EE usage, policy exceptions, and configuration changes can create governance blind spots and hinder compliance oversight.
These encryption challenges create security gaps in these widely-used collaboration platforms that can affect extensive parts of critical business systems.
Solution
Microsoft uses a layered encryption model that defaults to service-managed encryption and enables selective use of E2EE for high-sensitivity scenarios only. This model protects data within supported Teams services, but it doesn't extend Teams encryption guarantees to external or legacy communication segments. This model works by:
Encrypting data in transit by using Transport Layer Security (TLS) and Secure Real-Time Transport Protocol (SRTP) across client and service communications
Encrypting data at rest by using Microsoft-managed encryption controls for stored messages, files, recordings, and related collaboration data
Enforcing encryption by default for all Teams workloads, including chat, meetings, and calls
Centralizing identity enforcement by using Microsoft Entra ID with MFA and Conditional Access
Restricting privileged access through Microsoft service-operation controls, including Zero Standing Access and just-in-time privileged access, to limit persistent administrative permissions
Retaining service-side decryption for indexing, DLP, electronic evidence discovery (eDiscovery), and monitoring capabilities
Enabling E2EE only for approved, supported calls and meetings that require strict confidentiality with no service-side processing of protected media
Governing E2EE usage through tenant policies and role-based controls
Extending encryption ownership through Customer Key for customer-managed encryption at rest
E2EE is available for eligible one-to-one VoIP calls and supported meetings configured to require it, but not for PSTN calls. For supported communication types and feature limitations, see Encryption in Microsoft Teams.
Guidance
Adopt a default encryption model with policy-governed exceptions for E2EE, anchored in identity and compliance controls.
| Use case | Recommended action | Resource |
|---|---|---|
| Standard enterprise collaboration | Enforce default encryption Retain service-side processing Enable audit and monitoring |
Microsoft Teams Security Guide |
| High-sensitivity meetings or calls | Enable E2EE selectively Restrict to approved users Validate feature limitations |
Require end-to-end encryption for Teams meetings |
| Identity and access protection | Enforce MFA Apply Conditional Access Require compliant devices |
Zero Trust deployment with Microsoft 365 Plan a Microsoft Entra ID protection deployment |
| Data protection and compliance | Enable DLP and retention Apply sensitivity labels Govern collaboration workspaces |
Protect data with Microsoft Purview |
| Encryption key ownership | Deploy Customer Key Manage encryption keys Validate regulatory requirements |
Protect secrets best practices |
| E2EE policy configuration | Define policies in Teams admin center Control who can enable E2EE Validate client support |
End-to-end encryption for Teams |
Outcomes
Benefits
Protects Teams data in transit and at rest by default within supported services.
Maintains visibility for compliance, monitoring, and threat detection through service-managed encryption.
Enables secure handling of highly sensitive scenarios through controlled E2EE usage.
Reduces risk of unauthorized access through strong identity enforcement and least privilege access.
Aligns collaboration security with Zero Trust principles and regulatory requirements.
Trade-offs
E2EE makes recording, transcription, and related Microsoft 365 Copilot capabilities unavailable for protected calls and meetings. It prevents service-side inspection of protected media but doesn't extend to chat messages or shared files, and it doesn't disable their data loss prevention (DLP) policies.
Not all clients and platforms support E2EE, limiting interoperability.
Managing multiple encryption modes introduces operational complexity.
User experience can degrade due to missing collaboration features in E2EE sessions.
Governance requires coordination across security, compliance, and IT teams.
Key success factors
Successful implementation depends on consistent governance, identity enforcement, and monitoring. Focus on these success factors:
Organizational alignment on when collaboration workloads should use default encryption versus E2EE
Coverage of MFA and Conditional Access across all users
Percentage of collaboration data governed by DLP and retention policies
Reduction in unmanaged or inappropriate end-to-end encryption (E2EE) usage through centralized policy enforcement
Number of approved versus unapproved E2EE usage scenarios
Frequency of encryption policy audits and updates
Summary
Securing modern collaboration requires applying the right controls across identities, configurations, and communication pathways. A layered encryption approach that defaults to service-managed encryption and governs end-to-end encryption (E2EE) as an exception helps protect supported Teams communications. Standard encryption preserves service-side capabilities, while E2EE limits inspection of protected media. External and legacy communication segments require separate assessment and controls.
By integrating strong identity protection, enforcing centralized policies to reduce misconfigurations, and maintaining oversight of encrypted traffic, organizations can minimize risks from unauthorized access, phishing, and blind spots.