{"id":3272,"date":"2022-06-07T03:00:12","date_gmt":"2022-06-07T02:00:12","guid":{"rendered":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/"},"modified":"2022-06-07T03:00:12","modified_gmt":"2022-06-07T02:00:12","slug":"consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook","status":"publish","type":"post","link":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/","title":{"rendered":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook"},"content":{"rendered":"<div>\n<p>Microsoft 365 supports Information Rights Management (IRM) encryption and sensitivity labels with IRM encryption to provide permission control of sensitive content. While this supports most use cases, using encrypted content in delegation and shared mailbox scenarios has some inconsistencies across clients.<\/p>\n<p><font size=\"6\">Current behavior<\/font><\/p>\n<p><em><strong>Delegate access:<\/strong> <\/em>when delegates are granted <a href=\"https:\/\/docs.microsoft.com\/powershell\/module\/exchange\/add-mailboxpermission?view=exchange-ps\" target=\"_blank\" rel=\"noopener noreferrer\">FullAcccess<\/a> to the owner&#8217;s mailbox, their access to encrypted mail varies depending on the Outlook client they are using:<\/p>\n<ul>\n<li>Delegated access of encrypted mail is supported using Outlook on the web (OWA), Outlook for Mac, Outlook for iOS, Outlook for Android and Mail app on Windows<\/li>\n<li>Outlook for Windows client does not support delegate access of encrypted messages and delegates are blocked from reading encrypted messages if they are not on the recipient list (To, Cc or Bcc).<\/li>\n<\/ul>\n<p>Based on this behavior, users can simply access the encrypted message via OWA or one of the other clients delegates are not blocked.<\/p>\n<p><em><strong>Shared mailbox access:<\/strong> <\/em>for shared mailboxes, the challenge is slightly different. By design, users can open encrypted messages for a shared mailbox when they meet the following conditions:<\/p>\n<ul>\n<li>For Outlook for Windows, when the user is assigned &#8220;FullAccess&#8221; rights to the shared mailbox, and the AutoMapping parameter of <a href=\"https:\/\/docs.microsoft.com\/powershell\/module\/exchange\/add-mailboxpermission?view=exchange-ps\" target=\"_blank\" rel=\"noopener noreferrer\">Set-MailboxPermission<\/a> is set to $true.<\/li>\n<li>For other Outlook clients, when the user is assigned \u201cFullAccess\u201d rights to the shared mailbox.<\/li>\n<li>Known client limitations can be found <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/compliance\/ome-faq?view=o365-worldwide#can-i-open-encrypted-messages-sent-to-a-shared-mailbox-\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/li>\n<\/ul>\n<p>This means that once a user or group is granted &#8220;FullAccess&#8221; to a shared mailbox, they have access to all shared mailbox content from Outlook (OWA, iOS, Android, Mac, and Mail app on Windows). This is often unacceptable in scenarios where a shared mailbox contains encrypted content that is appropriate only for a subset of the users who have been granted &#8220;FullAccess.&#8221;<\/p>\n<p>For more information, see <a href=\"https:\/\/docs.microsoft.com\/exchange\/recipients-in-exchange-online\/manage-permissions-for-recipients\" target=\"_blank\" rel=\"noopener noreferrer\">Manage permissions for recipients in Exchange Online,<\/a> which tenant admins could use to limit delegate access to encrypted.<\/p>\n<p><font size=\"6\">New behavior: Mailbox Encrypted Message Access<\/font><\/p>\n<p>Based on customer feedback, we are introducing new Get\/Set\/Remove-MailboxIRMAcess cmdlets that provide admins with more granular access control of encrypted content, including in scenarios where delegates or shared mailbox members have FullAccess to the shared mailbox.<\/p>\n<p>Check who is blocked from accessing mailbox owner\u2019s encrypted messages:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-markdown\"><code>Get-MailboxIRMAccess -Identity &lt;MailboxIdParameter&gt; -User &lt;SecurityPrincipalIdParameter&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>Blocked a user from reading encrypted messages in a shared or delegated mailbox:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-markdown\"><code>Set-MailboxIRMAccess -Identity &lt;MalboxIdParameter&gt; -User &lt;SecurityPrincipalIdParameter&gt; -AccessLevel &lt;Block&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>Remove a user from the block list and allowing them to read encrypted mail:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-markdown\"><code>Remove-MailboxIRMAccess -Identity &lt;MalboxIdParameter&gt; -User &lt;SecurityPrincipalIdParameter&gt;<\/code><\/pre>\n<p>\u00a0<\/p>\n<p>After any of the above mailbox settings are changed, the Outlook client must be restarted.<\/p>\n<p><font size=\"5\">Parameter definitions:<\/font><\/p>\n<ul>\n<li>-Identity: The target mailbox. You can use any value that uniquely identifies the mailbox.<\/li>\n<li>-AccessLevel: Specifies what delegates can do with IRM-protected messages in the specified mailbox. Currently we only support \u201cBlock.\u201d<\/li>\n<li>-User: Specifies the delegate or shared mailbox member who is blocked from reading IRM-protected messages in the mailbox or shared mailbox. The user\u2019s login ID must be used.<\/li>\n<\/ul>\n<p><font size=\"5\">Let\u2019s cover some scenarios!<\/font><\/p>\n<p><strong>Scenario 1 \u2013 Delegate top secret conversation (total block)<\/strong><\/p>\n<p>Ashima is a VP of Finance at Contoso. Katie is Ashima\u2019s Administrative Assistant, who has full access to Ashima\u2019s inbox. Ashima has been involved in discussions to purchase another company with the CEO. This could have a high impact on the stock price if this information is leaked. Later, Ashima receives an email from the CEO that is only for the senior leadership team and protected by a Top-Secret label. Although Katie has access to Ashima\u2019s mailbox, she should not be able to see this email, as it\u2019s meant only for members of the senior leadership team.<\/p>\n<p>With the new behavior, the admin can use the following cmdlet to block Katie&#8217;s access to encrypted messages in Ashima&#8217;s mailbox while still allowing Katie full access to non-encrypted messages:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-markdown\"><code>Set-MailboxIRMAccess -Identity \"Ashima@contoso.com\" -User \"Katie@contoso.com\" -AccessLevel Block<\/code><\/pre>\n<p>\u00a0<\/p>\n<p><strong>Scenario 2: Shared mailbox select access to encrypted messages (only a subset of users can access encrypted content)<\/strong><\/p>\n<p>Contoso has a shared mailbox (CustomerData@contoso.com) that is used to receive encrypted emails containing customer data from the company\u2019s customer portal. Every day, several employees check the mailbox and route emails to the right departments or contacts. This mailbox also receives notifications or wrongly delivered emails. The admin wants to assign a few employees to clean up the mailbox but does not want them to be able to read encrypted messages sent from the company customer portal. To do this, the admin runs:<\/p>\n<p>\u00a0<\/p>\n<pre class=\"lia-code-sample language-markdown\"><code>Set-MailboxIRMAccess -Identity \"customerdata@contoso.com\" -User \"cleaner@contoso.com\u201d -Accesslevel Block<\/code><\/pre>\n<p>\u00a0<\/p>\n<p><font size=\"5\">Blocked user experience<\/font><\/p>\n<p>Once a delegate is blocked from viewing a mailbox owner\u2019s protected messages, the delegate will see the following when they try to open protected emails:<\/p>\n<p><span class=\"lia-inline-image-display-wrapper lia-image-align-center\" image-alt=\"EncrEmail01.jpg\" style=\"width: 400px;\"><img decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/377947iC3A60F87EC7894ED\/image-size\/medium?v=v2&amp;px=400\" role=\"button\" title=\"EncrEmail01.jpg\" alt=\"EncrEmail01.jpg\"><\/span><\/p>\n<p>If a shared mailbox member is blocked from viewing protected email in the mailbox, the user will see the following when they try to open protected emails:<\/p>\n<p><span class=\"lia-inline-image-display-wrapper lia-image-align-center\" image-alt=\"EncrEmail02.jpg\" style=\"width: 400px;\"><img decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/377948i2F84731342F09AE5\/image-size\/medium?v=v2&amp;px=400\" role=\"button\" title=\"EncrEmail02.jpg\" alt=\"EncrEmail02.jpg\"><\/span><\/p>\n<p><font size=\"6\">When will this feature be available?<\/font><\/p>\n<p>The new cmdlets are rolling out to tenants right now, and Outlook clients (OWA, Mac, iOS, Android, Mail app on Windows) will support the new setting by the end of June 2022.<\/p>\n<p><font size=\"5\">What about Outlook for Windows?<\/font><\/p>\n<p>The new block setting does not affect Outlook for Windows, which already has the ability to block access today, as described above.<\/p>\n<p>We hope you find the new behavior useful!<\/p>\n<p><span class=\"author\">The Outlook Team<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/consistently-block-delegates-or-shared-mailbox-members-from\/ba-p\/3473764\">Read full article (Microsoft Exchange Blog)<\/a><\/p>\n<p>All content and images belong to their respected owners, this article is curated for informational purposes only.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft 365 supports Information Rights Management (IRM) encryption and sensitivity labels with IRM encryption to provide permission control&hellip;\n","protected":false},"author":2,"featured_media":2564,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"csco_singular_sidebar":"","csco_page_header_type":"","csco_appearance_grid":"","csco_page_load_nextpost":"","csco_post_video_location":[],"csco_post_video_location_hash":"","csco_post_video_url":"","csco_post_video_bg_start_time":0,"csco_post_video_bg_end_time":0,"footnotes":""},"categories":[15],"tags":[426,66,701],"coauthors":[48],"class_list":["post-3272","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft-exchange-server","tag-information","tag-microsoft","tag-supports","cs-entry","cs-video-wrap"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Consistently block delegates or shared mailbox members from accessing protected messages in Outlook | Sebae Networks<\/title>\n<meta name=\"description\" content=\"View Consistently block delegates or shared mailbox members from accessing protected messages in Outlook for free, here at Sebae. Discover more great posts on our website.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook | Sebae Networks\" \/>\n<meta property=\"og:description\" content=\"View Consistently block delegates or shared mailbox members from accessing protected messages in Outlook for free, here at Sebae. Discover more great posts on our website.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/\" \/>\n<meta property=\"og:site_name\" content=\"Sebae Networks\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/sebaenetworks\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-07T02:00:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/377947iC3A60F87EC7894ED\/image-size\/medium?v=v2&amp;px=400\" \/>\n<meta name=\"author\" content=\"James Dean\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:site\" content=\"@sebaenetworks\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"James Dean\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook | Sebae Networks","description":"View Consistently block delegates or shared mailbox members from accessing protected messages in Outlook for free, here at Sebae. Discover more great posts on our website.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/","og_locale":"en_GB","og_type":"article","og_title":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook | Sebae Networks","og_description":"View Consistently block delegates or shared mailbox members from accessing protected messages in Outlook for free, here at Sebae. Discover more great posts on our website.","og_url":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/","og_site_name":"Sebae Networks","article_publisher":"https:\/\/www.facebook.com\/sebaenetworks","article_published_time":"2022-06-07T02:00:12+00:00","og_image":[{"url":"https:\/\/techcommunity.microsoft.com\/t5\/image\/serverpage\/image-id\/377947iC3A60F87EC7894ED\/image-size\/medium?v=v2&amp;px=400","type":"","width":"","height":""}],"author":"James Dean","twitter_card":"summary_large_image","twitter_creator":"@sebaenetworks","twitter_site":"@sebaenetworks","twitter_misc":{"Written by":"James Dean","Estimated reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#article","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/"},"author":{"name":"James Dean","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f"},"headline":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook","datePublished":"2022-06-07T02:00:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/"},"wordCount":884,"commentCount":0,"publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","keywords":["Information","Microsoft","supports"],"articleSection":["Microsoft Exchange Server"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/","url":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/","name":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook | Sebae Networks","isPartOf":{"@id":"https:\/\/www.sebae.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#primaryimage"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","datePublished":"2022-06-07T02:00:12+00:00","description":"View Consistently block delegates or shared mailbox members from accessing protected messages in Outlook for free, here at Sebae. Discover more great posts on our website.","breadcrumb":{"@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#primaryimage","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/11\/exchange-server-header.png","width":1920,"height":1080,"caption":"exchange server header"},{"@type":"BreadcrumbList","@id":"https:\/\/www.sebae.net\/blog\/consistently-block-delegates-or-shared-mailbox-members-from-accessing-protected-messages-in-outlook\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sebae.net\/blog\/"},{"@type":"ListItem","position":2,"name":"Consistently block delegates or shared mailbox members from accessing protected messages in Outlook"}]},{"@type":"WebSite","@id":"https:\/\/www.sebae.net\/blog\/#website","url":"https:\/\/www.sebae.net\/blog\/","name":"Sebae Networks","description":"Tech Tips, News, Tutorials &amp; Advice","publisher":{"@id":"https:\/\/www.sebae.net\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sebae.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.sebae.net\/blog\/#organization","name":"Sebae","url":"https:\/\/www.sebae.net\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2023\/06\/sebae-logo-icon.png","width":512,"height":512,"caption":"Sebae"},"image":{"@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/sebaenetworks","https:\/\/x.com\/sebaenetworks"]},{"@type":"Person","@id":"https:\/\/www.sebae.net\/blog\/#\/schema\/person\/6d07e05e3d3e4483117c4e2c3315a89f","name":"James Dean","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg72371c27260698ee55141397050ef40a","url":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","contentUrl":"https:\/\/www.sebae.net\/blog\/wp-content\/uploads\/2021\/10\/avatar_user_2_1634496168-96x96.jpg","caption":"James Dean"},"sameAs":["https:\/\/www.sebae.net"],"url":"https:\/\/www.sebae.net\/blog\/author\/jdean\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/3272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/comments?post=3272"}],"version-history":[{"count":0,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/posts\/3272\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media\/2564"}],"wp:attachment":[{"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/media?parent=3272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/categories?post=3272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/tags?post=3272"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sebae.net\/blog\/wp-json\/wp\/v2\/coauthors?post=3272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}