Microsoft Encryption for Outgoing Emails
Microsoft 365 provides the ability to encrypt the outgoing emails using Microsoft 365 Email Encryption. Encryption can be applied automatically for emails detected as sensitive by the DLP engine.
The Microsoft 365 Email Encryption is available only for the outgoing emails.
For more information about the Microsoft 365 encryption mechanism, see the Microsoft Documentation.
Required License for Encrypting Outgoing Emails
In Monitor only mode, you can use the existing license of Office 365 as the minimum requirement. However, if you want to use Microsoft Encryption as an action in policy, you must have license with Office 365 Message Encryption (OME) capabilities. For more details, see Microsoft plans with OME capabilities and Microsoft Documentation.
Encrypting Outgoing Emails
To encrypt emails using Microsoft, you must create a transport rule. To configure it, contact Check Point Support. Once the transport rule is configured, select the required DLP workflow that has encryption (Email is allowed. Encrypted by Microsoft or Email is blocked and user can resend as encrypted by Microsoft). Based on the workflow defined, the emails are encrypted automatically.
Outgoing Emails via Microsoft - Footprint
All outgoing emails that have data leak will be sent with a header:
-
Microsoft Encryption: X-CLOUD-SEC-AV-Encrypt-Microsoft: True
If you enable this Microsoft workflow for the first time, a new mail flow rule is added to Microsoft called Check Point - Encryption. See Check Point - Encryption.