I’m starting with Data classification and DLP in M365 - want to create some basic ones and got a bit confused… I would like to encrypt emails sent to outside of the organization… and looks like there are 3 ways to do it?<\/p>\n
\n
\n
Advertisement
LABEL - Create a “Label” that will be used to “Control Access” and allow “Add all users and groups in your organization”. This way if an email is sent outside, the external recipient will not able to read it. I will make the Label mandatory<\/p>\n<\/li>\n
\n
DLP - create a DLP policy with condition “Sender domain is” (add my domain) and action “Encrypt”.<\/p>\n<\/li>\n<\/ol>\n
3.Exchange TRASPORT RULE - with “Apply Office 365 Message Encryption…”<\/p>\n
Which one is recommended? \nAlso, wondering, what happens if I use option 1 and 2 together? :)… Just curious…<\/p>\n
This is a pretty basic I would say but cannot find some good explanation on when to use what/why<\/p>\n
Btw, I have M365 E3 and M365 E5 Security subscription.<\/p>","upvoteCount":2,"answerCount":15,"datePublished":"2024-05-05T20:44:02.124Z","author":{"@type":"Person","name":"mSumo","url":"https://community.spiceworks.com/u/mSumo"},"suggestedAnswer":[{"@type":"Answer","text":"
Hi experts,<\/p>\n
I’m starting with Data classification and DLP in M365 - want to create some basic ones and got a bit confused… I would like to encrypt emails sent to outside of the organization… and looks like there are 3 ways to do it?<\/p>\n
\n
\n
LABEL - Create a “Label” that will be used to “Control Access” and allow “Add all users and groups in your organization”. This way if an email is sent outside, the external recipient will not able to read it. I will make the Label mandatory<\/p>\n<\/li>\n
\n
DLP - create a DLP policy with condition “Sender domain is” (add my domain) and action “Encrypt”.<\/p>\n<\/li>\n<\/ol>\n
3.Exchange TRASPORT RULE - with “Apply Office 365 Message Encryption…”<\/p>\n
Which one is recommended? \nAlso, wondering, what happens if I use option 1 and 2 together? :)… Just curious…<\/p>\n
This is a pretty basic I would say but cannot find some good explanation on when to use what/why<\/p>\n
Btw, I have M365 E3 and M365 E5 Security subscription.<\/p>","upvoteCount":2,"datePublished":"2024-05-05T20:44:02.240Z","url":"https://community.spiceworks.com/t/encrypting-emails-sent-outside-the-company-m365/1071401/1","author":{"@type":"Person","name":"mSumo","url":"https://community.spiceworks.com/u/mSumo"}},{"@type":"Answer","text":"
For clarity, is your plan to encrypt ALL emails outside your tenancy or just defined ones?<\/p>","upvoteCount":0,"datePublished":"2024-05-05T20:57:59.230Z","url":"https://community.spiceworks.com/t/encrypting-emails-sent-outside-the-company-m365/1071401/2","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":"
Some context on each.<\/p>\n
Use sensitivity labels when you want fine-grained control over content protection, including encryption. It’s suitable for scenarios where you need different levels of protection (e.g., “Confidential,” “Internal Use Only,” etc.) based on the content.<\/p>\n
Use DLP policies when you want to enforce specific rules (e.g., prevent credit card numbers from being sent via email) and ensure compliance. While DLP can trigger encryption, it’s not the primary method for external email encryption.<\/p>\n
ETRs with OME are useful when you want a centralized approach to encrypting all external emails. It’s less granular than sensitivity labels but provides consistent encryption for outbound emails.<\/p>\n
You can use options 1 and 2 together, however, you may have conflicting rules. If you do this, test thoroughly.<\/p>\n
If you can give a little more details on the objective, if you mean all external emails or explicit ones, then this may help you decide which will be best for you.<\/p>","upvoteCount":1,"datePublished":"2024-05-05T21:03:16.451Z","url":"https://community.spiceworks.com/t/encrypting-emails-sent-outside-the-company-m365/1071401/3","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":"
Make sure you are aware of what the receiving user experience is going to be like if they are not an Office 365 user. Some people may see a message saying they have to sign in to read it and think it’s a phishing attack.<\/p>\n