Problem with Encrypted Emails in Classic Outlook: Microsoft Shares Temporary Solution

Problem with Encrypted Emails in Classic Outlook: Microsoft Shares Temporary Solution

Users of the classic Outlook version for Windows are currently unable to open encrypted emails from other organizations due to an error in Information Rights Management.

Users of the classic version of Outlook for Windows are currently unable to open OMEv2-encrypted emails originating from other organizations. The error is related to the configuration of Information Rights Management (IRM) and affects all Office channels. Microsoft is sharing a temporary solution for Outlook users.

Encrypted Email Error Message

When users receive an encrypted email from another organization, the message “Configure your computer for Information Rights Management” may appear. The error occurs with emails encrypted via Microsoft Purview, when the sender is in a different Microsoft 365 tenant.

Error message with encrypted emails. Source: Microsoft

Both the Outlook team and the Purview team at Microsoft are investigating the issue. There is no definitive solution available yet, but there are temporary measures that organizations can take to work around the problem.

Temporary Solutions

Microsoft proposes two temporary solutions. The simplest is to enable cross-tenant access and trust multi-factor authentication (MFA) claims from other Microsoft Entra tenants. This should be done in the Microsoft Entra admin center, under the default settings for incoming access. Organizations can indicate here that they trust MFA claims from external tenants.

Enabling cross-tenant access as a temporary solution. Source: Microsoft

The second option is to exclude external users from certain requirements within conditional access. However, this approach requires more customization and does not guarantee that all communication will run smoothly.

Importantly, the temporary solution only affects emails that an organization sends itself. In order to also correctly receive encrypted emails from other organizations, those sending parties must also make the same adjustment to their Entra configuration.