Send Encrypted Email Outlook Web App – S/MIME (Secure/Multipurpose Internet Mail Interface) is a widely accepted standard for sending digitally signed and encrypted messages. For more information, see S/MIME for signed subscriptions and encryption in Exchange Online.

To use S/MIME in Outlook for iOS and Android, you must configure the S/MIME requirements in Exchange Online. After you complete these steps, you can send an S/MIME document to Outlook for iOS and Android using the following:

To properly configure S/MIME in Exchange Online, follow the steps outlined in Configure S/MIME in Exchange Online. Specifically, this includes:

In manual and automated certificate deployment solutions, it is assumed that the root certificate of the chain of custody exists and can be found in your Exchange Online holding the virtual certificate domain. Trusted authentication is done on all digital documents. Online Exchange validates certificates by validating each certificate in the certificate chain until it reaches the trusted root certificate. This verification is done by obtaining an intermediate certificate from the right data entry in the certificate, until a trusted root certificate is located. Intermediate certificates can also include digitally signed emails. If Exchange Online finds a trusted root certificate and can request a certificate revocation for the certificate authority, the digital certificate chain is considered valid and valid for the digital certificate. If Exchange Online does not find a trusted root certificate or cannot reach a certificate revocation authority for the certificate, that certificate is considered invalid and untrusted.

Outlook iOS and Android leverages the primary ESMTP user’s email address to send messages, which is configured in the account profile. The S/MIME certificate used by Outlook for iOS and Android is calculated by comparing the user’s primary ESMTP email address in the account profile with the certificate value or domain defined at other costs; If these do not match, Outlook for iOS and Android will report that the certificate is not available (see Figure 7) and will not allow the user to sign in and/or send emails.

Outlook iOS and Outlook for Android support certificate delivery, which is when the certificate is emailed to the user and the user taps on the certification link in the app to start the certificate installation. The image below shows how emailing a document works on iOS.

A user can send their files and documents to themselves using Outlook. For more information, see Digital export certificate.

With Endpoint Manager, organizations can submit encrypted certificates from any Certification Authority. The Endpoint Manager will send credentials to all devices that will automatically be sent to the user registry. Commonly, the Simple Certificate Enrollment Protocol (SCEP) is used to sign the certificate. With SCEP, a private key is generated and stored on a written device and a unique certificate is sent to each user’s device address that can be identified for non-repudiation. Finally, Endpoint Manager supports authentication of clients that require NIST 800-157 certification. The Company Portal is used for signing documents and encryption through Intune.

Use the following steps to create and configure an Outlook for iOS S/MIME policy in Endpoint Manager. These settings provide for the delivery of signature certification and encryption.

Use the following steps to create and configure Outlook for iOS and Android S/MIME accounts in Endpoint Manager. These settings provide for the delivery of signature certification and encryption.

End users need to manually set S/MIME binding in their account settings, Security Settings, and control S/MIME Settings, which is by default. The following are the Outlook for iOS S/MIME security settings:

When the S/MIME setting is enabled, Outlook for iOS and Android automatically disable the Organize by Phone setting. This is because S/MIME encryption is becoming more difficult as social networks grow. By removing the chat thread, Outlook for iOS and Android reduces time problems with e-mails to recipients through signature and encryption. When this level is set, this change affects all aspects of the app. This dialog box is rendered in iOS as follows:

Once S/MIME is enabled and S/MIME certificates are installed, users can see the installed certificates by accessing their account settings and hitting Security. Additionally, users can click into each S/MIME certificate and view individual certificates, including information such as key usage and expiration date.

Outlook users can sign up or configure access to messages. This allows users to save time sending emails while having confidence in their signed/encrypted emails.

Outlook iOS and Android support access to public user authentication keys via LDAP secure endpoints in the client solution. To use the LDAP domain, follow these rules:

When Outlook iOS and Android allows document recipient search, the app will first look at the local machine, then search Azure Active Directory, and then evaluate each term of the LDAP directory. When Outlook for iOS and Android connects to the LDAP directory in order to find the recipient’s public certificate, certificate validation is performed to ensure that the certificate is not revoked. The certificate is only considered valid by the app if the certificate validation is complete.

After the certificate has been sent and S/MIME is in the app, users can consume related S/MIME and write content using the S/MIME certificate. If the S/MIME setting is not enabled, users will not be able to consume S/MIME content.

In the comments, users can view messages that are S/MIME signed or encrypted. In addition, users can tap S/MIME status to see more information about S/MIME status. The screenshots below show examples of how S/MIME messages are consumed on Android.

To read an encrypted message, the recipient’s certificate key must be present on the device.

Users can install a public certificate sender by hitting the S/MIME status key bar. The certificate will be installed on the user’s device, specifically in the Microsoft publisher keychain on iOS or the KeyStore system on Android. The Android version looks like the following:

If the certificate is invalid, Outlook for iOS and Android will prompt the user. The user can tap on the S/MIME status bar notification to see more about the certificate error, as in the example below.

Before a user can send a signature and/or password, Outlook for iOS and Android performs a validity check via a certificate to ensure that the subscriber’s encryption function is valid. If the certificate expires, Outlook for iOS and Android will prompt the user to receive a new certificate when the user tries to sign in for messages or access, starting 30 days before expiration.

When composing a message in Outlook for iOS and Android, the Sender can choose to sign the message and/or unsubscribe the message. By clicking on the ellipses and then signing in and entering, various S/MIME options are presented. Selecting the S/MIME option results in a link to the email address as soon as the message is saved or sent, assuming the sender has a valid certificate.

IOS and Android apps can send S/MIME signed messages and access distributed groups. Outlook calculates iOS and MAS credentials for specific users in distribution groups, including those located in distribution groups, but care must be taken to limit nested distribution groups to minimize the impact of compromise.

Outlook iOS and Android check all recipients before sending encrypted messages and confirm that the public certificate is valid for each recipient. The global address index (GAL) is checked first; If the recipient’s certificate is not in the GAL, Outlook asks the Microsoft keychain editor on iOS or the KeyStore system on Android to find the recipient’s certificate key. For recipients without a public certificate key (or an incorrect key), Outlook will ask them to delete it. Messages without encryption will not be sent to the recipient unless the encryption option is disabled by the sender in the mix. Every day your business exchanges effective information with customers, suppliers and partners. Much of this communication happens through email and Outlook and is built into your office applications.

But most of the survey is more confidential data or information captured is simply too large to send by email. So what should I do?

There are many ways to solve this problem but our advice is that you already have the tools!

In this video I will show you how easy it is to exchange encrypted email and large files from Outlook.

Our staff can now exchange sensitive patient information and larger files faster and cheaper. Therefore, we also strictly observe data protection regulations. Our hospitality IT infrastructure is well prepared for future thanks.

