An organization is concerned about data leakage from sensitive emails. They want to enforce encryption on emails containing financial information automatically. Which Microsoft 365 solution should they configure?
Trap 1: Data Loss Prevention (DLP) policies
Data Loss Prevention (DLP) policies are not primarily encryption tools; they are designed to detect, monitor, and block the transmission of sensitive data via policy rules. While DLP can integrate with encryption—for example, by applying a Rights Management–based action to encrypt emails—the DLP engine itself does not perform encryption. Thus, DLP alone would not meet the requirement to encrypt sensitive emails; it can only trigger such protection as part of a broader policy.
Trap 2: Microsoft Purview Information Protection (Microsoft Purview…
Microsoft Purview Information Protection (MIP) is centered on classifying and labeling documents and emails using sensitivity labels, which can include user-defined or automatic labeling. Although labels can be configured to apply encryption as an action, MIP is fundamentally a classification and governance framework, not a purpose-built email encryption solution. The encryption triggered by MIP policies is a separate action that requires additional configuration, whereas Microsoft Purview Message Encryption provides encryption directly through mail flow rules, making it the more precise answer for email encryption.
Trap 3: Exchange Online Protection (EOP)
Exchange Online Protection (EOP) is a cloud-based email filtering service that offers anti-malware, anti-spam, and some basic policy enforcement, but it does not include any native email encryption capability. EOP's role is to protect the email infrastructure from threats and to filter email traffic, not to apply encryption to messages. Therefore, relying on EOP alone would leave sensitive emails unencrypted, and it cannot fulfill the requirement to encrypt them.
- A
Data Loss Prevention (DLP) policies
Why wrong: Data Loss Prevention (DLP) policies are not primarily encryption tools; they are designed to detect, monitor, and block the transmission of sensitive data via policy rules. While DLP can integrate with encryption—for example, by applying a Rights Management–based action to encrypt emails—the DLP engine itself does not perform encryption. Thus, DLP alone would not meet the requirement to encrypt sensitive emails; it can only trigger such protection as part of a broader policy.
- B
Microsoft Purview Message Encryption
Microsoft Purview Message Encryption is the correct answer. It is a dedicated email encryption capability built on Azure Rights Management, allowing organizations to send and receive encrypted messages across domains. You can configure mail flow rules (transport rules) to automatically encrypt messages based on conditions such as the presence of sensitive content, specified users, or message classifications. This directly achieves the goal of encrypting sensitive emails, both in transit and at rest, and provides a secure access experience for recipients.
- C
Microsoft Purview Information Protection (Microsoft Purview Information Protection)
Why wrong: Microsoft Purview Information Protection (MIP) is centered on classifying and labeling documents and emails using sensitivity labels, which can include user-defined or automatic labeling. Although labels can be configured to apply encryption as an action, MIP is fundamentally a classification and governance framework, not a purpose-built email encryption solution. The encryption triggered by MIP policies is a separate action that requires additional configuration, whereas Microsoft Purview Message Encryption provides encryption directly through mail flow rules, making it the more precise answer for email encryption.
- D
Exchange Online Protection (EOP)
Why wrong: Exchange Online Protection (EOP) is a cloud-based email filtering service that offers anti-malware, anti-spam, and some basic policy enforcement, but it does not include any native email encryption capability. EOP's role is to protect the email infrastructure from threats and to filter email traffic, not to apply encryption to messages. Therefore, relying on EOP alone would leave sensitive emails unencrypted, and it cannot fulfill the requirement to encrypt them.