Quick Answer:

  • To secure email in Outlook effectively, open a new message >> select the “Options” tab on the top ribbon >> click “Encrypt” and choose “Encrypt-Only” or “Do Not Forward”. This applies Microsoft Purview Message Encryption, which ensures only the recipient can read the message and protects it from interception during transfer.
  • And to secure the Outlook 365 Environment (against ransomware, accidental deletion, and sophisticated account takeovers), enterprise administrators must enable: Multi-Factor Authentication via Conditional Access policies, disable legacy protocols, configure Microsoft Defender anti-phishing policies, deploy Data Loss Prevention Policies, and establish an independent data recovery solution using SysTools Office 365 Backup & Restore Tool.

Sending encrypted emails protects the data during the transfer. However, relying completely on native encryption leaves the data vulnerable once it reaches the inbox. Also, strict compliance mandates like HIPAA, FINRA, and state-level data privacy laws mandates robust data security.

Therefore, it is imperative to know how to secure email in Outlook effectively. So, join this his straightforward, step-by-step guide and learn how to secure email in Outlook (Classic, New, and Web). Including how to protect the complete Outlook environment.

Stay tuned till the end!

How to Make a Secure Email in Outlook 365?

To make a secure email in Outlook, understanding the encryption permissions available in Outlook 365 is necessary. Microsoft offers three different levels of restrictions depending on the degree of sensitivity of the information. Here are the three encryption levels:

Encryption Level

Best Used For 

What It Does 

Encrypt-Only

  • External Communications.
  • Encrypts the message, giving access only to the recipient to read it. However, it can be forwarded or printed.

Do Not Forward

  • Highly sensitive internal data.
  • Encrypts the message and strictly restricts the recipient from forwarding, copying, or printing the content.

S/MIME

(Secure/Multipurpose Internet Mail Extensions)

  • Regulated Industries 
  • Utilizes certificate-based encryption requiring both the sender and receiver to have digital keys.

Amongst the three encryption levels, Encrypt-Only is the standard way to send a secure email in Outlook for most users.

How to Send Email Securely in Outlook?

Sending a secure email in Outlook (Classic Desktop App, New Outlook for Windows, or Outlook on the Web) is a straightforward process. Microsoft makes Outlook email encryption easily accessible for end-users. Depending on the organization’s configuration, the application of encryption can be executed in just a few clicks.

Via the Outlook Desktop Application:

Step #1: Compose a New Message

  • Open Outlook (desktop application or web version) >> click “New Email”.
  • Add the recipient, subject line, and the sensitive body text.

Step #2: Access the Options Tab

  • In the new message window, look at the top navigation ribbon.
  • Click on the “Options” tab.

Step #3: Select and Apply the Encryption Level

  • Click the “Encrypt” button (padlock icon). This will trigger different permission levels.
  • Select “Encrypt-Only” (restricts external interception but allows forwarding) or “Do Not Forward” (locks the email completely to the recipient).

Step #4: Verify and Send the Email

  • Once the encryption is applied, a notification banner will appear at the top of the draft confirming that the email is restricted.
  • Click “Send”.

Via Outlook on the Web (OWA):

  • Click “New Message”.
  • Click the “Encrypt” button (located directly above the message body).
  • Optional: Click “Change Permissions” to apply “Do Not Forward”.

How to Open a Secure Email in Outlook? (Internal and External Recipients)

“How to open a secure email in Outlook?” or “If I encrypt this, will the recipient actually be able to read it?” is a common query when securing an email in Outlook. Fortunately, Microsoft Purview Message Encryption makes the experience seamless.

For Internal Recipients

  • If a secure email in Outlook is sent/received from a colleague within the same Microsoft 365 tenant, Outlook will automatically verify the credentials and decrypt the message smoothly in the reading pane. The email will land in the inbox with a lock icon.

For External Recipients (Google, Yahoo

  • If a secure message in Outlook is sent or received from external providers (such as Google, Yahoo, etc.), a notification email with a “Read the message” link will be sent to the recipient,

Here’s the correct way to open the notification email:

  • Click “Read the Message”. This will open a secure browser tab.
  • Authenticate using the existing credentials.
  • Alternatively, click on “Sign in with a one-time passcode” to bypass sign-in using credentials. Clicking this option will send a temporary code. The code needs to be entered into the secure portal to view the email and any attachments instantly.

Important Note: The one-time passcodes are valid for only 15 minutes. So, if the user takes too long to enter the code, they have to request a new one from the secure portal.

How to Secure the Outlook 365 Environment (Administrator Controls)

In order to secure the Outlook 365 environment at the administrative level, enterprise admins and IT teams are required to implement security policies across Microsoft Entra ID, Microsoft Defender, and Microsoft Purview:

#1: Enforce Multi-Factor Authentication (MFA) Via Conditional Access

According to industry statistics, over 99% of compromised accounts do not use Multi-factor authentication. Hence, enforcing MFA via Microsoft Entra ID Conditional Access Policies is essential. It safeguards the Outlook environment from aggressive credential stuffing attacks.

Step #1: Authenticate on Microsoft Entra Admin Center

  • Go to entra.microsoft.com >> log in to the Microsoft Entra admin center (as a Global Administrator or Conditional Access Administrator).

Step #2: Configure Conditional Access and Create New Policy

  • Expand “Protection” (in the left navigation pane)>> select “Conditional Access”.
  • Click “New Policy” >> provide a descriptive name (such as MFA for Exchange Online”).

Step #3: Select the Target Users or Groups

  • Under “Assignments”, click “Users” >> select the target users or groups.
  • Note: Keep in mind to exclude an admin account to prevent tenant lockout.

Step #4: Locate Office 365 Exchange Online

  • Click “Target Resources” >> select “Cloud apps”.
  • Choose “Select Apps” >> search for “Office 365 Exchange Online”.

Step #5: Turn on “Enable Policy”

  • Under “Access controls”, click “Grant” >> check the box for “Require multifactor authentication” >> click “Select”.
  • Lastly, set the “Enable Policy” toggle to “On” >> click “Create”.

#2: Disable Legacy Authentication Protocols

Since legacy protocols (such as POP3, IMAP4, and SMTP Auth) cannot process MFA prompts, they become highly vulnerable to cyberattacks.

Step #1: Access Entra Admin Center

  • Access the “Microsoft Entra Admin Center”.

Step #2: Create the New Policy

  • Go to “Protection” >> select “Conditional Access”.
  • Click “Policies” >> select “New Policy”.
  • Name the Policy (such as “Block Legacy Authentication”).\
  • Assign the new policy to “All Users”. Exclude the admin account.

Step #3: Configure and Enable the Policy

  • Under “Target Resources” >> select “All cloud apps”.
  • Under “Conditions” >> select “Client Apps” >> set the toggle to “Yes”.
  • Check only the boxes for “Exchange ActiveSync clients” and “Other clients”. This will cover POP/IMAP.
  • Under “Access Controls” >> click “Grant”.
  • Select “Block Access” >> click “Select”.
  • Configure the policy to “On” >> click “Create”.

#3: Configure Anti-Phishing and Safe Links

  • Setting up “Anti-Phishing” tools and deploying “Safe Links” via Microsoft Defender for Office 365 prevents malicious payloads before they hit a user’s mailbox.

Step #1: Access Microsoft Defender and Threat Policies

  • Move to the “Microsoft Defender” portal (security.microsoft.com).
  • In the left navigation pane, click “Email & collaboration” >> select “Policies & rules”.
  • Click on “Threat Policies”.

Step #2: Set up Anti-Phishing and Safe Links

  • For Anti-Phishing: Click “Anti-Phishing” >> select “Create” >> name the policy >> assign the domains. Under the settings, set the Phishing email threshold to at least 2-Aggressive. Also, enable the “Impersonation protection” for major executives and internal domains.
  • For Safe Links: Return to Threat Policies >> click “Safe Links” >> click “Create”. Assign it to the users and confirm “Select the action for unknown potentially malicious URLs in messages” is turned on. This will ensure that URLs are actively scanned at the time of click.

#4: Deploy Data Loss Prevention (DLP) Policies

Deploying Data Loss Prevention (DLP) policies restricts users from accidentally or maliciously breaching sensitive enterprise data via Outlook.

Step #1: Accesss Microsoft Purview Compliance Portal

  • Go to the “Microsoft Purview compliance portal” (compliance.microsoft.com).

Step #2: Create a Policy

  • In the left pane, select “Data Loss Prevention” >> click “Policies”.
  • Click “Create Policy”.

Step #3: Name the Policy 

  • Select an industry template that resonates with the organization’s compliance needs (such as US Financial Data, HIPAA, or a custom policy) >> click “Next”.
  • Name the policy >> select “Exchange email” (as the only location to implement the policy).

Step #4: Define the Conditions and Actions 

  • Under “Policy Settings”, define the conditions (such as emails containing credit card numbers) and the actions (like restricting users from sharing and blocking access).
  • Review the settings >> select “Turn it on right away” >> click “Submit”.

#5: Establish Independent Data Recovery

An Outlook environment cannot be fully secured without a reliable disaster recovery and backup solution. But why? Because, according to the Microsoft 365 Shared Responsibility Model, the user is responsible for their data security.

In simple words, native retention policies are not true backups. If a ransomware attack encrypts the Outlook mailboxes or a rogue admin permanently deletes critical enterprise communications, Microsoft’s native retention policies and litigation holds are simply insufficient or incredibly complex to recover from.

Hence, to truly secure emails in Outlook against permanent data loss, deploy an independent, automated third-party backup solution like the SysTools Office 365 Backup & Restore tool.

This corporate-grade backup utility is the industry-leading solution for enterprise-grade protection. Here are some key feature that makes it the first choice of organisation administrators and IT experts:

  • Automated Local & Cloud Backups: Secures Outlook emails, contacts, calendars, and documents. Including Shared Mailboxes and In-Place Archive Mailboxes.
  • Bulk Backups: Supports backups of Outlook mailboxes in bulk.
  • Ransomware Protection: Allows administrators to instantly restore uncorrupted data if an Outlook account is compromised.
  • Regulatory Compliance: Satisfies strict US data retention requirements with point-in-time recovery capabilities.
  • Frustration-Free Restoration: Offers precise recovery options like date filter and delta sync to prevent mass tenant overwrites.
  • Intuitive Dashboard: Features a built-in centralized dashboard to track backup processes.

So, choose SysTools and secure critical business communications effectively and efficiently. For any technical guidance and solutions, without any hesitation, contact us at [email protected] / [email protected].

Frequently Asked Questions

Q.1 How to encrypt an email in Outlook?

To encrypt an email in the Outlook desktop app, compose a new email, go to the “Options” tab >> click “Encrypt,” and select the desired restriction level (such as Encrypt-Only or Do Not Forward). In Outlook on the web, click the “Encrypt” button (right above the message body).

Q.2 Does Outlook have end-to-end encryption?

Yes, Outlook is powered by end-to-end encryption through S/MIME and Office 365 Message Encryption (OME). However, both sender and recipient environments are required to be configured appropriately with legitimate certificates to achieve complete E2EE via S/MIME.

Q.3 How to secure Outlook against hackers?

To secure Outlook against hackers, enforce Multi-Factor Authentication (MFA), disable legacy authentication protocols (IMAP/POP), and utilize Microsoft Defender for anti-phishing. And to ensure data recovery in case of a successful data breach, leverage professional tools like SysTools Office 365 Backup.

Q.4 Why is the Encrypt button greyed out or missing in Outlook?

Encrypt button being greyed out or missing in Outlook happens when the Microsoft 365 subscription doesn’t include “Microsoft Purview Message Encryption. Or the IT administrator has disabled it at the tenant level. It usually requires an Office 365 E3/E5 or Microsoft 365 Business Premium license.

Q.5 Does Outlook email encryption protect attachments?

Absolutely yes! When “Encrypt-Only” or “Do Not Forward” encryption is applied, any attached Office documents (Word, Excel, PowerPoint) or PDF absorb the same encryption and access restrictions as the email body.