How to Use Microsoft 365 Encryption in 2026: Protecting Sensitive Email and Documents
Businesses send sensitive information every day.
Contracts. Financial information. Employee records. Client documents. Commercial proposals. Legal correspondence.
Much of it travels through email or is stored in SharePoint and OneDrive.
Microsoft 365 already encrypts customer data at rest and in transit as part of the service. For example, Exchange Online uses TLS to help protect connections while email is travelling between supported mail systems. But that is different from applying protection to the message or document itself so that only authorised people can open it or perform certain actions with it.
That distinction matters.
If your business handles confidential information, Microsoft 365 provides several additional controls through Microsoft Purview, including message encryption and sensitivity labels.
Here is how they work in 2026.
Microsoft 365 Encryption Is Not Just One Thing
The phrase Microsoft 365 encryption can describe several different protections.
Encryption in transit
Microsoft 365 uses technologies such as TLS to protect data while it moves between systems.
Encryption at rest
Data stored within Microsoft 365 services is also encrypted by Microsoft as part of the platform.
Microsoft Purview Message Encryption
This allows businesses to protect individual email messages, including messages sent to people outside the organisation.
Microsoft says Purview Message Encryption supports encrypted communication with users of Microsoft 365 as well as services such as Gmail, Yahoo and other email providers.
Sensitivity labels
Microsoft Purview sensitivity labels can classify information and, where configured, apply encryption and usage restrictions to emails and documents.
These layers solve different problems.
TLS protects the journey.
Message encryption and sensitivity labels can help protect the information itself.
How to Send an Encrypted Email in Outlook
For organisations where Microsoft Purview Message Encryption is available and configured, Outlook can provide encryption options while composing an email.
In supported versions of Outlook, the basic process is:
1. Create a new message.
2. Open Options.
3. Select Encrypt.
4. Choose the appropriate protection.
5. Complete the email and send it.
Microsoft currently documents options including Encrypt and Do Not Forward, although exactly what appears depends on your Microsoft 365 licensing, Outlook version and organisational configuration.
That last point is important.
If you cannot see an encryption option, it does not necessarily mean Outlook is broken.
Your organisation may need Microsoft 365 licensing or administrator configuration before the functionality becomes available.
Encrypt vs Do Not Forward
These sound similar but they solve slightly different problems.
Encrypt
Encrypt protects the message so that authorised recipients can access it.
This is useful when you need to protect confidential email while still allowing normal collaboration with the recipient.
Do Not Forward
Do Not Forward applies additional usage restrictions.
Microsoft documents that it can prevent forwarding and restrict actions such as copying or printing, depending on the protection being applied and the client being used.
That could make it appropriate for information such as:
HR correspondence.
Commercially sensitive information.
Legal documents.
Confidential financial information.
Sensitive customer communications.
But there is an important reality check:
Do Not Forward does not make information impossible to leak.
Someone could potentially photograph a screen, manually reproduce information or disclose it another way.
Information protection reduces risk.
It doesn't repeal the laws of physics.
What Are Microsoft Purview Sensitivity Labels?
Sensitivity labels are where Microsoft 365 information protection becomes much more useful for businesses.
Instead of asking employees to make a complicated security decision every time they send something, an organisation can create understandable classifications such as:
Public
Internal
Confidential
Highly Confidential
The names are completely configurable.
The organisation decides what they mean and which protections should apply.
A Confidential label might encrypt a document so only employees can access it.
A Highly Confidential – Finance label might restrict access to members of the finance department.
Another label could protect an email against forwarding.
Microsoft Purview allows administrators to configure labels that apply encryption and specify usage permissions.
The employee therefore does not need to understand encryption algorithms or rights-management technology.
They need to understand:
“This document is Confidential.”
The technology can handle much of the protection behind that decision.
Sensitivity Labels Can Protect Documents Too
Email is only part of the problem.
Sensitive documents frequently end up:
Downloaded.
Forwarded.
Copied onto laptops.
Stored in SharePoint.
Moved into OneDrive.
Shared with external organisations.
Microsoft Purview sensitivity labels can apply protection to supported Office documents, helping protection remain associated with the information rather than depending solely on the folder where it happens to be stored.
Microsoft has continued expanding sensitivity-label support in SharePoint and OneDrive. Its August 2026 guidance confirms that SharePoint and OneDrive can recognise and process sensitivity labels on supported Word, Excel, PowerPoint and PDF files when the required capability has been enabled.
That is fundamentally different from ordinary folder permissions.
A folder permission says:
“Who can access this location?”
Information protection can say:
“Who can use this particular document?”
Don't Encrypt Everything
It can be tempting to decide:
“Security is good, so let's encrypt every email.”
That isn't necessarily the best approach.
Overusing restrictive controls can make employees look for ways around them.
A meeting invitation probably does not need the same protection as an acquisition document or employee disciplinary record.
Instead, classify information according to risk.
Ask:
Would disclosure harm a client?
Could it create financial loss?
Does it contain personal information?
Is it commercially sensitive?
Would unauthorised disclosure create a legal or regulatory problem?
Then apply appropriate protection.
Good information security should make secure behaviour easier, not turn routine work into an obstacle course.
Use Automatic Protection Where Appropriate
Not every decision needs to depend on an employee remembering to press Encrypt.
Microsoft 365 administrators can create mail flow rules that automatically apply Microsoft Purview Message Encryption when specified conditions are met.
For example, an organisation might create rules around particular:
Recipients.
Domains.
Message properties.
Data types.
Business processes.
This can be especially useful where an organisation regularly sends specific types of sensitive information.
The aim is not necessarily to encrypt everything automatically.
It is to identify predictable situations where protection should consistently be applied.
Combine Encryption With Data Loss Prevention
Encryption becomes more powerful when it forms part of a wider information-protection strategy.
For example, Microsoft Purview Data Loss Prevention can help businesses identify and control sensitive information.
Sensitivity labels can classify it.
Encryption can protect it.
Access policies can limit who gets into the environment.
Endpoint controls can help protect the devices accessing it.
The result is much stronger than simply giving employees an Encrypt button and hoping everybody remembers when to use it.
Encryption Does Not Replace Secure Sharing
Email isn't always the best way to share sensitive files.
Sometimes sending an encrypted attachment is appropriate.
In other situations, sharing a controlled SharePoint or OneDrive location can provide a better workflow because access can be managed centrally and revoked later.
Businesses should therefore ask:
Should this information actually be attached to an email?
Sometimes the safer approach is sending access to the document rather than sending another copy of the document.
Encryption Does Not Fix a Compromised Account
This is one of the most important limitations to understand.
Imagine an attacker steals an employee's credentials and successfully signs into Microsoft 365 as that employee.
Encryption cannot magically protect information that the employee is legitimately authorised to access.
The system sees the attacker as the authorised user.
This is why information protection needs to work alongside strong identity security.
That can include:
MFA
Passkeys and phishing-resistant authentication
Microsoft Entra Conditional Access
Risk-based access controls
Secure administrator accounts
Managed devices
Endpoint Detection and Response
Microsoft's approach to sensitivity labels and encryption is intended to be part of a wider information-protection strategy rather than a standalone defence.
Don't Email Passwords Just Because the Message Is Encrypted
One line in the previous version of this article suggested encryption for sending passwords or account details.
I'd change that advice.
Encryption makes an email more secure, but email should not become your normal password-distribution system simply because encryption exists.
Where possible, use:
A password manager.
Secure one-time sharing.
Proper account provisioning.
Temporary passwords that must immediately be changed.
Passkeys or passwordless authentication where appropriate.
The objective should increasingly be to reduce the number of reusable passwords being passed around at all.
Don't Confuse “Confidential” With Encryption
Outlook has historically included message sensitivity settings such as:
Normal.
Personal.
Private.
Confidential.
Those labels should not automatically be assumed to provide cryptographic protection.
Microsoft distinguishes these conventional sensitivity markings from Microsoft Purview information protection and encryption controls.
Simply marking something:
CONFIDENTIAL
does not necessarily prevent somebody opening it.
Your organisation needs properly configured protection policies.
External Recipients Can Still Receive Encrypted Email
Encryption becomes considerably less useful if it only works internally.
Microsoft Purview Message Encryption is specifically designed to allow encrypted messages to be exchanged with recipients outside the Microsoft 365 organisation.
Depending on the recipient and service, they may authenticate using their existing account or use Microsoft's encrypted-message experience.
That means a business can protect information sent to:
Clients.
Solicitors.
Accountants.
Suppliers.
External consultants.
Other third parties.
But test the experience.
If your business regularly exchanges encrypted information with an important customer, make sure both parties understand how to access it before somebody sends an urgent document at 4:55 on Friday afternoon.
Common Microsoft 365 Encryption Mistakes
The technology is powerful, but configuration matters.
Some common problems include:
Creating labels nobody understands.
If employees cannot tell the difference between Confidential and Highly Confidential, classification becomes guesswork.
Publishing too many labels.
Ten subtly different security classifications can become harder to use than three or four clear ones.
Not training employees.
People need to know when protection is appropriate.
Ignoring external sharing.
Encryption needs to fit how customers and suppliers genuinely work.
Assuming encryption equals backup.
It doesn't.
Assuming encryption stops phishing.
It doesn't.
Assuming Microsoft 365 automatically configures your ideal information-protection policy.
It doesn't.
The underlying Microsoft 365 service provides extensive encryption, but customer-level information protection still requires design and configuration.
A Sensible Microsoft 365 Encryption Strategy for 2026
For many SMEs, a practical approach is:
1. Identify the information that actually needs additional protection.
Start with financial, HR, legal, customer and commercially sensitive information.
2. Create simple sensitivity classifications.
Keep labels understandable.
3. Configure appropriate encryption and usage restrictions.
Match the protection to the risk.
4. Train employees.
Show them what labels mean and when to use them.
5. Automate predictable cases.
Use appropriate policies, DLP or mail-flow rules where useful.
6. Protect identities too.
Use MFA, Conditional Access and phishing-resistant authentication where appropriate.
7. Review the configuration periodically.
Businesses change.
Your information-protection rules need to change with them.
Microsoft 365 Encryption With Hamilton Group
Microsoft 365 already provides substantial encryption underneath the platform.
The bigger question for businesses is:
Are you using the customer-controlled protection features correctly?
Hamilton Group can help organisations review and configure Microsoft Purview Message Encryption, sensitivity labels, secure email, SharePoint and OneDrive protection, Data Loss Prevention, Microsoft Entra ID, Conditional Access and wider Microsoft 365 security.
We can also help design information-protection policies that employees can realistically understand and use rather than deploying a complicated collection of labels nobody knows what to do with.
And when your employees need IT assistance, our aim is to make first contact on support requests within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our Microsoft 365 and cyber-security experts.
SEO Meta Description
.
SEO Keywords
Blog Summary
.