Encrypted Email Microsoft 365 Setup Guide for 2026

📅 July 20, 2026 ✍️ By Chris Almond ⏱️ 8 min read
encrypted email microsoft 365 guide featured image

🔑 Key Takeaways

  • Purview Message Encryption ships free on Business Premium, E3, and E5; Standard and Basic skip it.
  • Accept the Microsoft BAA in the admin center Terms link before the first PHI message leaves.
  • Four permission templates cover most PHI use; sensitivity labels auto-trigger them at send time.
  • S/MIME beats Purview on cryptography but tanks on patient recipients who cannot install a cert.
  • Purview portal drops adoption 15 to 25%; layer Mailhippo for external patient mail flow.

Encrypted email on Microsoft 365 uses Microsoft Purview Message Encryption behind the scenes. The service ships with Business Premium, E3, E5, and F3 plans at no extra cost.

Practices sending PHI to patients or vendors need three things in place. A qualifying license, a signed business associate agreement with Microsoft, and a published sensitivity label that maps to an encryption template. Once those three exist, users see the Encrypt button in Outlook and can send encrypted email from any device.

This guide walks through the setup steps, the license comparison, the sender experience across desktop, web, and mobile, and where the portal-based delivery step creates friction for high-volume patient communication.

Encrypted email Microsoft 365 licensing landscape

Purview Message Encryption ships with Business Premium at $22 per user per month, E3 at $36, E5 at $57, and Frontline F3 at $8. Business Basic at $6 and Business Standard at $12.50 do not include the Encrypt button.

Practices on Basic or Standard have two upgrade paths. Move the tenant to Business Premium for the full compliance stack. Add the Microsoft 365 E3 Compliance add-on at $12 per user per month to gain Purview without paying for Business Premium features the practice does not use.

Nonprofits get 30 to 75 percent off list on every plan through the Microsoft Nonprofits program. Business Premium runs about $5.50 for verified nonprofits. Documentation lives at Microsoft Nonprofits portal.

Confirm the license status in the Microsoft 365 admin center under Billing, Licenses. See Microsoft 365 email encryption setup for the regional configuration walkthrough.

Business associate agreement for encrypted email Microsoft 365

Microsoft signs a business associate agreement with covered entities on qualifying paid plans. The BAA covers Exchange Online, SharePoint Online, OneDrive, Teams, and Purview.

Administrators accept the BAA in the Microsoft 365 admin center. Open Billing, Your Products, then click the Terms link on the eligible plan. Read the BAA in full and click Accept. The tenant is HIPAA-eligible immediately after acceptance.

The BAA does not cover any consumer Outlook.com account or any free Microsoft account. Verify the tenant type in the admin console before treating any mailbox as HIPAA-eligible.

After BAA acceptance, configure the required admin settings. Enable multi-factor authentication for every user. Turn on audit logging in the compliance portal. Set retention that meets the six-year Privacy Rule requirement. Reference the sample BAA at HHS sample BAA provisions.

encrypted email microsoft 365 in article illustration one

Enabling Microsoft 365 email encryption with Microsoft Purview

Sign in to compliance.microsoft.com with a global admin or compliance admin account. Open Information Protection, then Labels.

Click Create Label. Give the label a display name like Confidential, add a description, and pick a color. On the encryption step, choose Assign Permissions Now.

Configure the permission block. Add users or groups, set the permission level, and save the encryption settings. Publish the label to the tenant. Users see the Encrypt button in Outlook after publication.

Test on a pilot user before rolling to production. Send a message from the pilot mailbox to an external Gmail address and confirm the recipient gets the portal notification. Reference Microsoft Purview email encryption for the deep configuration walkthrough.

Sending encrypted email from desktop Outlook

Compose the message. Go to the Options ribbon at the top of the composer window. The Encrypt button lives in the Permission group in the middle of the ribbon.

Click Encrypt. A dropdown appears with the available permission templates. Pick Encrypt for basic encryption or Do Not Forward for stronger controls that block forwarding and printing.

The composer displays a lock icon at the top and a permission banner near the subject line. Send the message. External recipients get a notification email with a portal link.

If the Encrypt button is grayed out, the tenant does not have a published sensitivity label yet. Check with the admin. See encrypt email Microsoft Outlook for the full sender walkthrough.

Example

A 12-provider mental health group runs Microsoft 365 Business Standard at $12.50 per user per month. Adding the E3 Compliance add-on at $12 per user brings Purview Message Encryption online for $144 per user per year versus a full Business Premium upgrade at $9.50 delta per seat. The compliance admin accepts the BAA in the admin center, publishes a Confidential sensitivity label, and rolls out training to 22 clinical staff. First-month portal support tickets from patients hit 18, dropping to 4 after a screenshot walkthrough goes into the intake packet.

Sending encrypted email from Outlook web

Sign in to outlook.office.com. Compose the message as usual. Click the three-dot menu at the top of the composer, next to the Send button.

Choose Encrypt from the dropdown. A submenu opens with the available permission templates. Pick Encrypt or Do Not Forward. The composer shows a lock icon and a permission banner at the top.

Send the message. The recipient experience matches desktop Outlook. External recipients get a notification email with a portal link.

Outlook web sometimes hides advanced permission templates behind the tenant plan tier. Enterprise E5 tenants see every option. Business Premium tenants see the default four. See Microsoft Outlook 365 encrypt email for the tier-by-tier feature matrix.

encrypted email microsoft 365 in article illustration two

Sending encrypted email from Outlook mobile

The Outlook mobile app on iOS and Android places the encryption toggle inside the ellipsis menu of the composer. Tap the ellipsis to open the extended menu.

Tap Encrypt Message. A screen appears with the available permission templates. Pick the template and tap the back arrow to return to the composer.

The lock icon in the composer header confirms encryption is active. Send the message from the mobile composer. The recipient experience matches desktop and web.

Users on personal iPhones sending occasional PHI often struggle with the mobile encryption workflow because the ellipsis menu is not obvious. Train users on the workflow before rollout. Screenshots in the training material help far more than a written procedure.

Recipient experience for Microsoft 365 encrypted email

External recipients get a notification email with a portal link. The notification email includes the sender name, subject line, and a button that opens the portal.

Recipients sign in with Microsoft, Google, or a one-time passcode. The Microsoft option works for anyone with a Microsoft account. The Google option works for anyone with a Google account. The one-time passcode works for anyone else.

Reply from the portal stays encrypted. The reply routes back through Microsoft servers and lands in the original sender inbox as a normal encrypted message.

The friction of the portal step drops adoption. Practices sending 200 patient messages per week often see 30 to 50 first-time recipients need help with the portal. Support ticket volume tracks directly to the portal experience.

💡Pro Tip: Test Purview on a pilot before tenant-wide rollout

Publishing a sensitivity label to every user at once floods the help desk with grayed-out Encrypt buttons and confused patients on the receiving end. Publish the label to a pilot group of 3 to 5 staff first. Send test messages to Gmail, Yahoo, and Outlook.com addresses. Confirm the portal login works on iOS Safari and Android Chrome before opening the label to the full tenant. This single step prevents the two-week support backlog most practices hit.

S/MIME as an alternative encrypted email path on Microsoft 365

S/MIME encryption sits alongside Purview Message Encryption in Microsoft 365. S/MIME uses certificates installed on the sender and recipient devices.

Configuring S/MIME in Microsoft 365 requires the admin to upload the certificate authority chain to the Exchange admin center. Users install their personal certificate in the Windows certificate store or the Outlook mobile app.

S/MIME provides stronger cryptographic guarantees than Purview because the message content decrypts only on the recipient device. Microsoft servers never see the plaintext.

The tradeoff is setup complexity. Most healthcare practices skip S/MIME because patients cannot install certificates. Reference the current S/MIME setup path at Microsoft Learn S/MIME configuration.

Common Microsoft 365 encrypted email problems and fixes

The Encrypt button is grayed out. The tenant does not have a published sensitivity label with encryption enabled, or the user account does not have a Purview-eligible license.

The recipient gets a portal link but cannot log in. The one-time passcode option ships to the same email address the notification came to. Ask the recipient to check the inbox for the passcode message and to check spam if the passcode does not appear.

Attachments open with a permissions error. The permission template applied to the message restricts attachments. Change the template to Encrypt without additional restrictions.

Common troubleshooting checklist:

  • Confirm the license includes Purview Message Encryption
  • Confirm the BAA is accepted in the admin center
  • Confirm at least one sensitivity label is published with encryption
  • Confirm the Outlook client version is current
  • Confirm the recipient inbox is not blocking the portal notification domain

When to layer a zero-step alternative on top of Microsoft 365

Practices with heavy external patient mail volume often outgrow the Purview portal experience. Support ticket volume from patients who cannot log in to the portal starts to eat into clinical time.

A zero-step encryption service like Mailhippo works alongside Microsoft 365. Purview handles internal traffic between mailboxes on the tenant. Mailhippo handles external mail to patients and vendors without a portal step. The two services coexist without a routing conflict.

Practices running HIPAA compliant website design already understand the reasonable and appropriate standard. Applying the same standard to email means picking the tool that keeps compliance tight while dropping recipient friction. See also security features for healthcare websites for the parallel web guidance.

For further reference, review Microsoft Learn Purview Message Encryption, the HHS HIPAA Security Rule, and the HIPAA Journal guide to compliant email before finalizing the Microsoft 365 encrypted email stack. See also Microsoft email encryption and Microsoft Office 365 email encryption for related walkthroughs. See the Mailhippo secure email service overview for the zero-step alternative details.

Frequently Asked Questions

How do I send encrypted email in Microsoft 365? +

On desktop Outlook, compose the message, go to the Options ribbon, and click Encrypt. Pick a permission template from the dropdown or accept the default Encrypt option. Send the message. On Outlook web, click the three-dot menu at the top of the composer, choose Encrypt, and pick the template. On Outlook mobile, tap the ellipsis in the composer, tap Encrypt Message, and pick the template. External recipients open the message through a portal with Microsoft, Google, or one-time passcode sign-in.

What license do I need for Microsoft 365 email encryption? +

Purview Message Encryption ships with Business Premium at $22 per user per month, E3 at $36 per user per month, E5 at $57 per user per month, and Frontline F3 at $8 per user per month. Business Basic at $6 and Business Standard at $12.50 do not include the Encrypt button. Practices on Basic or Standard either upgrade to Business Premium or add the Microsoft 365 E3 Compliance add-on at $12 per user per month. Nonprofits get 30 to 75 percent off list on all plans.

Is Microsoft 365 email HIPAA compliant? +

Microsoft 365 paid business plans are HIPAA-eligible when the tenant has a signed BAA with Microsoft. Accept the BAA in the admin center under Billing, Your Products, then the Terms link on the eligible plan. The BAA covers Exchange Online, SharePoint, OneDrive, Teams, and Purview. Practices sending PHI on Outlook.com free or any consumer Microsoft account are not covered by the BAA. Verify the tenant type in the admin console. Configure required admin settings after BAA acceptance including two-factor authentication and audit logging.

How do I enable Microsoft 365 email encryption with Microsoft Purview? +

Sign in to the Microsoft 365 admin center. Confirm the tenant has a plan that includes Purview Message Encryption. Sign in to compliance.microsoft.com. Open Information Protection, then Labels. Create a sensitivity label with encryption enabled and one of the four default permission templates. Publish the label to the tenant. Users see the Encrypt button in Outlook after publication. Test on a pilot user before rolling to production. Reference the Microsoft Learn docs for the full step-by-step configuration.

Where does the Microsoft 365 encrypted email license appear in the admin center? +

Sign in to the Microsoft 365 admin center. Open Billing, Licenses. The license list shows every SKU purchased. Business Premium, E3, E5, and F3 all include Purview Message Encryption automatically. Business Basic and Business Standard show the base license without Purview. Add the Microsoft 365 E3 Compliance add-on if you need Purview on top of Business Standard. The add-on appears as a separate line item in the license list after purchase.

Why is the Encrypt button missing from my Outlook? +

Three common reasons. The tenant does not include Purview Message Encryption on the current 365 plan. A tenant admin has not published a sensitivity label with encryption enabled. The Outlook client version is too old and does not render the Encrypt button. Update Outlook to the current channel. Confirm the plan includes Purview. Sign in to compliance.microsoft.com and publish a label with encryption. If the button still does not appear, restart Outlook to pick up the new label policy.

What is the difference between Microsoft 365 encryption and S/MIME? +

Microsoft 365 encryption through Purview Message Encryption uses a portal-based delivery model. External recipients open messages through a portal with sign-in. S/MIME uses certificates installed on both the sender and recipient devices. S/MIME provides stronger end-to-end guarantees but requires certificate management on both ends. Most healthcare practices pick Purview because patients cannot install certificates. Organizations with technical partners who already have S/MIME certificates prefer S/MIME because the recipient experience is smoother inside Outlook.

Leave a Reply

Your email address will not be published. Required fields are marked *

Send your first secure email today Start free — no credit card required. HIPAA-compliant encryption in minutes. Start Free →