[mh_key_takeaways]
Outlook 365 encrypt email works through Microsoft Purview Message Encryption, a service built into Business Premium and Enterprise plans. Clicking the Encrypt button in the Options ribbon triggers the flow, and the recipient reads the message inline or through a branded portal.
This guide walks through desktop, web, and mobile steps, the two default encryption templates, mail flow rule automation, and HIPAA fit. Practices that need a simpler option can layer a dedicated encrypted email service on top of the existing Outlook account.
Every step below reflects the Microsoft 365 admin experience as of 2026. Feature names shift year to year, so cross-check the Microsoft learn documentation before a large rollout.
Licensing decides whether the Encrypt button appears
The Encrypt button appears in Outlook only when the mailbox license includes Purview Message Encryption. Business Premium, E3, E5, and equivalent education, nonprofit, and government plans include it by default.
Business Standard, Business Basic, E1, and Apps-only plans do not include it. Users on those plans see no Encrypt option in the Options ribbon, and the compose window offers no sensitivity label picker.
Two paths fix the gap. Upgrade specific seats to Business Premium, or add the Microsoft 365 E5 Compliance license per user. Both carry a monthly cost that scales with headcount.
A third path skips the Microsoft licensing question entirely by routing sensitive mail through a dedicated service that owns the encryption layer. That approach fits smaller practices that resist the per-seat cost of Business Premium.
The Encrypt button in Outlook desktop lives inside the Options ribbon
Open a new message in Outlook for Windows or Mac. Click the Options tab at the top of the compose window. Look for the Encrypt button in the Permission group next to the sensitivity label picker.
Click Encrypt, then pick Encrypt-Only or Do Not Forward from the dropdown. A blue banner appears above the recipient field confirming the message is encrypted.
The dropdown may show additional custom templates if the tenant administrator created them. Common examples include Confidential, Highly Confidential, or a template branded with the practice name.
Attachments follow the same encryption policy as the message body. Office files stay protected after download for recipients who use Microsoft 365, and PDFs open through the portal viewer.

Outlook on the web uses a different menu path
The web app hides the Encrypt option under the three-dot menu at the top of the compose window. Click the three dots, hover on Encrypt, and pick a template.
The Encrypt icon shows a lock next to the recipient field once the setting applies. Removing the encryption before send requires clicking Change permissions and picking No Restriction.
Outlook on the web does not support switching from Encrypt-Only to Do Not Forward after the setting is applied without recomposing. Pick the template first, then finish the message body.
The web experience matches the desktop flow for external recipients. The link and portal path stay identical regardless of which Outlook client sent the message.
Mobile Outlook supports encryption on both iOS and Android
Open the Outlook mobile app and start a new message. Tap the arrow icon at the top right of the compose window to expand the options. Tap Encrypt and pick a template.
The mobile flow requires Outlook version 4.2338 or later on iOS and 4.2337 or later on Android. Older builds show the Encrypt option grayed out even on Business Premium tenants.
Attachments compose the same way as on desktop. Files pulled from OneDrive or SharePoint apply their existing sensitivity labels, and files uploaded from the device follow the message-level template.
Reading an encrypted message on mobile works inline for internal recipients. External recipients tap the Read the message button, which opens the browser to the Office 365 Message Encryption portal.
[mh_example]
Encrypt-Only and Do Not Forward templates behave differently
Encrypt-Only encrypts the message body and attachments during transit and at rest. The recipient reads, replies, forwards, prints, and copies content without restriction. This template fits routine sensitive mail like invoices or draft contracts.
Do Not Forward encrypts the same content and adds usage rights. The recipient reads and replies, but the client blocks Forward, Copy, and Print actions. The portal viewer hides the download button.
Neither template can be changed after the message is sent. Recall works only for internal Microsoft 365 recipients, so external messages stay in the recipient inbox until the mailbox owner deletes them.
Custom templates built in the Microsoft 365 admin center support intermediate policies. A template can allow reply but block forward, or allow reply-all but block print. Setup takes 10 minutes in the Purview compliance portal.
Mail flow rules automate encryption for sensitive messages
Automatic encryption removes the burden from staff who forget to click Encrypt. Open the Exchange admin center, go to Mail flow, then Rules, and click Add rule.
Set the condition to match a keyword in the subject or body. Common patterns include patient ID, DOB, MRN, SSN, and the word confidential. Regex matching handles credit card and Social Security number patterns.
Add the action Apply Office 365 Message Encryption and rights protection. Pick Encrypt or Do Not Forward from the dropdown. Save the rule in preview mode first.
Review the message tracking log after a week. False matches on routine internal replies signal that the keyword list is too broad. Refine the list, then flip the rule to enforced mode.

External recipient experience depends on the recipient mail provider
Microsoft 365 and Outlook.com recipients read the message inline without a portal step. The reading pane shows the encrypted content, and Reply works normally.
Gmail recipients see a preview and click Read the message to open the Office 365 Message Encryption viewer. Signing in with a Google account skips the passcode step.
Every other provider, including Yahoo, AOL, and consumer ISP addresses, hits the branded portal and requests a one-time passcode. The code arrives at the same email address within seconds and stays valid for 15 minutes.
Branding the portal with practice logo, header text, and disclaimer content builds trust with first-time recipients. Setup takes two minutes under Microsoft 365 admin center, Settings, Org settings, Organization profile.
HIPAA compliance requires more than the Encrypt button
Purview Message Encryption meets the HIPAA Security Rule technical safeguard for encryption in transit and at rest. That single control is necessary but not sufficient for a compliant email workflow.
The covered entity must sign the Microsoft Business Associate Agreement through the Service Trust Portal. The BAA covers Microsoft 365, Azure, and Dynamics 365 at no extra cost.
Workforce training documents that staff know when to click Encrypt and how to explain the portal to a patient. The Security Rule administrative safeguards require annual training records.
Practices building a broader patient communication stack should also review the healthcare website security features that intake forms and patient portals should meet.
[mh_protip]
Related Microsoft encryption paths cover different scenarios
Purview Message Encryption is the modern default for outbound message encryption. Older tenants may still see references to Azure Information Protection, which is now merged into Purview.
S/MIME remains available for tenants that manage certificates and want end-to-end encryption where Microsoft servers cannot decrypt content. Setup takes hours per user and fits regulated industries that require certificate control.
The broader encrypt 365 email workflow spans licensing, sensitivity labels, mail flow rules, and DLP policies. Practices with a compliance officer often build the full stack, and small offices pick the two or three features that fit daily use.
For a step-by-step tour of the classic Encrypt button experience, the how to encrypt email in outlook 365 guide walks through the same flow with additional screenshots and troubleshooting tips.
Alternatives fit practices without Business Premium licensing
Practices on Business Standard or Business Basic face a real cost decision. Upgrading every seat to Business Premium runs about $22 per user per month, which adds up quickly for a 20-person practice.
The Microsoft 365 E5 Compliance add-on costs less per seat but still requires an existing Business or Enterprise base license. Both paths keep encryption inside the Microsoft ecosystem.
Dedicated encrypted email services layer on top of any Outlook or Gmail account with no licensing changes. A HIPAA-compliant secure email service like Mailhippo includes a BAA in the base plan and adds no portal step for common recipient providers.
The decision comes down to team size, existing licensing, and how often mail flows to Gmail and non-Microsoft recipients. Larger tenants with Business Premium already in place stay with Outlook encryption, and smaller offices often pick a dedicated service for simpler daily use.
Common pitfalls slow down early rollouts
The most common early problem is missing licensing. A staff member sees no Encrypt button, tickets IT, and IT confirms the seat is on Business Standard. Audit licensing before training rollout.
The second most common problem is recipient confusion during the first message. The portal step surprises patients and referring providers who expect inline mail. A short cover message explaining what to expect cuts support calls.
Mail flow rules that match too broadly encrypt normal internal replies. Staff read the encrypted format as a signal that something is confidential, which trains them to distrust routine mail. Refine keywords in preview mode.
Attachment size limits still apply. Purview encryption does not raise the 150 MB Exchange Online message ceiling. Large radiology or imaging files still need a separate transfer path with a signed BAA.
- Confirm Business Premium, E3, E5, or E5 Compliance licensing on every seat that sends encrypted mail.
- Brand the recipient portal with practice logo, header text, and support contact before the first external send.
- Default clinical staff to Do Not Forward and administrative staff to Encrypt-Only, then adjust based on real use.
- Test mail flow rules in preview mode for a full week before enforcing them tenant-wide.
- Document workforce training records annually to meet the HIPAA Security Rule administrative safeguards.
The Outlook 365 encrypt email flow is production-ready for practices on the right licensing tier. Practices outside that tier have three real options, and the right pick depends on team size, mail volume, and how often sensitive messages cross into Gmail and consumer inboxes.
- Sign the Microsoft BAA through the Service Trust Portal before any PHI moves through Outlook.
- Reference HHS Security Rule guidance when writing internal encryption policies.
- Cross-check feature availability on the Microsoft Purview documentation before large rollouts.
[mh_faqs]





