Saturday, November 15, 2014

Current Office 365 Encryption Solutions

The question comes up a lot on is does Office 365 support encryption? The answer is Yes and there are lots of encryption solutions implemented.
A great resource that you should always start at is the Office 365 Trust Center - http://trust.office365.com. You should also review the Office 365 Security Whitepaper located here - http://www.microsoft.com/en-us/download/details.aspx?id=26552.
I usually break this down into a couple different views. Encryption in Transit, Encryption at Rest and Payload Encryption.

Encryption in Transit
All Office 365 traffic / data is encrypted in using SSL/TLS to client machines connecting to the service. Read about this in the Office 365 Security Whitepaper.

Encryption at Rest
BitLocker has been deployed to encrypt data at rest inside of Office 365.
Additionally for OneDrive for Business and SharePoint Online a new file based encryption solution has been implemented. Read about both of theses in the Office 365 Security Whitepaper.

Payload Encryption
There are additional solutions that customers can choose to utilize with Office 365 to encrypt data.

S/MIME was actually the original intent of why I was writing this blog; but I figured it was worth communicating that encryption is more than just S/MIME. S/MIME encryption of email is supported with Office 365. Please review these two article for more information: http://blogs.office.com/2014/02/26/smime-encryption-now-in-office-365/ and http://technet.microsoft.com/en-us/library/dn626158(v=exchg.150).aspx.

UPDATE 1/2/2015 - Shortly after I wrote this blog, a really good article was created here - http://blogs.technet.com/b/exchange/archive/2014/12/15/how-to-configure-s-mime-in-office-365.aspx

Rights Management Service (RMS) is supported as well. Office 365 supports both Windows RMS or Azure RMS. You can use RMS is a great solution to assist with DLP for email and documents. You have the ability to create policy to encrypt data. For SharePoint Online please review the Service Description here - https://support.office.com/en-us/article/Set-up-Information-Rights-Management-IRM-in-SharePoint-admin-center-239ce6eb-4e81-42db-bf86-a01362fed65c?ui=en-US&rs=en-US&ad=US. For Exchange Online please review http://technet.microsoft.com/en-us/library/jj983436(v=exchg.150).aspx.

Office 365 Message Encryption (OME) is another solution that is available to you. This is another solution provided that allows you administrators to create policy to encrypt data that is leaving the organization. For detailed information, please review this - http://technet.microsoft.com/library/dn569286.aspx.

Additionally in Exchange Online Protection (EOP) you have the ability to enforce Transport Layer Security (TLS) for SMTP messages to partners. For more information, please review the following - http://technet.microsoft.com/en-us/library/jj723154(v=exchg.150).aspx.

No comments: