Skip to Content

Encryption

Manage encryption settings for data at rest and in transit across Microsoft 365 services.

Encryption Coverage

ServiceAt RestIn Transit
Exchange OnlineBitLocker + service encryptionTLS 1.2
SharePoint OnlineBitLocker + per-file encryptionTLS 1.2
OneDriveBitLocker + per-file encryptionTLS 1.2
TeamsBitLockerTLS 1.2 + SRTP

Customer Key

Optional customer-managed encryption keys (BYOK) for additional control:

  • Requires Azure Key Vault
  • Provides data purge capability
  • Available for Exchange, SharePoint, and Teams

Message Encryption

  • Office 365 Message Encryption — Encrypt emails sent externally
  • S/MIME — Certificate-based email encryption
  • Information Rights Management — Persistent protection with usage rights

API Reference

  • GET /api/security/encryption/status — Get encryption status
  • GET /api/security/encryption/customer-key — Get Customer Key status
Last updated on