Ways to Block Mailbox Delegates from Accessing IRM Protected Emails

Ways to Stop Delegates from Reading Your Protected Emails

Your protected emails could still be exposed! 

Did you know? By default, delegates with Full Access to a mailbox can read IRM-protected emails. That’s right, even emails you thought were “for your eyes only” could be visible to others!  

The good thing is that there are ways to prevent this and take back control of your sensitive emails. Depending on your setup, whether it’s a user mailbox or a shared mailbox, and whether you’re on Outlook for Windows, Mac, or mobile, you can choose the method that works best: 

  1. Method 1: Use built-in protection like Encrypt-Only or Do Not Forward. Only the recipients in the To/Cc/Bcc fields can read the email. 
  2. Method 2: Apply a sensitivity label that enforces Encrypt-Only or Do Not Forward. This works similarly to Method A, but utilizes labels for easier management. 
  3. Method 3: Run the Set-MailboxIRMAccess cmdlet in Exchange Online PowerShell to block delegate access—perfect for shared mailboxes or specific scenarios. 

💡Tip: If your sensitivity label assigns access to predetermined users or groups, anyone in that list can still read your message, even if they weren’t in To/Cc/Bcc. So pick the right method carefully! 

Keeping control of your sensitive emails is possible; it just takes a few smart settings.  

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *

Subscribe to Newsletter

Subscribe to our email newsletter to get the latest posts delivered right to your email.
Powered by Amail.