Skip to main content

Exchange Online OMEv2 and RMS Attachment Decryption Rule

EXCHANGE ONLINE ENCRYPTION EXCEPTION

Handle OMEv2 and RMS removal as a controlled exception

Transport rules that remove encryption must be narrow, approved, auditable and tied to a clear business process because they can increase data leakage risk.

ScopeNarrow
RuleEXO
RiskData
AuditEvidence

Executive Summary​

This guide describes how Exchange Online transport rules can be used to remove OMEv2 protection and RMS attachment encryption for specific outbound mail scenarios.

This configuration should be used carefully because it can remove encryption protection from sensitive documents.


Business Scenario​

Organizations may need to remove encryption from specific outbound messages when:

  • A trusted external recipient cannot open protected files
  • A business process requires recipient-side labeling
  • Inter-company collaboration requires file reclassification
  • A controlled exception is approved by security or compliance

Important Warning​

Removing encryption from email or attachments can increase data leakage risk.

This should only be used with:

  • Approved recipients
  • Narrow sender/recipient scope
  • Legal or compliance approval
  • Audit review
  • Periodic policy review

Architecture​

Encryption exception flowNarrow transport rule scope
01Internal senderApproved sender or business process requires a controlled encryption exception.
02Exchange OnlineMessage is evaluated by mail flow and transport rule conditions.
03Transport ruleRule removes OMEv2 or RMS attachment protection only for approved scope.
04External recipientApproved recipient receives usable content with audit and exception record.

Control Scope​

ControlRecommendation
Recipient ScopeLimit to approved recipients or domains
Sender ScopeRestrict to internal users or specific groups
Rule ConditionUse clear and auditable conditions
Rule ActionRemove OMEv2 and RMS attachment encryption
ReviewReview periodically with security team

Example PowerShell Pattern​

Connect to Exchange Online.

Import-Module ExchangeOnlineManagement
Connect-ExchangeOnline

Create a transport rule for a specific approved recipient scenario.

New-TransportRule `
-Name "Remove OMEv2 for Approved External Recipient" `
-SentTo "<approved-recipient@domain.com>" `
-FromScope InOrganization `
-RemoveOMEv2 $true

Enable RMS attachment encryption removal.

Set-TransportRule `
"Remove OMEv2 for Approved External Recipient" `
-RemoveRMSAttachmentEncryption $true

Validation​

Validate with test messages:

TestExpected Result
Approved recipientAttachment can be opened without original encryption
Non-approved recipientEncryption remains enforced
Internal recipientRule behavior follows defined condition
Audit reviewRule execution can be reviewed

Governance Requirements​

AreaRequirement
Data ProtectionConfirm sensitivity and business justification
Recipient ValidationConfirm external recipient is trusted
AuditMaintain transport rule change history
Exception ReviewReview exception periodically
Risk AcceptanceCapture business approval

Risk and Mitigation​

RiskImpactMitigation
Overly broad ruleSensitive data exposedLimit recipient and sender scope
No approvalCompliance violationRequire formal exception approval
Recipient misuseData leakageUse trusted recipients only
Forgotten exceptionLong-term exposureReview rules periodically

  • Encryption Exception Request
  • Transport Rule Design
  • Approved Recipient List
  • Security Approval
  • Test Evidence
  • Review Schedule

References​

  • Exchange Online Transport Rules
  • Office Message Encryption
  • Microsoft Purview Information Protection
  • RMS Attachment Encryption

한국어 요약​

이 문서는 Exchange Online transport rule을 사용해 승인된 예외 상황에서 OMEv2 또는 RMS attachment encryption을 제거하는 설계 패턴을 설명합니다.

이 기능은 편의 기능이 아니라 보안 예외 관리 대상입니다. recipient, sender, domain, business justification, approval owner, review schedule이 명확하지 않으면 data leakage risk가 커질 수 있습니다.

Exception Approval Checklist​

CheckpointRequired Evidence
Business reason암호화 제거가 필요한 업무 사유
Recipient trust승인된 외부 수신자 또는 도메인 검증
Rule scopesender, recipient, condition, exception 범위
Security approval보안 또는 compliance 승인 기록
Test evidenceapproved recipient와 non-approved recipient 테스트 결과
Review cadence예외 rule의 정기 검토 주기

Search Keywords​

이 문서는 다음 검색 의도에 답합니다.

  • Exchange Online RemoveOMEv2
  • Remove RMS attachment encryption
  • Office Message Encryption exception
  • Exchange Online transport rule encryption
  • Microsoft Purview Information Protection exception
  • Exchange Online 암호화 제거
  • OMEv2 예외 정책
  • RMS attachment encryption 제거

Contact / Asset Request​

암호화 예외 요청서, transport rule design sheet, 승인 evidence template이 필요하면 Contact and Asset Request를 통해 요청할 수 있습니다.