Why Revoking External Access Doesn't Block Encrypted Outlook Messages
Question details
The administrator or sender needs to troubleshoot why external recipients retain access to encrypted emails even after external access has been explicitly removed.

- Product
- Microsoft Outlook
- Device & OS
- not provided
- Scenario
- An external user receives an encrypted email and continues to view it through the Office 365 Message Encryption Portal after their access was revoked.
- Observed behavior
- The recipient bypasses the access revocation and successfully opens the encrypted message in the portal, contrary to the expected blocked state.
Ensure you have Exchange Administrator or Global Administrator privileges in your Microsoft 365 tenant, and have access to the Exchange Admin Center and Microsoft Entra ID.
Review Tenant Encryption and Rights Management Settings
Verify that your Azure Rights Management Services (RMS) and Office 365 Message Encryption (OME) configurations correctly enforce access revocation for external users.
When external access is removed, the Message Encryption Portal relies on Azure Rights Management (RMS) tokens to validate permissions. If the token expiration is set too long or offline access is permitted, recipients may still view the message until the cache expires.
Open PowerShell as an Administrator, connect to Exchange Online, and run the 'Get-IRMConfiguration' cmdlet to ensure that your tenant's Information Rights Management is properly enforcing licensing restrictions.
Sign in to the Microsoft Purview compliance portal. Navigate to Information protection > Labels, and review the specific label applied to the encrypted email. Ensure that the 'Assign permissions now' setting explicitly blocks offline access for external users.
If immediate revocation is required, you can use the 'Revoke-AzureADUserAllRefreshToken' PowerShell cmdlet for the specific external guest account to invalidate their current access tokens.

Analyze Conditional Access and Transport Rules
Check if conflicting Mail Flow rules or Microsoft Entra Conditional Access policies are overriding the external access restrictions.
Looking for a Lightweight Alternative to Microsoft Office?
Managing complex Microsoft 365 encryption rules, Conditional Access policies, and admin centers can be overwhelming for everyday tasks. If you need a powerful, free, and straightforward office suite for creating and sharing documents without the administrative overhead, WPS Office is the perfect solution.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install and Launch: Run the installation file and follow the on-screen prompts. Once installed, launch the WPS Office suite.
- 3. Open Office Files Instantly: Drag and drop your existing Microsoft Office files (.docx, .xlsx, .pptx) directly into WPS Office to continue your work without any formatting loss.

Frequently Asked Questions
How long does it take for access revocation to take effect in the OME Portal?
It can take anywhere from a few minutes to up to 30 minutes for revocation changes to fully propagate across the Rights Management Services and the Office 365 Message Encryption Portal.
Can I track if an external user opened the encrypted email before access was removed?
Yes. If your organization has Azure Information Protection Premium licensing, you can use the AIP tracking portal or Purview Audit logs to see when and by whom the encrypted document was accessed.
Why do some external users bypass transport rules for encrypted messages?
Mail flow rules are evaluated before a message is encrypted. If the recipient uses the web-based OME portal, certain client-side restrictions or caching might temporarily bypass those rules if offline access was previously granted by a protection label.




