


Make a certificate selection for digital signature and encryption In Select an account, select the account for which you want to configure S/MIME options On the device, perform the following steps: (add select certificate) Use certificates for authentication in Microsoft Intune.How to Create PFX Certificate Profiles in Configuration Manager.Valid Personal Information Exchange (PFX) certificates are installed on the device.Users can't use S/MIME signing and encryption with a personal account such as S/MIME is enabled for Exchange accounts (on-premises and Exchange Online).The following table lists the Windows editions that support Email Encryption (S/MIME): Windows ProĮmail Encryption (S/MIME) license entitlements are granted by the following licenses: Windows Pro/Pro Education/SEįor more information about Windows licensing, see Windows licensing overview. Windows edition and licensing requirements Recipients can only verify the digital signature if they're using an email client that supports S/MIME. Digital signaturesĪ digitally signed message reassures the recipient that the message hasn't been tampered with, and verifies the identity of the sender.

If you try to send an encrypted message to recipients whose encryption certificate isn't available, the app prompts you to remove these recipients before sending the email. Users can only read encrypted messages if the message is received on their Exchange account, and they have corresponding decryption keys.Įncrypted messages can be read only by recipients who have a certificate. Users can send encrypted message to recipients that have an encryption certificate. Users can digitally sign a message, which provides the recipients with a way to verify the identity of the sender and that the message hasn't been tampered with. To read the messages, recipients must have a digital identification (ID), also known as a certificate. S/MIME enables users to encrypt outgoing messages and attachments so that only intended recipients can read them. Secure/Multipurpose Internet Mail Extensions (S/MIME) provides an added layer of security for email sent to and from an Exchange ActiveSync (EAS) account.
