You are not signed in to office with an account that has permission to open this workbook

Najin S 0 Reputation points
2025-12-03T19:00:00.35+00:00

User is sending encrypted email to external recipient - Gmail/Yahoo. Email is getting encrypted via DLP policy and encrypt RMS template is being used in the policy. When external recipients are opening any attachment in the email. They are getting below error.

User's image

How do we avoid this with gmail or yahoo users.

Microsoft Security | Microsoft Purview
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. VRISHABHANATH PATIL 1,820 Reputation points Microsoft External Staff Moderator
    2025-12-04T01:19:25.5533333+00:00

    Hi @Najin S

    Thank you for contacting Microsoft QA.

    It seems like you're facing an issue where external recipients are unable to open attachments from an encrypted email sent via a DLP policy when using Gmail or Yahoo. This can happen due to various encryption settings and permissions that need to be in place for these external services to access the protected content.

    Here's how you can potentially resolve this issue:

    Check User Permissions: Make sure that the external recipients have permissions to open the content. This could mean that they need to have an Azure Active Directory (AAD) or Microsoft Accounts associated with the encryption being used.

    RMS (Rights Management Service) Configuration: Ensure that the encryption template used in your Data Loss Prevention (DLP) policy allows external sharing. You may need to configure the Azure Information Protection (AIP) settings that dictate how external users can access protected files. Here’s a resource for reference: Assigning usage rights and access controls to external users.

    Test with Different Email Services: Sometimes, email clients handle protected content differently. Try using other email accounts beyond Gmail/Yahoo to see if the issue persists across different services.

    Evaluate DLP Policy: Review the DLP policy settings to ensure that it aligns with your organization's requirements for external sharing. This could involve adjusting how the policies classify sensitive information.

    External Recipients’ Responsibilities: Inform the external recipients that they may need to sign in with a Microsoft account (or create one if they don't have it) to view the protected content. This is often necessary with Azure RMS-encrypted files.

    If these steps don’t work, it might be helpful to gather more information to pinpoint the root of the issue. Here are some follow-up questions you could ask the customer:

    1. What specific error message are the external recipients seeing when they attempt to open the attachments?
    2. Are the external recipients using the mobile app, web, or desktop version of Gmail/Yahoo?
    3. Have you tested sending the email to different external addresses, and does the issue persist across all email services?
    4. Can external recipients access other secured attachments successfully, or is it only with this specific DLP policy/template?
    5. Is there a need for external recipients to create a Microsoft account to access this content, and have you communicated this to them?

    Hope this helps you get one step closer to resolving the issue! If you have any more questions or need further assistance, feel free to ask!

    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.