Using New Outlook on Windows for professional communication and productivity
Hi Dana,
Thank you for confirming that the issue occurs in both new Outlook and Outlook on the web and affects all users of the shared mailbox.
This suggests the problem is related to the shared mailbox’s permissions or its handling of the encrypted message, rather than an Outlook installation or a visible attachment. The attachment error can appear because Outlook treats the protected content from the original encrypted message as part of the reply, even when no regular files are attached.
To resolve the issue, please follow these steps:
- Open the Shared Mailbox Separately
In Outlook on the web:
- Select your profile picture.
- Select Open another mailbox.
- Enter the shared mailbox address.
- Open the encrypted conversation from that separate window and try replying.
- Check and Reapply Mailbox Permissions
- Please ask your IT administrator to connect to Exchange Online PowerShell and replace the example addresses below with the actual shared mailbox and user addresses:
Connect-ExchangeOnline
$SharedMailbox = "******@company.com"
$User = "******@company.com"
- Check the user’s current Full Access and Send As permissions:
Get-MailboxPermission -Identity $SharedMailbox |
Where-Object {
$_.User -like $User -and
$_.AccessRights -contains "FullAccess"
} |
Format-List User,AccessRights,Deny,IsInherited
Get-RecipientPermission -Identity $SharedMailbox -Trustee $User |
Format-List Trustee,AccessRights,IsInherited
Full Access allows a delegate to open and manage the mailbox, while Send As allows messages to be sent as the shared mailbox. Automapping only works when Full Access is assigned directly to an individual user, not through a group.
- If Full Access was assigned through a security group, assign it directly to a test user. If the user already has direct Full Access, remove and re-add it to explicitly enable automapping:
Remove-MailboxPermission -Identity $SharedMailbox `
-User $User `
-AccessRights FullAccess `
-InheritanceType All `
-Confirm:$false
Add-MailboxPermission -Identity $SharedMailbox `
-User $User `
-AccessRights FullAccess `
-InheritanceType All `
-AutoMapping $true
- If Send As is missing, add it:
Add-RecipientPermission -Identity $SharedMailbox `
-Trustee $User `
-AccessRights SendAs `
-Confirm:$false
- Test a New Encrypted Conversation
Send a completely new encrypted email from the shared mailbox and ask the recipient to reply. If the new conversation works, the original encrypted thread may contain an invalid protected-message reference.
- Verify the Encryption Configuration
- Ask your IT administrator to check the tenant’s Information Rights Management configuration:
Get-IRMConfiguration |
Format-List AzureRMSLicensingEnabled,InternalLicensingEnabled,SimplifiedClientAccessEnabled
- Then test the encryption configuration using a licensed user as the sender:
Test-IRMConfiguration -Sender "******@company.com"
- Next, identify the Outlook on the web mailbox policy assigned to the shared mailbox:
Get-CASMailbox -Identity "******@company.com" |
Format-List OwaMailboxPolicy
- Check whether IRM is enabled for that policy:
$Policy = (Get-CASMailbox -Identity "******@company.com").OwaMailboxPolicy
Get-OwaMailboxPolicy -Identity $Policy |
Format-List Identity,IRMEnabled
- If IRMEnabled is False, enable it for the policy assigned to the mailbox:
Set-OwaMailboxPolicy -Identity $Policy -IRMEnabled $true
- If SimplifiedClientAccessEnabled is False, enable it:
Set-IRMConfiguration -SimplifiedClientAccessEnabled $true
- After completing the checks, disconnect the PowerShell session:
Disconnect-ExchangeOnline -Confirm:$false
In case you do not know who is your IT admin, kindly refer to this article: How do I find my Microsoft 365 admin? - Microsoft Support
I hope your issue gets resolved soon. Any updates would be greatly appreciated.