Using New Outlook on Windows for professional communication and productivity
The exact error is not covered by a current Microsoft known-issue fix; because it occurs for every delegate in both new Outlook and Outlook on the web, verify the shared-mailbox/Purview configuration and then open a Microsoft 365 support case if those checks are clean.
The attachment wording is likely misleading. The accompanying message—“The original message can't be shown right now”—suggests that the modern Outlook service cannot retrieve or process the protected original while constructing the reply, but Microsoft has not documented that as the confirmed cause of this exact error.
1. Test the documented shared-mailbox access path
If webmail was tested by expanding the shared mailbox beneath the user's primary mailbox, perform this distinct test:
- Sign in to Outlook on the web.
- Select the profile picture in the upper-right corner.
- Select Open another mailbox.
- Enter the shared-mailbox address and open it in its own browser tab.
- Open the encrypted conversation there and send the reply.
Microsoft documents Open another mailbox as a workaround for a related condition where encrypted or restricted messages cannot be loaded through delegated shared-mailbox access.^1^
If webmail was already tested with the mailbox open in its own tab, skip this test.
2. Check how Full Access was assigned
An Exchange Online administrator should verify that the affected delegates have Full Access. New Outlook and Outlook on the web support delegates reading IRM-protected messages when they have Full Access; automapping is specifically relevant to classic Outlook.^2^
If Full Access was granted only through a security group, test one user with Full Access assigned directly. Microsoft documents that security-group membership is not expanded for automapping and recommends explicit Full Access assignments when automapping is required.^3^
This is a configuration check, not a documented fix for this exact reply error. Do not remove existing group permissions until direct assignment has been tested.
3. Run the Purview diagnostic and verify the assigned OWA policy
A Microsoft 365 Global Administrator should run the Microsoft Purview Message Encryption diagnostic from the Microsoft 365 admin center. An authorized Exchange Online administrator should then identify the OWA mailbox policy assigned to the affected user and check its IRM setting rather than assuming the default policy applies.^4^
Get-CASMailbox -Identity <DelegateUserAddress> |
Format-List OwaMailboxPolicy
Get-OwaMailboxPolicy -Identity <AssignedPolicyName> |
Format-List IRMEnabled
# Run only if IRMEnabled is False:
Set-OwaMailboxPolicy -Identity <AssignedPolicyName> `
-IRMEnabled $true
Also verify that each delegate signing in to Outlook has a license that supports Microsoft Purview Message Encryption. Because the failure also occurs in Outlook on the web for all users, clearing local Outlook credentials is unlikely to address this case.
4. Check for the cross-tenant sensitivity-label condition
A separate by-design failure applies only when all these conditions are true:
- The encrypted message came from an external organization.
- Your organization enforces mandatory sensitivity labeling.
- The user selects a sensitivity label that itself applies encryption.
In that case, reply using a label that does not apply encryption, such as General. Outlook cannot replace encryption owned by the external sender with encryption from the replying organization.^5^
5. Escalate if the checks pass
If the separate-tab test, direct Full Access test, Purview diagnostic, assigned-policy check, and licensing check do not resolve it, open a Microsoft 365 support request. Include:
- Shared-mailbox address with identifying portions redacted in screenshots
- UTC timestamp of a failed send
- Affected delegate and recipient domains
- Whether the original message is internal or external
- Encryption policy or sensitivity-label name
- Full error details, request/correlation IDs, and any NDR
- Confirmation that both new Outlook and Outlook on the web fail for all delegates
This gives Microsoft Support the data needed to trace the protected-message operation in Exchange Online.
References
- Can't read encrypted or restricted message sent to shared mailbox in ...
- Prevent mailbox delegates from reading protected messages
- Mailboxes to which your account has full access aren't automapped to Outlook profile
- Resolve Microsoft Purview Message Encryption issues
- Users might get an error applying an encrypted sensitivity label when replying to an encrypted message sent from an external organization | Microsoft Support