Getting Decryption Error when sending emails with ADRMS rules

Ye Wint Aung 0 Reputation points
2023-06-17T16:31:38.36+00:00

We have an OnPrem exchange server setup with Exchange Server 2013 and Exchange Server 2016 on the same domain with Exchange Autodiscovery.

We also have Active Directory Rights Management 2013 (ADRMS) with simple ADRMS rules (Do not reply / Do not forward / Do not reply all) enabled to both Exchange Server (2013 / 2016) environments.

We have recently got an error when sending emails with the ADRMS rule enabled, and the recipient cannot receive the emails sent with the ADRMS rule but the sender got an Exchange server auto-response with an error "Microsoft Exchange Transport cannot RMS decrypt the message".

The error occurred on every sent with the ADRMS rules, no matter between 2016 mailboxes, 2013 mailboxes, or sending emails across 2013 and 2016 mailboxes vice visa.

Also, we have set the transport decryption setting to "Optional"; "Set-IRMConfiguration -TransportDecryptionSetting Mandatory".

The reason we cannot disable the transport decryption setting to "Disabled" is that we are using TrendMicro SMEX and TrendMicro SMEX cannot scan email with transport decryption set to "Disabled".

https://success.trendmicro.com/dcx/s/solution/1103689-scanning-encrypted-messages-in-scanmail-for-exchange-smex-using-microsoft-ad-rms?language=en_US

Did anyone have a clue how to resolve this issue?

Did anyone have a clue how to resolve this issue?

Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,239 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,392 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
510 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.