What Type of Encryption Is Deployed?
Microsoft stores Office 365 customer data in two different states. Data is stored at rest on storage media and in transit from the data center over a network to a customer device. All email and related content are encrypted on disk using BitLocker 256-bit AES Encryption.
BitLocker 256-bit AES Encryption is a combination of full disk encryption designed to protect data for entire disk volumes. It uses the AES encryption algorithm. The Advanced Encryption Standard (AES) is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology (NIST). AES is widely used by the U.S. government as well as governments throughout the globe.
The BitLocker 256-bit AES encryption policies are also applied to all email contents including these types:
- Mailbox database files
- Mailbox transaction log files
- Search content index files
- Transport database files
- Transport transaction log files
- Page file OS system disk tracing/message tracking logs