Skip to content
Avanet

Share password-protected files with Sophos Device Encryption

Sophos Device Encryption can encrypt selected files on a managed Windows computer using AES-256 and package them into a password-protected HTML file. The recipient does not need a Sophos client: a supported browser and the separately transmitted password are sufficient.

Quick path: Open the appropriate device encryption policy under My Products > Encryption > Policies, activate the Explorer context menu or the add-in for classic Outlook under Settings, activate the policy and test it with a harmless file. The password is never sent along with the HTML file via the same channel.

Documented size limit: Sophos states that it can protect files up to 50 MB. Neither a limit per file nor an overall limit for multiple attachments can be derived from this. Multi-file scenarios at this limit are therefore tested separately in the agent build used and are not released based on this number.

Choose the right function

This feature protects one or more files on the Windows endpoint. It does not encrypt the entire email or the drive and is not the same as BitLocker. For central management of drive encryption, use Manage BitLocker with Sophos Fusion.

The following procedures also solve other tasks:

The HTML file is a good fit for targeted, clientless file sharing. However, do not assume that it provides central delivery confirmation, message recall, process control, DLP decisions, or a managed message portal. Select the appropriate email product when these capabilities are required.

Requirements before approval

The following points are checked before the pilot:

  • A valid Sophos Encryption license is active in the tenant. Product license check details are explained in How is Sophos Fusion licensed?.
  • The sender is running on a supported Windows endpoint with Device Encryption component version 2.0 or later installed. Current operating-system and agent support is checked using the Sophos Endpoint system requirements and plan lifecycle process.
  • The device encryption policy is assigned to the correct user or group and activated.
  • For the Outlook route, classic Outlook for Windows is used. The add-in does not work in the new Outlook.
  • The recipient can open the HTML file locally in a supported browser. Sophos documents Chrome and Firefox on Windows, macOS and Android, as well as Edge on Windows 10 or newer. The old Internet Explorer information is not a recommendation for a new rollout.
  • A separate secure channel exists for the password, such as an approved password manager, a verified phone call, or another organization-wide approved channel.

The function is part of a device encryption policy, but drive encryption is a separate decision. The Device Encryption is on setting is not enabled solely for file exchange without checking the impact on BitLocker and the recovery process.

Configure the policy precisely

First, the policy name, assignment and previous values are documented. This means that the change can be reversed in a targeted manner without changing other encryption settings.

  1. In Sophos Fusion, open My Products > Encryption > Policies.
  2. Edit an existing pilot policy or create a device encryption policy for the pilot group using Add Policy.
  3. Under Settings go to the Password protect files for secure sharing (Windows only) area.
  4. Set the required settings:
    • Enable right-click context menu shows Create password-protected file in the file context menu.
    • Enable Outlook add-in provides Protect Attachments in the classic Outlook ribbon.
    • Always ask how to proceed with attached files forces users to choose between password-protected and unprotected sending of a message with attachments.
    • Under Excluded domains, only enter complete domain names and separate multiple values with commas, for example example.org,subsidiary.example. The prompt from the previous setting does not apply to such domains.
  5. Save the policy, double-check the correct assignment and ensure that the policy is activated.
  6. Allow the policy to synchronize on the pilot device. After activating the Outlook add-in, Outlook must be restarted.

Excluded domains are not a global release list and not a DLP rule. They suppress the prompt Always ask how to proceed with attached files for recipients of the registered domains. The behavior of a message with both excluded and non-excluded recipients is not clearly described in the current product documentation. Such mixed recipient groups are tested in the specific tenant before approval or avoided organizationally.

Protect file as sender

In Windows Explorer

  1. Select a copy of a harmless test file. It may not contain any customer, personal or access data.
  2. Right-click and select Create password-protected file.
  3. Set a unique, strong password in the dialog that appears and complete the process. There are no unconfirmed minimum lengths or character specifications; the actual displayed requirements of the installed build apply.
  4. Verify that a new HTML file has been created with the encrypted content and that the original test file exists unchanged.
  5. Only send the HTML file via the intended delivery method.
  6. Send the password to the verified recipient via the pre-arranged separate channel.

A folder is not protected directly. Sophos recommends that you first create the folder as a ZIP file and then protect this ZIP file with the function. The ZIP file is simply the content to be encrypted; the password still doesn’t belong in the same message.

In classic Outlook for Windows

  1. Create a new message to a documented test recipient and attach harmless files.
  2. Select Protect Attachments in the Outlook ribbon. Sophos repackages all unprotected attachments into a new HTML attachment with encrypted content.
  3. Set the password according to the dialog and check the recipient, subject and HTML attachment before sending.
  4. Send the message and submit the password separately.

If Always ask how to proceed with attached files is active, Outlook requires a decision for protected or unprotected sending for messages with attachments. This choice does not replace organizational classification: users need to know which files need to be protected and when unprotected sending is permitted.

Open HTML file as recipient

  1. Check the sender and expected file name via the agreed process. Do not open an unexpected HTML file.
  2. Save the HTML attachment locally and open it in a supported browser by double-clicking it. The preview of the email program is not a reliable functional test.
  3. Enter the password received via the separate channel.
  4. Decrypt the included file in the browser and save it to an approved storage location.
  5. Check file name, type and expected test content. In the event of a productive exchange, the normal requirements for retention and deletion then apply.

Recipients can also return a received file using either the same password or a new password, or they can create a new password-protected file. For the operational process, a new, unique password per exchange is preferable; reuse increases the impact of unintentional disclosure.

Pilot and acceptance

A successful positive test alone is not enough. For approval, at least the following cases are documented with time, policy, device, agent version, browser and result:

AreaImplementation and acceptance criteria
Windows ExplorerPackaging a harmless file into HTML. The original file must be preserved and the recipient must be able to open the contents with the correct password.
Classic OutlookRestart Outlook after activating the add-in. Protect Attachments must appear and the HTML attachment must be able to be opened by the recipient.
Password checkThe file must not be decryptable with an intentionally incorrect password. The correct password must then continue to work.
Transmission methodNeither the message nor the file may contain the password. The verified recipient receives it exclusively via the approved separate channel.
Domain exceptionsConfirm with a message only to example.org that the configured exception suppresses the prompt. In a separate test with a close but not excluded domain such as example.net, the prompt must still appear; a vague domain comparison must not take place.
Supported BrowserAt least one actually used, supported browser must open and decrypt the test file.
File sizeTest small files first. Log single and multi-file tests near 50 MB separately and do not derive an undocumented general limit rule from the results.

A separate controlled test is required for mixed excluded and non-excluded recipients. Until this test has been completed with the build in use, do not infer how the product will behave or approve this recipient combination for production.

Troubleshoot systematically

The Explorer menu is missing

First check Windows platform, Device Encryption version 2.0 or newer, policy activation, assignment and Enable right-click context menu. Then wait for the policy synchronization and open Explorer again. If the entry is missing, the local device encryption status is checked instead of repeatedly turning the entire policy off and on.

Protect Attachments is missing in Outlook

Make sure you are running classic Outlook for Windows and not the new Outlook. Then check Enable Outlook add-in, policy assignment and the required Outlook restart. A visible button does not prove that the packaging, password and recipient browser work; the positive test remains required.

The prompt does not appear

Check whether Always ask how to proceed with attached files is active and whether the complete recipient domain is listed under Excluded domains. Entries must be full domains and separated by commas. No rule may be derived from a test with multiple recipient domains without separate proof.

The HTML file cannot be opened

First save the file locally and open it with a documented supported browser. Then check the transmission path, file size, and password channel. If the password is incorrect, stop further attempts until the recipient has verified the sender and the password intended for this exact exchange. If a mail gateway blocks HTML attachments, do not relax its protection without review; use an approved transmission path or a suitable portal process instead.

The password has been forgotten or is no longer available

First check the recipient, the supported browser and the password entry. If the password is still missing afterwards, it can neither be reset nor restored for the existing protected HTML file. Keep the original, unchanged file and create a new protected HTML file from it with a new password. Resend this password only via the approved separate channel. Before re-sharing, confirm that the recipient can open the new protected HTML file in the supported browser with the new password and extract the contents.

Outlook packages multiple attachments unexpectedly

Sophos documents that all unprotected attachments are repackaged into a new HTML attachment. However, the 50 MB specification does not explain how the limit is counted for multiple attachments. Therefore, reproduce the case with smaller, harmless files, record the agent version and result and clarify with Sophos Support if the behavior differs.

Rollback and ongoing operation

During a rollback, only the file sharing function is changed, not the entire device encryption policy:

  1. In the affected policy, set Enable right-click context menu, Enable Outlook add-in and Always ask how to proceed with attached files to the documented previous values.
  2. Empty or reset the Excluded domains list only if no remaining configuration relies on it.
  3. Save policy and have it synchronized on a pilot device.
  4. Reopen Outlook and check that Protect Attachments is no longer offered according to the target status. Also check the Explorer context menu.
  5. Carry out a negative test and document that a new password-protected HTML file can no longer be created using the deactivated method.

Disabling these settings is not described as a recall, password reset, or expiration of already distributed HTML files. The current range of functions does not document any central control for this. Files that have already been created, their copies and separately transmitted passwords are therefore taken into account in the company’s own specifications for the life cycle of information.

The pilot is repeated at least for license changes, agent or Outlook upgrades, a switch to the new Outlook and changes to the browser or mail gateway standard. In addition, policy assignment, responsible person, Excluded domains, password channel and any additional exceptions required are checked regularly.