When an Encryption Management Server Web Email Protection user sends a message to an internal user, the message is not encrypted.
This occurs because, by default, messages from Web Email Protection users are treated as Outbound.
In the Encryption Management Server administration console, under Mail / Mail Policy there is an Outbound policy chain.
One of the rules near the top of the Outbound policy chain is:
No Encryption for Regular Internal Users
The Conditions for that rule are:
If all of the following are true:
And none of the following are true:
In many environments, this rule will be matched when a Web Email Protection user sends a message to an internal user and therefore the message will be sent unencrypted.
Symantec Encryption Management Server 3.4.2 and above.
If an internal user does not have Desktop Email Encryption installed, they will not be able to decrypt messages. Therefore the rule No Encryption for Regular Internal Users is necessary for such users.
If all internal users have Desktop Email Encryption installed then this rule can be disabled. This will cause the message to be encrypted if any of the conditions in the rule named Always Encrypt Sensitive Messages are matched. By default, the conditions are:
If all of the following are true:
To disable the rule from the Encryption Management server administration console:
Alternatively, a rule can be added that encrypts messages to internal users who are members of a particular Consumer Policy. For example, all users with Desktop Email Encryption may be members of a particular consumer policy. The conditions for such a rule might be:
If all of the following are true: