Your encrypted emails seem to be bypassing DLP Cloud Service for Email
search cancel

Your encrypted emails seem to be bypassing DLP Cloud Service for Email

book

Article ID: 220197

calendar_today

Updated On:

Products

Data Loss Prevention Cloud Service for Email

Issue/Introduction

You are testing encryption of Outlook email content, also called Outlook Message Encryption (OME) or Purview, which incorporates Microsoft Information Protection (MIP).

Although it contains the headers from DLP the encrypted content seems to be bypassing DLP without inspection.

Environment

Release : 15.8+

Component : Cloud Service for Email

Cause

MIP was formerly also known as Azure Information Protection (AIP).

OME, MIP and AIP all rely on Microsoft's Rights Management Solution (RMS) for encryption and decryption of email content.

The Cloud Service for Email can inspect RMS-encrypted content, but additional steps are required after initial enrollment of the Cloud Detector.

Resolution

You need to enable the AIP plugin to the DLP Cloud Service by enrolling your AIP Credentials at the Cloud Management Portal.

See this page for documentation on how to do that:

Set up MIP for DLP Cloud Services (broadcom.com)

Additional Information