DLP Enforce : Decrypted MPIP Content in the Incident Snapshot
search cancel

DLP Enforce : Decrypted MPIP Content in the Incident Snapshot

book

Article ID: 394283

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention Network Prevent for Email Data Loss Prevention Cloud Service for Email

Issue/Introduction

DLP supports the detection of MPIP encrypted files and emails. By default, the Incident Snapshot page only shows the policy violation, not all the body content.

With Data Loss Prevention 16.1, you can view the original email body and you can download the decrypted email file and its attachments.

This feature is not available for Endpoint incidents.

Environment

DLP 16.1

Resolution

To enable viewing and downloading, make sure that the decrypt.mip.message.and.attachments.feature.enabled setting is enabled.

Also ensure that your DLP account has permission to view the MPIP decrypted content.

By default the setting is disabled and you cannot view or download MPIP decrypted content and files until you enable the setting.

The property "decrypt.mip.message.and.attachments.feature.enabled" should be set to "true" in the Enforce.properties file on the Enforce server.

Enforce.properties file will be in the directory: \Program Files\Symantec\DataLossPrevention\EnforceServer\16.1.00000\Protect\config\

Additional Information

https://techdocs.broadcom.com/us/en/symantec-security-software/information-security/data-loss-prevention/16-1/what-s-new-in-data-loss-prevention-16-1/enforce-server-features-in-dlp-16-1.html#_95830c93-6137-4277-9291-cf5e763579d8_section_9