Inconsistent Detection of MPIP Labels in Encrypted Co-authored Office Files (DLP 16.0.x)
search cancel

Inconsistent Detection of MPIP Labels in Encrypted Co-authored Office Files (DLP 16.0.x)

book

Article ID: 443479

calendar_today

Updated On:

Products

Data Loss Prevention Network Monitor and Prevent for Email and Web Data Loss Prevention Data Loss Prevention Endpoint Prevent Data Loss Prevention Enforce Data Loss Prevention Network Monitor and Prevent for Email Data Loss Prevention Network Monitor Data Loss Prevention Network Monitor and Prevent for Web Data Loss Prevention Network Prevent for Email Data Loss Prevention Plus Suite Data Loss Prevention Network Discover Data Loss Prevention Endpoint Discover

Issue/Introduction

When Microsoft Co-authoring and Encryption are enabled for an Office document, sensitivity label metadata may be stored in a dedicated LabelInfo stream within the encrypted Office file structure. When examining the file with tools such as 7-Zip, this information is typically visible under:

[6] DataSpaces\TransformInfo\LabelInfo

This differs from traditional unencrypted Office documents, where label metadata is often accessible through the standard Office Open XML (OOXML) package structure.

In Symantec DLP 16.0.x, customers may observe that policies using Keyword Matching to identify sensitivity labels behave differently across detection channels. For example, a policy may successfully identify the label on Network Prevent but fail to detect the same label on the Endpoint Agent.

In these cases, the Endpoint Agent may still detect sensitive content within the document, but it may not be able to locate or process the label metadata stored within the encrypted LabelInfo stream. As a result, the label value itself may not be available for keyword matching, even though content inspection continues to function normally.

Environment

Symantec DLP 16.0.x

Cause

The issue is caused by a difference in how Network Prevent and the Endpoint Agent process encrypted Office documents and extract sensitivity label metadata.

In Network Prevent (16.0.x), the server-side Office parser is able to correctly interpret the encrypted document structure and map the LabelInfo metadata into the detection stream. This allows the policy engine to evaluate sensitivity labels using Keyword Matching rules.

In contrast, the Endpoint Agent (16.0.x) relies on a local OOXML plugin that may not fully map the encrypted metadata structure and can fall back to the bundled KeyView engine. While KeyView in 16.0.x can successfully extract decrypted document content, it does not consistently perform the enhanced metadata mapping required for the co-authored label path. As a result, the sensitivity label value may not be exposed to the detection engine as searchable keyword text.

Consequently, Keyword Matching policies that rely specifically on sensitivity label values may fail to trigger, even though the document content itself is correctly extracted and evaluated.

Resolution

To ensure reliable Keyword Matching against MPIP labels in encrypted, co-authored files, an upgrade to DLP 16.1 or later is required. Symantec DLP 16.0.x is approaching End of Support on June 20, 2026, after which it will no longer receive fixes or compatibility updates.

DLP 16.1 delivers a full resolution through an updated KeyView engine and a unified OOXML plugin architecture. This ensures that label metadata is consistently and accurately extracted, making it available for keyword-based policies across all detection components.