Getting Started with Your PGP Encryption Cloud Server (Add on to Email Security.Cloud for email encryption)
search cancel

Getting Started with Your PGP Encryption Cloud Server (Add on to Email Security.Cloud for email encryption)

book

Article ID: 443804

calendar_today

Updated On:

Products

Desktop Email Encryption Drive Encryption Encryption Management Server Endpoint Encryption File Share Encryption Gateway Email Encryption Policy Based Encryption Messaging Gateway Messaging Gateway for Service Providers Messaging Gateway Hardware

Issue/Introduction

Congratulations on your purchase of PGP Encryption Cloud Server!  This is an integration to the Email Security.Cloud offering and allows seamless email encryption with a Secure Inbox portal, Secure PDF, as well as SMIME and PGP Key Encryption! 

This guide outlines the essential steps to get your PGP Encryption Cloud Server up and running at the initial phase! 

Environment

*Email Security.Cloud (ESS) customers adding PGP Encryption Cloud Server (PGP)

*Symantec Messaging Gateway (SMG) customers adding ESS + PGP Encryption Cloud Server

 

Resolution

 

 

Phase 1: Onboarding & Account Setup

After your purchase is complete, you will receive two key confirmation emails to start the process.

 

Confirmation Email 1 (License & Contract):

*Sent from "erp dash donotreply at broadcom dot com".
*Action: This email provides the link to the Broadcom Support Portal.
If you are a new user, follow the instructions to create your account on the above portal.
*It also contains information on product maintenance and license details.

Confirmation Email 2 (Delivery):

*Contains your specific contract information, SKU listings, and product descriptions
*Your product will be listed as “Policy-Based Email Encryption Advanced PGP Cloud” or a similar name.  You may also see the name show up as “Gateway Email Encryption”.

 

 

Phase 2: Provisioning & Credentials

Once you have processed the initial emails, your instance will need to be prepared for you.

*Complete the Provisioning Form: You must fill out the provided provisioning form to start the creation of your secure portal instance.  This provisioning form was provided to you as part of the purchase.  If you have not received this form, reach out to your sales team who is currently helping you with this purchase. 

*Wait Time: The provisioning process typically takes 3-5 business days. If you would like it expedited, you will want to submit two support cases:  One to the Email Security.Cloud team, and one to the PGP Encryption Support team.  They will then collaborate to get the instance running as soon as possible. 

*Receive Credentials: After the provisioning has been completed for PGP Encryption Cloud Server, you will receive a third email with your admin portal login details. 
Important: Login immediately upon receipt as these credentials will expire.
You will be required to change your password during your first sign-in. 
The PGP Encryption Cloud Server credentials email will look similar to the following:

The email will include everything you need to login to the secure portal.

SMG Customers: If you are an SMG customer, and new to ESS and PGP, the process above will also include provisioning the Email Security.Cloud (ESS) instance as well as PGP Encryption Cloud Server.

Note: It is not possible to route email from SMG to PGP Encryption Server alone. ESS is needed due to the secure infrastructure being utilized.
Once ESS is provisioned for you, SMG email can be routed to ESS, and then ESS can in turn be routed go PGP Encryption Cloud Server.

 

Phase 3: Configuration & Go-Live

After logging in, you can begin the setup process. 

*Customization: Configure your branding and policy settings within the portal. 
For more information on the branding, see the following article:

436388 - Customizing the Web Email Protection templates for PGP Encryption Server 11.5 and above (Symantec Encryption Management Server)

The branding are an important part of the end-user experience and it will give your clients familiarity with your brand.  If the default is fine, no further action is needed.
Once you have the branding topic completed, you can move into the finalizing integration of ESS to PGP Encryption Cloud Server! 


*Finalizing Integration: Once your configuration is correct, and if you have not already done this, open a support ticket (Make sure the ticket is “Technical”, not “Non-technical”.  
If you open as “Non-technical, this will go to Customer Care who will not be able to validate the technical aspects of the software with you)  with the ESS team to point the ESS product to the PGP Encryption Cloud Server for mail processing. 

Once you receive the above email to login to the PGP Encryption Server, you can then submit additional support cases to then route email to the proper flow following an ESS-to-PGP, or SMG-to-ESS-to-PGP flow.

To receive assistance with this, submit the following two cases:
Case 1: "Need to forward email from ESS to PGP Encryption Cloud Server (ESS Team)" (Log this under Email Security.Cloud)
Case 2: "Need to forward email from ESS to PGP Encryption Cloud Server (PGP Team)" (Log this under Gateway Email Encryption)

If you also own SMG and added the ESS+PGP SKU/bundle, submit a third case to the SMG team and they can assist with routing the emails properly:
Case 3: Case 1: "Need to forward email from ESS to PGP Encryption Cloud Server (SMG Team)" (Log this under Symantec Messaging Gateway)

Our respective teams will work together to ensure that all components are ready and working. 
The PGP Encryption Team will also consult with any additional settings that may be needed to ensure you are ready to go.

 

*Support: Now that you have PGP Encryption Cloud Server, if you have any questions related to the PGP side, any new questions and topics you need assistance with should be logged as a support case to the PGP Encryption Support team.  When you log your case, be sure to choose “Gateway Email Encryption” from the product list.  This ensures your request is routed to the specialized Encryption support team.  

If you do not have “Gateway Email Encryption” as the product, ensure you have added your Site ID to your Broadcom Support ID.

If you are still unsure how to log a support ticket to the proper teams, see the following article:

209191 - Opening a case for Endpoint Encryption, Endpoint Protection and other Enterprise Security Solutions

 

Quick Reference: Common Questions

Question: Are emails transmitted securely?
Answer: Yes, but only if your organization enforces TLS between your mail servers and the Email Security Services (ESS) infrastructure.

Question: How long are encrypted emails available?
Answer: If using the "pull" method, the default expiry is 30 days. If you need them longer, you must save them before this window closes. Emails sent via "push" method remain until deleted by the recipient.

Question: Does an administrator bypass encryption?
Answer: Yes, the PBE service does not intercept administrator emails to prevent policy conflicts. It is recommended that administrators use a specific dedicated email address (such as, pgpadmin@example.com) for administrative tasks.  Then when you send email, you will know not to use the “pgpadmin” email account, or whatever email address you choose. The email address is only an example, use whatever email address you would like. 

Question: Can I encrypt at the touch of a button?
Answer: Yes, for Outlook users. Download the Email Encryption Add-In to add an "Encrypt" option directly to your Outlook toolbar. 

Question: Does policy order matter?
Answer: Yes. Data Protection services scan policies in order. If an email triggers a policy with an exit action (like redirection), it will not be scanned for subsequent policies. 

For more information on policy migration, check the official Broadcom documentation.

 

Additional Information

Please Note: If the customer has SMG On premise, then it is not possible to route mail from there to the PGP Encryption Cloud Server.
The reason for this is Broadcom manages the entire instance of PGP Encryption Cloud Server within our own infrastructure.
That being the case, we do not allow on premise solutions to then route to our cloud servers.
 
This is something we are looking into for the future, but currently, the only way we allow this is with the ESS (Email Security.cloud) offering.

446663 - Using the Secure Portal Account for PGP Encryption Cloud Server (Web Email Protection)