DLP with Except if message type is Encrypted is not skipping the encrypted email

Brass Contributor

Robin_Poulose_0-1644463448746.png

 

DLP policy created with the exception to exclude the encrypted email however it dont work , still email is received for approval  

 

5 Replies
Hello, try setting it up the other way around. Meaning, when it contains GDPR + is being shared outside the org. = restrict access or encrypt the content in M365 locations (either block or encrypt using built-in protection or sensitivity labels).
Thanks! But I found another work around , I used message type is PermissionControlled instead of Encrypted.
https://community.spiceworks.com/topic/2306136-transport-rule-not-working
Encrypted: Encrypted messages.
PermissionControlled: Messages that have specific permissions configured.
PermissionControlled :It is usually the emails that have been controlled by information security management services, such as the previous Active Directory Rights Management Service (RMS) and Azure Information Protection (AIP) service.


Hello again, out of curiosity, which encryption type are you using here?
New OME encryption. On outlook Web app we get encrypt button.

@Robin_Poulose 

The key to this is to create a custom DLP policy that looks for the key word(s) used in the Exchange Mail Flow Rule in the Subject (in the case below "Secure:").  This policy needs to be in priority 0 and once matched, stops processing additional DLP policies.  See below:

Todd_Gengenbach_0-1707431933346.png