Use Case 3: DLP quarantine
This use case is designed to route the emails with DLP X-Header response “DLP reject” to quarantine. Currently, this use case is supported using header “DLP-Reject”. In a future release, DLP X-Header response “DLP-Quarantine” will be introduced.
Steps
- In Microsoft Exchange admin center page, navigate to Mail flow > Rules. The Rules screen appears.
- Click Add a rule + > Create a new rule. The New transport rule screen appears.
-
On the Set rule conditions page,
- Enter a unique name (ex. DLP Quarantine) for the rule in the Name field.
-
In Apply this rule if* field:
- Select The message headers… from the first drop-down list.
- Then select matches any of these text patterns from the second drop-down list.
- Click Enter text. The specify header name window appears.
- Enter message header X-Forcepoint-DLP-Email and then click Save.
- Click Enter words. The specify words or phrases window appears.
- Enter header text DLP-Reject and then click Save.
-
In Do the following* field:
- Select Redirect the message to from the first drop-down list.
- Then select hosted quarantine from the second drop-down list.
- When you complete setting the Set rule conditions page, click Next.
-
On the Set rule settings page, configure the following settings:
- Select Enforced as Rule mode.
- Select High in Severity.
- Tick Stop processing more rules.
- When you complete setting the Set rule settings page, click Next.
- On the Review and finish page, verify the settings and click Finish.
-
The Transport rule created successfully message appears. Then, click Done.
The inbound mail flow rule for the DLP Quarantine is created.
Note: After creation of the mail flow rule (DLP Quarantine), it might take 30 minutes or more for the new rule to be applied to emails.