Create a Transport Rule for Manager Approval
Table of Contents
Expand all | Collapse all
-
- Register and Activate Enterprise DLP on Prisma Access (Panorama Managed)
- Edit the Enterprise DLP Snippet Settings on the DLP App
- Enable Role Based Access to Enterprise DLP on Strata Cloud Manager
- Enable Optical Character Recognition on Strata Cloud Manager
- Enable Optical Character Recognition for Enterprise DLP
-
-
- Create a Data Profile on the DLP App
- Create a Data Profile with EDM Data Sets on the DLP App
- Create a Data Profile with Data Patterns and EDM Data Sets on the DLP App
- Create a Data Profile with Nested Data Profiles on the DLP App
- Create a Data Profile on Strata Cloud Manager
- Create a Data Profile with EDM Data Sets on Strata Cloud Manager
- Create a Data Profile with Data Patterns and EDM Data Sets on Strata Cloud Manager
- Create a Data Profile with Nested Data Profiles on Strata Cloud Manager
- Create a Data Filtering Profile on Panorama
- Create a Data Filtering Profile on Panorama for Non-File Detection
- Update a Data Profile on the DLP App
- Update a Data Profile on Strata Cloud Manager
- Update a Data Filtering Profile on Panorama
- Enable Existing Data Patterns and Filtering Profiles
-
- How Does Email DLP Work?
- Activate Email DLP
- Add an Enterprise DLP Email Policy
- Review Email DLP Incidents
-
- Monitor DLP Status with the DLP Health and Telemetry App
- View Enterprise DLP Log Details on the DLP App
- Manage Enterprise DLP Incidents on the DLP App
- View Enterprise DLP Audit Logs on the DLP App
- View Enterprise DLP Log Details on Strata Cloud Manager
- Manage Enterprise DLP Incidents on Strata Cloud Manager
- View Enterprise DLP Audit Logs on Strata Cloud Manager
- View Enterprise DLP Log Details on Panorama
Create a Transport Rule for Manager Approval
Create a Microsoft Exchange email transport rule to forward an email to the sender's
manager for approval after inspection by
Enterprise Data Loss Prevention (E-DLP)
.Where Can I Use This? | What Do I Need? |
---|---|
|
|
The Microsoft Exchange transport rule for manager approval instructs Microsoft
Exchange to forward the email to the sender's manager when
Enterprise Data Loss Prevention (E-DLP)
cloud service returns a Forward email for approval by end user's
manager
verdict for an email that contains sensitive data. Enterprise DLP
adds x-panw-action: fwd_to_manager
to the email header for inspected emails if Enterprise DLP
renders a
Forward email for approval by end user's manager
verdict. The email is transported back to Microsoft Exchange so a manager can review
the email contents and decide whether to approve or block the email. Any future
emails with this header already included will not be forwarded to Enterprise DLP
again. Instead, Microsoft Exchange will take the action specified in the
transport rule. Microsoft Exchange Active Directory is required to assign a manager to a user. To
successfully send an email for manager approval if sensitive data is detected by
Enterprise DLP
, the sender must have a manager assigned. If no manager is assigned to the sender, then the email is sent to the recipient
because no manager is assigned to approve or reject the email.
Additionally, Microsoft supports email approvals on the web browser-based
Microsoft Exchange only. Approving or rejecting emails on the Microsoft Exchange
mobile application or desktop client is not supported.
- Create the outbound and inbound connectors.Skip this step if you have already created both the outbound and inbound connectors.
- Selectto create a new email transport rule.Mail flowRulesAdd a ruleCreate a new rule
- Configure the transport rule conditions.
- Enter aNamefor the transport rule.
- Add the email message header.Thefw_to_managerheader is added by the DLP cloud service when an email contains sensitive information requiring manager approval.
- ForApply this rule if, selectThe message headers....
- Selectmatch these text patterns.
- ClickEnter Text. When promoted, enter the following.x-panw-actionClickSaveto continue.ClickEnter words. When prompted, enter the following andAdd:fwd_to_managerSelect the word you added. ClickSaveto continue.
Specify the action Microsoft Exchange takes when an email header includes the header added byEnterprise DLP.Microsoft Exchange Active Directory is required to assign a manager to a user. To successfully forward a sender's email if sensitive data is detected byEnterprise DLP, a user must have a manager assigned.If no manager is assigned to a user, then the email is sent to the recipient because no manager is assigned to approve or reject the email.- ForDo the following, selectForward the message for approval.
- Selectto the sender's manager.
ClickNextto continue. - Configure the transport rule settings.
- For theRule mode, ensureEnforceis selected.This setting is enabled by default when a new transport rule is created.
- (Optional) Configure the rest of the transport rule settings as needed.
- ClickNextto continue.
- Review the transport rule configuration and clickFinish.ClickDonewhen prompted that the transport rule was successfully created. You are redirected back to the Microsoft Exchange Rules page.
- Modify the email transport rule priority as needed.To change the priority of a transport rule, select the transport rule andMove UporMove Downas needed.A proper rule hierarchy is recommended to ensure emails successfully forward toEnterprise DLP.
- The email transport rule should always be the highest priority rule relative to the other transport rules required for Email DLP.
- Any email encryption rules not created as part of the email DLP configuration must be ordered below the transport rules created for Email DLP.Enterprise DLPcannot inspect encrypted emails.
- There is no impact in regards to priority between the quarantine transport rules, block transport rule, encrypt transport rule, or any other transport rules that exist.AfterEnterprise DLPinspects and returns the email back to Microsoft Exchange, the appropriate transport rule action will occur based on the email header.