You create no-decryption policies for traffic
that you
choose
not to decrypt because the traffic is personal,
sensitive, or subject to local laws and regulations. For example,
you may choose not to decrypt the traffic of certain executives
or traffic between finance users and finance servers that contain
personal information. (Don’t exclude traffic that you can’t decrypt
because a site breaks decryption for technical reasons such as a
pinned certificate or mutual authentication by policy. Instead,
add the hostname to the
Decryption Exclusion List.)