Policy Based Encryption Essentials Administrator Guide
Policy Based Encryption Essentials Administrator Guide
Table of Contents
About Policy Based Encryption Essentials...................................................................................... 3
Introduction to Policy Based Encryption Essentials................................................................................................... 3
Defining a Policy Based Encryption Essentials policy................................................................................................3
Enforcing TLS between your domains and the Email Security Services infrastructure.......................................... 5
Installing the PBE Essentials Email Encryption Add-In.............................................................................................. 6
FAQs on Policy Based Encryption Essentials and Policy Based Encryption Advanced......................................... 7
Legal Notice.......................................................................................................................................... 9
Documentation Legal Notice...........................................................................................................................................9
2
Policy Based Encryption Essentials Administrator Guide
About Policy Based Encryption Essentials
Introduction to Policy Based Encryption Essentials
Policy Based Encryption (PBE) Essentials is an email encryption service that is available to Email [Link]
customers who have the Email Safeguard bundle or are provisioned with the Email Data Protection service.
PBE Essentials is used to encrypt your organization's outbound email that contains sensitive information, and the service
is invoked with the Data Protection policies that you configure. You can set up Data Protection policies to look for specific
keywords within the subject line, body, and attachments of email that is sent from your organization. These keywords
act as flags to trigger encryption. Your users can also use the Email Encryption Add-In, which provides an option within
Microsoft Outlook to add a trigger header to outbound email messages. When messages are flagged for encryption, the
original message and any attachments are sent to the recipient in an encrypted PDF attachment.
See also
Introduction to Policy Based Encryption Essentials
Defining a Policy Based Encryption Essentials policy
Installing the PBE Essentials Email Encryption Add-In
Defining a Policy Based Encryption Essentials policy
Policy Based Encryption Essentials (PBE Essentials) is closely integrated with Email Data Protection (Data
Protection). When an outbound email meets the criteria you define in a Data Protection policy, encryption is triggered.
The emails that trigger the policy are redirected to a specific email address, which routes the email through the encryption
infrastructure and on to the recipient.
Two PBE Essentials templates are available in the Email Data Protection policy list to help you create custom policies for
your organization. Each policy is a set of rules that are designed to analyze your organization's email and encrypt any
email that matches the predefined conditions. You are not required to use a template to create a policy, but the templates
provide relevant default settings to help you maintain consistency. For example, the templates have the recipient group
condition and the redirect to administrator address included as defaults. You configure your policies to encrypt those
emails that meet specific criteria. The criteria are trigger keywords or phrases that the sender types into the body of an
email. For example, you can set up a policy that encrypts any emails that include the word "encrypted". Other triggers for
a policy might include number sequences that appear to be credit card numbers, or particular product or project names.
If the Email Encryption Add-In for Microsoft Outlook is configured in your organization, your users can also insert headers
into their email to trigger encryption.
3
Policy Based Encryption Essentials Administrator Guide
Table 1: Policy Based Encryption Essentials Templates
Template Name and Redirect to Administrator Email Address Description and Actions
PBE Essentials Trigger Template (EU) The recipient receives the original message in an encrypted
secure@[Link] PDF attachment.
This template is set to look for a specific keyword within the
subject, email body, attachments, or the header inserted by the
Email Encryption Add-In of email sent from your organization.
Apply To: Outbound Email Only
Execute If: All rules are met
Action: Redirect to administrator (check the box to stop the
evaluation of lower priority policies)
Notification: Use settings as defined on Email Data Protection
Settings page
PBE Essentials Trigger Template (US) The recipient receives the original message in an encrypted
secure@[Link] PDF attachment.
This template is set to look for a specific keyword within the
subject, email body, attachments, or the header inserted by the
Email Encryption Add-In of email sent from your organization.
Apply To: Outbound Email Only
Execute If: All rules are met
Action: Redirect to administrator (check the box to stop the
evaluation of lower priority policies)
Notification: Use settings as defined on Email Data Protection
Settings page
NOTE
Legacy Policy Based Encryption E and Policy Based Encryption Z templates are available in the portal for
use by existing customers of those services. If you are a Policy Based Encryption E customer who is interested
in using Policy Based Encryption Advanced functionality, speak to your Support Representative about
updating your organization's existing encryption profile. Policy Based Encryption Essentials customers can
only use the Policy Based Encryption Essentials templates.
To define an encryption policy from a template
1. Select Services > Email Services > Data Protection.
2. Click the New Policy from Template option.
3. Select the appropriate PBE Essentials template from the list and click Create. A new PBE Essentials policy is created
at the bottom of your policy list. You may need to adjust the number of policies shown to display your newly created
PBE Essentials policy in the list, or you can manually navigate to the end of the list.
4. Click on the newly created policy name to open it. You can modify the name of the policy if required. The policy will
already have the default setting of Outbound mail only applied, and the default action is Redirect to Administrator.
5. Ensure that you are using the correct template, and then double-check the policy is using the correct redirect address.
6. The first rule in a PBE Essentials template policy is a Recipient Group rule. Note that all PBE Essentials policies
require a recipient group rule to be triggered. By default, the Recipient Group rule in a PBE Essentials template is
configured to trigger if the message recipient does not match an address in the “Default PBE Recipient Group”. By
default, the default group contains “example@[Link]”, so as long as example@[Link] is not a recipient
4
Policy Based Encryption Essentials Administrator Guide
of the message, the rule will always be triggered. This setup works for almost all configurations and therefore rarely
needs to be modified.
7. The PBE Essentials templates contain two additional rules by default that are used to help identify messages
containing sensitive data. The first rule looks for common keywords that may be found in messages that customers
may want to be encrypted. Examples of these keywords are “confidential”, “sensitive”, and “encrypt”. The second such
rule looks for headers that are found in a message if the sender has flagged the message for encryption using the
Email Encryption Add-In. These rules can be left in place, or you can remove them and create your own new rules to
identify messages with sensitive data.
8. Once your PBE Essentials policy is finalized, click the Save button in the bottom right hand corner of the page. Once
saved, you can move the policy to where you want it positioned in your policy list. Note that you must activate the
policy by clicking the Activate link in the far right hand column. Once activated, your policy will typically be in effect in
30-60 minutes.
See also
Introduction to Policy Based Encryption Essentials
Installing the PBE Essentials Email Encryption Add-In
Enforcing TLS between your domains and the Email Security Services
infrastructure
Policy Based Encryption Essentials (PBE Essentials) and Policy Based Encryption Advanced (PBE Advanced) are
Email [Link] services that provide an extra level of email encryption. PBE Essentials and PBE Advanced do not
have any dependencies on other encryption technologies, so you can easily send encrypted email to third-party recipients.
PBE Essentials and PBE Advanced are cloud-based email encryption services that are integrated with the Email Data
Protection service. Email Data Protection policies identify when messages should be encrypted using different types of
triggers. Email messages that trigger encryption policies are routed through an email encryption infrastructure and then on
to the recipients.
NOTE
Outbound messages from your organization that are flagged for encryption by the PBE Essentials or PBE
Advanced services must be routed securely using TLS from your mail servers to the Email Security Services
(ESS) infrastructure. A failure to send outbound messages for encryption over TLS results in a bounce
back to the message sender. To ensure that all outbound messages are routed securely to the ESS
infrastructure, you are advised to enforce TLS encryption on all outbound messages from your domains
that are enabled with PBE Essentials or PBE Advanced. To enable TLS outbound from your domains to
the ESS infrastructure, navigate in the portal to Services > Email Services > Encryption. Within the TLS
Enforcements tab, click on the domains you want to configure, or click on Default Settings. In the section
titled TLS Enforcements between you and the Email Security Service..., ensure that Always enforce TLS
outbound from my domain to the Email Security Services infrastructure is checked.
This diagram shows the portion of the process where TLS encryption is enabled outbound from your domains to the ESS
infrastructure:
5
Policy Based Encryption Essentials Administrator Guide
Figure 1: Always enforce TLS outbound from my domain to the Email Security Services infrastructure
NOTE
To ensure that third-party replies to your PBE Essentials or PBE Advanced encrypted messages are delivered
securely to your domains, you can enable TLS encryption from the ESS infrastructure to your domains. To
enable TLS inbound from the ESS infrastructure to your domains, navigate in the portal to Services > Email
Services > Encryption. Within the TLS Enforcements tab, click on the domains you want to configure, or click
on Default Settings. In the section titled TLS Enforcements between you and the Email Security Service...,
ensure that Always enforce TLS inbound from the Email Security Services infrastructure to my domain is
checked.
This diagram shows the portion of the process where TLS encryption is enabled inbound from the ESS infrastructure to
your domains:
Figure 2: Always enforce TLS inbound from the Email Security Services infrastructure to my domain
Installing the PBE Essentials Email Encryption Add-In
As an administrator for your organization, you can deploy the Email Encryption Add-In to your users' Microsoft Outlook
installations. With the Email Encryption Add-In installed, an Encrypt button is configured to appear in the Microsoft
Outlook ribbon when a user composes or replies to an email. Upon clicking the Encrypt button, this header is inserted
into the outbound email: x-echoworx-encrypt: yes
The Encrypt button can be used as an encryption trigger. A rule condition exists in the Policy Based Encryption
Essentials templates to detect this trigger. The Email Encryption Add-In is installed using an installation wizard. Note that
a reboot is not required after installation.
To install the Email Encryption Add-In for Outlook
1. Download the installer from the following location:
[Link]
[Link]
6
Policy Based Encryption Essentials Administrator Guide
2. Double-click the installer, then click Next.
3. If you accept the End User License Agreement, select I accept the terms of the license agreement and then click
Next.
4. Accept the default destination folder, or click Change... and select the required folder.
The default destination folder is C:\Program Files\Encryption Services.
5. Read the message and then click Install.
6. To complete the installation, click Finish.
NOTE
PBE Essentials customers have access to a particular version of the Email Encryption Add-In that allows users
to set a one-time shared pass phrase on push encrypted email messages.
See also
Introduction to Policy Based Encryption Essentials
Defining a Policy Based Encryption Essentials policy
FAQs on Policy Based Encryption Essentials and Policy Based
Encryption Advanced
The following frequently asked questions provide further information about the Policy Based Encryption Essentials and the
Policy Based Encryption Advanced services.
Table 2: FAQs
Question Answer
Are email messages transmitted Only if your organization has enforced TLS between your mail servers and the Email Security
securely to the Email Security Services (ESS) infrastructure. When an email triggers a Data Protection encryption rule, your
Services infrastructure? email is only encrypted on the first leg of its journey if TLS is enforced from your domain to the
ESS infrastructure. Mail cannot be identified as needing to be encrypted until it is scanned by the
Data Protection service.
Will an encrypted email be When using the pull methodology, emails are not retained indefinitely. Messages expire and are
available indefinitely? no longer available after the configured time. The default expiry period is 30 days.
If a user needs to access emails after this time, their content must have been printed or copied
into another format before expiry. Expired emails cannot be retrieved.
Emails that are sent using the push method are available until they are deleted. They are stored in
the recipient's email system.
Does an email that is sent by an Yes. The PBE service does not intercept any emails that an administrator sends—to avoid policies
administrator bypass encryption? blocking Administrator emails.
We recommend that administrators use a special email address (e.g.
ccadmin@[Link]) for administrative purposes, instead of their own personal email
address. Then all emails that are sent from the personal email address can be encrypted when
they trigger the encryption policy, as normal.
Does the order of Data Protection Yes, the Data Protection service scans emails for each policy in order. When an email triggers a
policies make any difference to policy with an exit action, such as the redirect to administrator action that is used in Policy Based
how Policy Based Encryption Encryption, the email is not scanned for any further policies.
works?
7
Policy Based Encryption Essentials Administrator Guide
Question Answer
The sender of a sensitive email Yes, for Outlook users. The Email Encryption Add-In for Microsoft Outlook has been developed
wants to ensure that it is encrypted to complement the PBE Advanced service. The Email Encryption Add-In puts an Encrypt option
at the touch of a button. Is this in the Outlook toolbar when an email is composed. The Add-In can be downloaded from the
possible? following site:
[Link]
act=download&entp=advanced&locale=en_US&cat=Resource_Center&f=GE/[Link]
See also
Introduction to Policy Based Encryption Essentials
Introduction to Policy Based Encryption Advanced
8
Policy Based Encryption Essentials Administrator Guide
Legal Notice
Documentation Legal Notice
This Documentation, which includes embedded help systems and electronically distributed materials, (hereinafter referred
to as the “Documentation”) is for your informational purposes only and is subject to change or withdrawal by Broadcom
at any time. This Documentation is proprietary information of Broadcom and may not be copied, transferred, reproduced,
disclosed, modified or duplicated, in whole or in part, without the prior written consent of Broadcom.
If you are a licensed user of the software product(s) addressed in the Documentation, you may print or otherwise make
available a reasonable number of copies of the Documentation for internal use by you and your employees in connection
with that software, provided that all Broadcom copyright notices and legends are affixed to each reproduced copy.
The right to print or otherwise make available copies of the Documentation is limited to the period during which the
applicable license for such software remains in full force and effect. Should the license terminate for any reason, it is your
responsibility to certify in writing to Broadcom that all copies and partial copies of the Documentation have been returned
to Broadcom or destroyed.
TO THE EXTENT PERMITTED BY APPLICABLE LAW, BROADCOM PROVIDES THIS DOCUMENTATION “AS
IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING WITHOUT LIMITATION, ANY IMPLIED WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NONINFRINGEMENT. IN NO EVENT WILL
BROADCOM BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY LOSS OR DAMAGE, DIRECT OR INDIRECT,
FROM THE USE OF THIS DOCUMENTATION, INCLUDING WITHOUT LIMITATION, LOST PROFITS, LOST
INVESTMENT, BUSINESS INTERRUPTION, GOODWILL, OR LOST DATA, EVEN IF BROADCOM IS EXPRESSLY
ADVISED IN ADVANCE OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE.
The use of any software product referenced in the Documentation is governed by the applicable license agreement and
such license agreement is not modified in any way by the terms of this notice.
The manufacturer of this Documentation is Broadcom Inc.
Provided with “Restricted Rights.” Use, duplication or disclosure by the United States Government is subject to the
restrictions set forth in FAR Sections 12.212, 52.227-14, and 52.227-19(c)(1) - (2) and DFARS Section 252.227-7014(b)
(3), as applicable, or their successors.
Copyright © 2005-2022 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its
subsidiaries. All trademarks, trade names, service marks, and logos referenced herein belong to their respective
companies.