Skip to main content
McAfee Enterprise MVISION Cloud

Configure Passive Email DLP for Gmail

Skyhigh CASB's email passive mode Data Loss Prevention (DLP) solution is designed to scan email as it is sent by a user. When a Gmail user sends an email, G Suite sends send a copy of the email to Skyhigh CASB for analysis. You must configure Gmail to use Skyhigh CASB passive email DLP.

Prerequisites

Before you begin, make sure that you have:

  • A G Suite Enterprise account. (G Suite for Business will not work.)
  • An admin account to the G Suite tenant.
  • An Skyhigh CASB tenant

Configure Passive Email DLP for Gmail 

Perform the following steps in both the Google Suite administrator console and Skyhigh CASB.

To configure Gmail: 

  1. Log in to Skyhigh CASB. 
  2. Go to Settings > Service Management and click Add Service Instance.
  3. Select Gmail, enter a name for this new instance, and click Done.
  4. Select Configure for the new instance. 
  5. Domains. Enter the public domains that Skyhigh CASB DLP will accept for Email DLP. 

NOTE: This list of domains is shared with other Email DLP services (for example, Exchange).

1_add DLP configuration.png
 

  1. Copy the journal mailbox, as you need this later. Do not click Next yet.

    2_Passive Email DLP.png
  2. Log in to the G Suite admin console at https://admin.google.com) and go to Billing. Make sure that the license is GSuite Enterprise. (This is mandatory.)

    1_GSuite.png

  3. Go to Home > Apps > GSuite > Gmail.

    2_settings.png

  4. Select Advanced Settings.

    .3_quarantines.png

  5. On the General Settings tab, find the Routing section

  6. For Third-party email archiving, select Configure
    4_routing.png

  7. Enter a description for this third-party email archive.

  8. Paste the journal mailbox you copied from Skyhigh CASB under Send journal messages to this email address.

    5_add setting.png

  9. Return to Skyhigh CASB.
  10. Under Passive Email DLP, select the checkbox for I have set up journaling in Gmail and have verified that envelope-journaled messages will be sent to the address above. Then click Next.

    3b_PassiveDLP.png
     
  11. Review the configuration and click Done.

    4b_Summary.png
  • Was this article helpful?