Log in to Office 365 as a Global Admin and navigate to the Exchange Admin center.
Select Mail flow, then rules.
Configure a new rule as follows:
Name: Send to Skyhigh Security Cloud Email DLP for inspection
Apply this rule if: The sender is a member of the [security group you created earlier in Step 2]
Click More options.
From the Do the following drop down, choose Redirect the message to then choose the following connector.
Select the Office 365 to Skyhigh Security Cloud Email DLP connector. Click OK.
On the new rule screen, add an exception. Under Except if, choose A message header matches, then pickmatches these text patterns. Click Enter text then type X-SHN-DLP-SCAN . Click OK.
Type success in the text box, then click OK.
Deselect Audit this rule with severity level, then click Save to save the rule.
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Synchronizing DLP policies with Skyhigh Security Cloud > Working with DLP policies in Skyhigh Security Cloud > Protecting email - using Trellix DLP policies in Skyhigh Security Cloud > Enabling inline DLP
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Synchronizing DLP policies with Skyhigh Security Cloud > Working with DLP policies in Skyhigh Security Cloud > Protecting email - using Trellix DLP policies in Skyhigh Security Cloud > Enabling inline DLP
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.14.x Product Guide > Synchronizing DLP policies with Skyhigh Security Cloud > Working with DLP policies in Skyhigh Security Cloud > Protecting email - using Trellix DLP policies in Skyhigh Security Cloud > Enabling inline DLP
Data Loss Prevention (DLP) > Trellix Data Loss Prevention 11.12.x Product Guide - June 2025 > Synchronizing DLP policies with Skyhigh Security Cloud > Working with DLP policies in Skyhigh Security Cloud > Protecting email - using Trellix DLP policies in Skyhigh Security Cloud > Enabling inline DLP