MIP enables you to discover, classify, and protect sensitive information wherever it exists or travels. You can create and use sensitivity labels to protect encrypted and non-encrypted documents.
Register the client application in Azure Active Directory. After registering the new application, obtain the Application (client) ID and Directory (tenant) ID from the overview menu option generated during provisioning Enterprise Application for Trellix DLP usage. Also, obtain the Client Secret Code that is created during application registration on the Azure portal. You will need these values for configuring the registered servers from ePO - On-prem later. For more information, see KB91833.
These credentials have an expiration date and must be renewed.
Preconfigure the Application permissions required for MIP service rights. Also, configure the permissions for these services in the Azure portal:
Azure Rights Management Service
Microsoft Purview Information Protection Sync Service
Configure sensitivity labels and label actions in Microsoft Purview compliance portal. For information about sensitivity labels and how they can help you protect your organization's data, see https://learn.microsoft.com/en-us/microsoft-365/compliance/get-started-with-sensitivity-labels?view=o365-worldwide.
In ePO - On-prem, configure the registered Azure server to connect and use AIP services.
Trellix DLP Network uses MIP credentials for decryption and these credentials are verified during configuration. Information protection is applicable to both Email Protection and Web Protection rules. Trellix DLP Network identifies the AIP encrypted content and decrypt both documents and emails protected by the configured MIP tenant for content inspection. If a protected email also contains protected documents, both the email and documents are decrypted. Both MS Office documents and files protected manually via the MIP classify and protect plugin are supported.
For more information, see Configure the registered Azure server in ePO - On-prem for Microsoft Information Protection with Trellix DLP Network.
Any data violation is shown in the Incident Manager. Trellix DLP Network blocks content that couldn't be decrypted. Trellix DLP Network also monitors MIP decryption events and such Information is shown as events and logs.