Create a remediation policy to tell Email Security - Cloud what to do with emails that are detected as problematic.
In Email Security - Cloud, select Configuration > Policies.
Select Create Policy.
For Integration Type, select Google Workspace API.
For Rule Type, select Remediation.
Enter a policy name and description (optional).
Click Create.
The policy configuration page opens.
Next to Configuration, select Manage.
From the platform drop-down, select Google Workspace.
Select the authorization you previously created.
For Policy Mode, select the mode that best suits your needs:
Manual - Enables the ability to select messages from Email trace and apply actions to them directly
Native - Scans all emails as they are received by Gmail
Retroactive(Auto) - If a link in an email is determined to be harmful at a later point, remediation actions will be taken on those emails in Gmail inboxes
For policy action, choose the actions desired for Advanced Threats (Detected Malicious behavior) and Riskware (Potentially malicious or otherwise risky behavior):
Quarantine - Moves message to a space in Trellix's cloud from which messages can be released
Move - Moves messages to an inbox in Google Workspace
Permanent Delete
Take No Action (Monitor)
Click Save.