I’ve created a denylist dictionary for a CAP policy that matches Titus label metadata. During testing, the rule blocks labelled .docx, .xlsx and .pptx attachments as intended. I confirmed the metadata values by unzipping the Office files and inspecting their custom XML properties.
I haven’t specified a file type under Restrict Content Detection, and no file types are blocked by this policy. My understanding is that the dictionary should therefore be applied to all content the policy can inspect.
The issue is with emails labelled using the same Titus plugin in Outlook Classic. If the email is labelled but has no matching attachment, the CAP rule neither blocks it nor generates a report.
I saved a labelled email as a .msg file and searched it in a text editor for the metadata value in my dictionary, but couldn’t find it. Where does Outlook store the Titus label for an email, and can a CAP content detection dictionary inspect that value? If so, is there a different property or inspection method I should use for the email itself?
The behavior you’re seeing is expected. The Data Classification integration currently detects labels stored in file metadata, but does not detect classification labels applied directly to emails.
I’m not familiar enough with the Titus Outlook implementation to say exactly where the email-level label is stored or whether it is exposed in a way that CAP could inspect. So I’d rather not speculate on that part.
That said, I do see value in extending the detection to cover classification labels applied directly to emails. It’s something worth investigating on our side.
Could you please submit this as a feature request in the Ideas section of the Community? That will allow us to track the requirement and investigate the possibilities for supporting email-level Titus classification.
I have found where the label is in the email properties, under x-titus-metadata-40: and the value is Base64 encoded. I have found a Metadat in the email properties now, under ‘x-titus-metadata-40:’, however it’s Base64 encoded.
Can I make a Dictionary with the Base64 data or can the decoded content be detected?
When I decode the Base64 data it reveals the labels in the metadata, but I’ve not had a successful test to block/report sending.
Just to confirm, you’re using New Outlook with a Web Add-in, correct? I ask because the Titus add-in also triggers when the user clicks Send, the same as ours. That could make this a question of precedence: we inspect and allow the email, then Titus applies the label.
It’s also possible that the EPP agent can’t parse and decode the label metadata, which would mean it can’t detect the label at all.
Either way, I think this is worth investigating on our end.
We’re actually testing on Outlook Classic, because we had issues deploying the Titus add-in on New. Classic is supported until 2029 so will stick with that until Titus add-in on New is more reliable.