TITUS Message Classification Outlook Web App Version 3.8 Administration Guide 2010
TITUS Message Classification Outlook Web App Version 3.8 Administration Guide 2010
Version 3.8
TITUS Message Classification version 3.8
Information in this document is subject to change without notice. Complying with all applicable
copyright laws is the responsibility of the user. No part of this document may be reproduced or
transmitted in any form or by any means, electronic or mechanical, for any purpose, without the
express written consent of TITUS Inc.
TITUS is a registered trademark of TITUS Inc. All other product and company names mentioned
are trademarks or registered trademarks of their respective owners. TITUS Inc. may have patent
applications, trademarks, copyrights or other intellectual property rights covering subject matter
in this document.
At TITUS we work to help businesses better manage and secure valuable corporate information.
Our solutions enable enterprises, military and government organizations to classify information
and meet regulatory compliance by securing unstructured information.
www.titus.com
2
Administration Tool Guide
Table of Contents
1 ABOUT THIS GUIDE .......................................................................................................................... 7
2 INTRODUCTION TO TITUS MESSAGE CLASSIFICATION FOR MICROSOFT OUTLOOK WEB APP .......... 8
2.1 OVERVIEW OF TITUS MESSAGE CLASSIFICATION FOR MICROSOFT OUTLOOK WEB APP................................... 8
2.2 IMPORTANT TERMINOLOGY.................................................................................................................. 9
6 INSTALLING TITUS MESSAGE CLASSIFICATION FOR MICROSOFT OUTLOOK WEB APP .................... 16
6.1 INSTALLING TITUS MESSAGE CLASSIFICATION FOR MICROSOFT OUTLOOK WEB APP .................................... 16
6.2 UPGRADING TITUS MESSAGE CLASSIFICATION FOR MICROSOFT WEB APP ................................................. 19
6.2.1 Uninstalling TITUS Message Classification for Microsoft Outlook Web App .......................... 19
6.2.2 Installing a new version of TITUS Message Classification for Microsoft Outlook Web App ... 20
6.3 APPLYING FIXES OR SERVICE PACKS TO THE MICROSOFT EXCHANGE SERVER ................................................ 21
7.1 ABOUT THE MODIFIED TITUS MESSAGE CLASSIFICATION FOR MICROSOFT OUTLOOK WEB APP LOGON PAGE ... 22
7.2 MODIFYING THE CONFIGURATION CACHE ............................................................................................. 22
3
TITUS Message Classification version 3.8
4
Administration Tool Guide
16 ASSOCIATING POLICY GROUPS WITH CONTROL DEFINITIONS AND CONTROL SELECTION ITEMS ... 86
17.1 USING A REGISTRY KEY TO ENABLE THE CACHING USER PASSWORD METHOD IN PROXY SERVERS .................. 88
5
TITUS Message Classification version 3.8
Format= ............................................................................................................................................... 92
Prefix= .................................................................................................................................................. 92
Postfix= ................................................................................................................................................ 92
TokenPrefix= ........................................................................................................................................ 93
TokenPostfix= ....................................................................................................................................... 93
TokenSeparator=.................................................................................................................................. 93
CONTACT US .......................................................................................................................................... 95
6
Administration Tool Guide
Instructions describing how to deploy and configure TITUS Message Classification for Outlook
Web App on Exchange 2013 are located in a separate document.
1.2 Purpose
This guide explains:
How to configure TITUS Message Classification for Web App to suit your
organizational needs.
How to administer the product using the TITUS Message Classification for Microsoft
Outlook Web App Administration Tool.
TITUS Message Classification for Microsoft Outlook Web App brings the familiar features of the
TITUS client to the Outlook Web App environment. TITUS Message Classification for Microsoft
Outlook Web App is fully interoperable with the Message Classification for Outlook client.
Messages classified in the Message Classification Outlook Web App create the same message
properties as those created with the full Outlook client. This ensures that a message sent from
the Outlook Web App is recognized in the Outlook client and vice-versa.
To suit the unique needs of every organization, TITUS Message Classification for Microsoft
Outlook Web App is completely customizable. This allows your organization to create custom
settings and labels that are relevant to your users.
The screen capture below illustrates an example of the Classification options that can be
implemented into the TITUS Message Classification for Microsoft Outlook Web App user
interface.
8
Administration Tool Guide
Terminology Description
Control Definition A Control Definition defines the Control that is presented to the
user in the TITUS Message Classification user interface. It is an
administrative term used in the Administration Tool. There are
several different Control Definition types, as described in the next
section.
Control Definition Type Dropdown Control: Users can select one value from a dropdown
menu of pre-defined choices. This Control type is ideal for the first
level of classification.
Type-In Control: Users can type in a value. This is ideal if you would
like users to be able to add their own unique classification
properties to the message, such as Keywords to associate with
the message.
Multi-select Control: Users can list several choices and the user is
able to select as many options as applicable.
Control Selection Item A Control Selection Item is a customized label that is associated
with a Control Definition. For example, the Control Definition
Classification can contain Control Selection Items such as
UNCLASSIFIED, CONFIDENTIAL, or SECRET.
Terminology Description
Policy Item In the Administration Tool, individual Policies are called Policy
Items. An example is a Labeling Item. Multiple Policy Items can be
combined under one Policy Group Definition in the Administration
Tool, and then associated with a Control Selection Item.
Policy Group A Policy Group is made up of one or more Policy Items.
Control Structure The Control Structure defines the relationships between Control
Definitions and their Sub-controls. This hierarchy, which is
configured in the Administration Tool, determines how
classifications are presented to the user in TITUS Message
Classification for Microsoft Outlook Web App.
10
Administration Tool Guide
The information in this section reflects the supported software environments at the time of the
product release. To obtain the latest information, log into the TITUS Customer Support portal
and navigate to the Software Environments page.
For Exchange 2010 save the TITUS Configuration file (.tl file) to C:\Program
Files\Microsoft\Exchange Server\V14\ClientAccess\Owa.
1. Review the System Support and Requirements section and perform any updates to your
system that are required.
2. Install or Upgrade TITUS Message Classification for Microsoft Outlook Web App.
3. Configure your system to optimize the performance of TITUS Message Classification for
Microsoft Outlook Web App.
4. Install the TITUS Message Classification for Microsoft Outlook Web App Administration
Tool.
5. Start the Administration Tool and enter your license key information on the License Info
Tab. A license key is required in order to use the TITUS Message Classification for Microsoft
Outlook Web App Administration Tool. This step is only required the first time you open the
TITUS Message Classification for Microsoft Outlook Web App Administration Tool.
6. Create your Control Definitions. These are the Controls that appear on the TITUS Message
Classification for Microsoft Outlook Web App toolbar and Select dialog. For example, you
can have a dropdown Control called Classification.
7. Create your Control Selection Items. These are the choices that appear to users when they
select a Control. For example, the Classification Control can have four Control Selection
Items: NONE, UNCLASSIFIED, CONFIDENTIAL, and SECRET.
8. Create your Policy Groups. Policy Groups contain one or more Policy Items. Policy Items can
be configured to create the Policies that are then applied to individual Control Selection
Items or Control Definitions.
9. Configure the Global Options. These are settings that define, enable, and/or customize the
TITUS Message Classification for Microsoft Outlook for Web App features that will appear to
users in your organization using Outlook Web App.
10. Configure Portion Marking (Ultra Edition feature). Portion marking enables an email author
to apply classifications to individual portions of an email.
11. Create the Control Structure. This is the classification hierarchy that appears to end users. It
is based on the Control Definitions you created in Step 6, but now the Control Definitions
are listed in a hierarchical list. This is how TITUS Message Classification for Microsoft Web
App supports context sensitive labels, where only the Controls relevant to the users
previous Control Selection are presented.
12
Administration Tool Guide
12. Associate Policy Groups with Control Definitions or Control Selection Items. TITUS
Message Classification for Microsoft Web App requires this association in order to apply the
appropriate Policy when the user selects a classification. For example, you may want to
apply a Subject Labeling Policy when a user selects SECRET. Policy Groups can be applied at
the Control Definition or Control Selection level.
13. Save the Configuration File. Save the Configuration file in the correct location.
14. Use a Registry Key to enable the Caching user password method in Proxy Servers (Ultra
Edition Feature Only).
This procedure is only required if you are deploying TITUS Message Classification for
Microsoft Outlook Web App in a Proxy Server environment.
This release of TITUS Message Classification for Microsoft Outlook Web App has not been tested
with any additional Microsoft Exchange configurations, including configurations where hotfixes,
service packs, or rollups have been added to Exchange 2010.
Please check with TITUS by logging onto the support portal at http://support.titus.com before
installing any hotfixes in your Exchange environment. Applying hotfixes may cause TITUS
Message Classification for Microsoft Outlook Web App to stop working.
If you have applied other patches or fixes to your environment, and TITUS Message
Classification for Microsoft Web App no longer works, check the Problem Resolution section at
the end of this guide for further instructions.
If you are not sure what version of Exchange you are running, refer to the following procedures
to locate your Exchange version information.
For instructions on how to update your Microsoft Exchange environment refer to, Applying
Fixes or Service Packs to the Microsoft Exchange Server in this document.
The folder with the highest build number will indicate the current version of Outlook
Web App on your server.
For Microsoft Exchange 2010 SP3 RU7 the current version of Outlook Web App is
14.3.210.2.
14
Administration Tool Guide
TITUS Message Classification for Microsoft Outlook Web App will not be enabled using the
Outlook Web App Light.
The information in this section reflects the supported software environments at the time of the
product release. To obtain the latest information, log into the TITUS Customer Support portal
and navigate to the Software Environments page.
The following procedures assume you have already installed and configured Windows Server
and Exchange Server 2010 with the appropriate service packs and rollups as specified in
Supported Microsoft Exchange Platforms in this guide.
It is recommended you test the installation and settings on a separate test Exchange Server
before installing the product on your production Exchange Server.
During the installation, Internet Information Services (IIS) will be restarted. This may affect
services that depend on IIS.
16
Administration Tool Guide
3. Click the I Agree radio button if you agree to the License Agreement terms.
If the Install button is greyed out you will need to specify the folder into which
Microsoft Exchange is installed.
If the folder is correct, and the button is greyed out, then the files under the OWA folder
(original Microsoft OWA files) have been modified, and will need to be replaced with the
original files. Until the original files are replaced in the OWA folder, the installation will
not continue. This is required to ensure the integrity of the installation of this product.
18
Administration Tool Guide
Before upgrading to a new version of TITUS Message Classification for Web App any previous
versions of the software should be uninstalled.
If you uninstall TITUS Message Classification for Microsoft Outlook Web App, Internet
Information Services (IIS) will be restarted. This may affect services that depend on IIS.
2. Right click on the application and select Uninstall from the Context menu.
3. Click Yes to remove TITUS Message Classification for Microsoft Outlook Web App from
your computer.
If you are migrating from TITUS Message Classification for Microsoft Outlook Web Access V1.6,
2.0 or V3.0, please contact TITUS support ([email protected]). The support organization must
perform this migration for you.
1. Before Upgrading TITUS Message Classification for Microsoft Outlook Web App you
must uninstall the previous version. Refer to, Uninstalling TITUS Message Classification
for Microsoft Outlook Web App in this document for instructions.
3. Install the newest release of TITUS Message Classification for Microsoft Outlook Web
App.
20
Administration Tool Guide
Before applying a fix or service pack to the Exchange Server check the TITUS Support portal
(http://support.titus.com). This site will list the Exchange Server fixes supported by TITUS.
Note: Although this step is not required, TITUS recommends that a copy is saved outside
of the Exchange directory as a precaution.
This change forces TITUS Message Classification for Microsoft Outlook Web App to download
the configuration file every time it is accessed. This will ensure that any changes in the
configuration are captured when you perform a refresh. To undo this change, open the
Configuration.aspx and remove the line that you added. The configuration file is now cached,
and must be cleared manually from your temporary internet files in order for it to be updated.
2. Add the following line as the second line in the Configuration.aspx file:
22
Administration Tool Guide
1. Navigate to the folder that contains the Administration Tool setup file:
TITUSMessageClassificationWebAppAdminTool_2010.msi
The TITUS Message Classification Web App Administration Tool Setup Wizard appears.
4. Use the scroll bar to scroll through the License Agreement until you have read the entire
content.
5. If you agree with the licensing terms, click the I accept the terms in the License
Agreement radio button, and click the Next button.
6. Click the Install button on the next screen to begin the installation procedure.
7. Click the Finish button when the Installation Complete dialog box appears.
24
Administration Tool Guide
If this is the first time you have logged in to a new install or upgrade of TITUS Message
Classification for Microsoft Web App the license information must be entered before
you can proceed. See, Entering License Information for more information and
instructions.
For more information and instructions see, Starting the Administration Tool in this
document.
The License Info tab appears on the left side of the window.
2. Enter the Organization Name provided to you with your License Key in the Organization
Name text box.
3. Enter (copy and paste) the license key in the License Key text box.
4. In the Property Name field, specify the prefix to be used with all TITUS Message
Classification for Microsoft Web App Properties. These properties are visible to the end
user under the Properties dialog box. Typically, you enter your organizations name as
the Property Name.
You can not enter any special characters in the Property Name field. Ensure that the
name contains only letters, numbers, and dots.
26
Administration Tool Guide
3. Open the TITUS Message Classification for Microsoft Web App configuration file
(TMCWA.tl) located in:
C:\Program Files\Microsoft\Exchange Server\V14\ClientAccess\Owa for Microsoft
Exchange 2010
The Administration Tool enables you to define as many Control Definitions as required, giving
users the ability to label an email with as much detail as necessary. TITUS Message Classification
for Microsoft Outlook Web App can force users to select a value for any or all Controls, or
defaults can be defined by the Administrator.
TITUS Message Classification for Microsoft Web App enables Control Definitions to be placed in
a hierarchical structure, so that one Control Definition can be a sub-control of another. This
Control Structure enables TITUS Message Classification for Microsoft Web App to present users
with only the Controls that are relevant to their selections. To illustrate this concept, take the
following example Control Structure:
If the user selects SECRET from the Classification control, then the user is presented with the
sub-control Sensitivity.
28
Administration Tool Guide
1. Click in the text box beside Name and enter a name for the Control Definition.
This is the name that will describe the items that the user can select. For example if the
Control Definition name is Classification the Selection Items would present the users
with a list of Classifications for the message.
Dropdown to create a Dropdown Control. The Dropdown Control allows users to select
one value from a dropdown menu of predefined choices. This Control type is ideal for
the first level of classification.
Dropdown/Type-In to create a Dropdown/Type-In Control. The Dropdown/Type-In
Control allows users to select one value from the pre-defined values in the dropdown or
to type in their own values.
Type-In to create a Type-In Control. The Type-In Control enables users to type in a value.
This is ideal if you would like users to be able to add their own unique classification
properties, such as Keywords to associate with the email.
Multi-Select to create a Multi-Select Control. The Multi-Select Control allows the
Administrator to provide a list of several choices. The user is able to select as many
options as applicable.
Calendar to create a Calendar Control. The Calendar Control enables users to choose a
date from the calendar or an administrator-defined period of time for specific Control
Definitions. This type of Control can be used for creating Control Definitions such as
Retention Period.
The Add Control window adjusts to the selected Control Type. The required properties
for each Control Type are different.
30
Administration Tool Guide
This field is auto-populated with the information entered in the Name field, but can be changed
if required.
1. Click in the text box beside the Caption Attribute and enter a Caption name in the text
box.
This field is auto-populated with the information entered in the Name field, but can be changed
if required.
1. Click in the text box beside the Property Name field enter a Property name in the text
box.
1. Click in the text box beside Tooltip and enter a Tooltip in the text box.
To enable and configure the Portion Marking feature see Section 14, Configuring Portion
Marking (Ultra Edition feature).
The Portion Marking feature is available only in the Ultra edition of TITUS Message Classification
for Microsoft Web App.
By default Portion Marking is set to No.
32
Administration Tool Guide
The order of the Control Selection Items impacts how the On Downgrade Action operates. Refer
to Section 11.5, Changing the order of Control Selection Items for more information.
Ignore to ignore any change that the user makes and enable the downgrade to be
made.
Warn to warn the users that they are downgrading the Control Selection Item. A
message appears asking the user if they want to proceed.
Prevent to prevent the user from downgrading the Control Selection Item. A message
appears informing the user that they may not proceed.
2. Select Edit.
Refer to Creating a Control Definition in this document for more information about
Control Definitions.
3. Select:
34
Administration Tool Guide
2. Select Delete.
You should enter the Control Selection Items in hierarchical order, beginning from the lowest to
the highest classification level. The placing of the Control Selection Items in the tree is especially
important in context to the Downgrade option, where the downgrade action is invoked if a user
attempts to select an Item that is listed above the current Control Selection Item in the Control
Definition tree. Take the following Control Definition tree as an example:
In this case, UNCLASSIFIED takes precedence over NONE, CONFIDENTIAL takes precedence over
UNCLASSIFIED. In the event that you have Warn selected as the On Downgrade Action for
CONFIDENTIAL, if a user attempts to change the Classification of an email from CONFIDENTIAL
to UNCLASSIFIED or NONE, a warning appears.
36
Administration Tool Guide
To create a Calendar Control Selection Item see Section 11.1.2, Adding a Calendar Control
Selection Item to a Control Definition.
Type-in Control Definitions do not require Control Selection Items. The user is permitted to
enter the value for the Control Definition in a text box.
3. Enter a name for the first Control Selection Item, such as UNCLASSIFIED in the Name
text box.
Enter the Control Selection Items in hierarchical order, beginning from the lowest to the
highest classification level.
The order of the Control Selection Items in the tree defines how the Downgrade option
operates. The downgrade action is invoked if a user attempts to select an Item that is
listed above the current Control Selection Item in the Control Definition tree.
4. If required, enter an Alternate Label for the Control Select Item in the Alternate Labels
text box.
For example if you named the Control Selection Top Secret, you could have alternate
label TS. This enables you to use abbreviations in subject labels and body tags.
Repeat these steps to enter more Control Selection Items, such as UNCLASSIFIED,
CONFIDENTIAL, INTERNAL DISTRIBUTION.
1. Right click on the Control Selection item to which you want to add alternate labels and
select Edit.
You can enter as many Alternate Labels as required. Separate them with a carriage
return.
38
Administration Tool Guide
2. Enter a name for the Control Selection Item in the Name text box.
3. Enter a brief description of the Control Selection that aids users in classifying emails in
the Tooltip text box.
4. Select the Manual Date radio button to enable the user to enter a date manually.
5. Select the Today plus radio button to enable the user to choose a date that is
dependent on the current date, plus certain number of days or years from the current
date.
1. Right click on the Control Selection Item that you want to edit and select Edit.
See, Adding Control Selection Items to a Control Definition in this document for more
information.
40
Administration Tool Guide
1. Right click on the Control Selection Item that will appear below the new Control
Selection Item.
See, Adding Control Selection Items to a Control Definition in this document for more
information.
If Force Selection is enabled for the Control Definition, the Make Default selection for the
Control Selection Item is disabled and can not be selected. See, Enabling/Disabling Force
Selection in this document for more information.
1. Right click on the Control Selection Item that you want to set as Default and select Make
Default.
In the example above, emails in Microsoft Outlook for Web App are by default classified
as General Business.
42
Administration Tool Guide
The order of the Control Selection Items in the tree defines how the Downgrade option
operates. The downgrade action is invoked if a user attempts to select an Item that is listed
above the current Control Selection Item in the Control Definition tree. For more information
see, Viewing the On Downgrade Message settings in this document.
3. Select:
Top to move the Control Selection Item to the top of the list.
1. Right click on the Control Selection Item that you want to delete and select Delete.
44
Administration Tool Guide
Grouping Policy Items together into Policy Groups enables the Administrator to set up and
administer the Policy framework.
TITUS Classification for Microsoft Web App provides the option of disabling or enabling task
support. By default task support is enabled. For more information see Section 13.1.2,
Disabling/Enabling Calendar Support.
When task support is enabled, tasks can be classified using TITUS Classification for Outlook Web
App. Not all TITUS Policies can be applied to tasks. See Section 13.1.3, Disabling/Enabling Task
Item Support for more information.
The supported Policies are applied to Calendar items only when Calendar support is enabled.
See Section 13.1.2, Disabling/Enabling Calendar Support for more information.
Body Tagging
Custom X-Header *
Reject
S/MIME Sign/Encrypt
Safe Recipients
Subject Labelling
Warn on Send
3. Enter a name for the Policy Group in the Policy Name text box.
4. To add a Policy Item to the Policy Group, click on the Policy Item name in the Available
text box and click on the move arrow ( ).
46
Administration Tool Guide
The bottom part of the Add Policy Group window displays the options that can be
configured for the selected Policy in the Applied list box.
When you click on a Policy option a brief description of the option is provided.
A Policy Group is made up of one or more Policy Items. Add as many Policy Items that
are required to create the Policy Group.
In order to display additional information fields before or after the message text, TITUS Message
Classification for Microsoft Outlook Web App supports replaceable parameters and additional
formatting options, including HTML.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
Both the Top and Bottom check boxes to have the tags placed at the top and bottom of
the message.
4. Click in the text box beside the Body Tag option and enter the HTML code or plain text
to create the tag.
Or
48
Administration Tool Guide
6. Click in the ellipses button to view the Edit tag / HTML Editor window.
7. Click the dropdown icon ( ) to select the Field Codes to include in the Body Tagging
Policy.
The list of Field Codes displayed reflects the Control Definitions that you created in your
Control Configuration and the built-in field codes. For more information see Field
Codes.
The Policy Group containing the Body Tagging Policy Item must be added to the Control
Definition or Control Selection Item before it is enabled.
Note: HTML formatting in body tags is automatically removed for plaintext messages. If
your organization does not allow HTML in messages, you can still use the Body Tagging
feature. The formatting will be removed by TITUS Message Classification for Microsoft
Outlook Web App when the message is sent.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
2. Click in the text box beside Name and enter a name for the Custom X-Header Attribute.
If you do not enter an X before the name, TITUS Message Classification for Microsoft
Outlook Web App will add it to the message for you. The name should reflect the
information to be embedded in the header.
3. Click in the text box beside the Header Tag option and enter the text to create the tag.
If entering more than one header tag, use spaces to separate the tags, not line breaks or
other control characters.
50
Administration Tool Guide
Or
6. Click the dropdown icon ( ) to select the Field Codes to embed in the Custom X-
Header.
The list of Field Codes displayed reflects the Control Definitions that you created in your
Control Configuration and the built in field codes. For more information see Field
Codes.
7. Select the required Field Codes from the list displayed. You do not have to put a
separator between the options that you choose. If you choose to put a separator, use a
space, not a line break or any other control character.
This Policy is intended for organizations that use both OWA and Microsoft Outlook. The Reject
Policy prevents users from viewing sensitive messages in OWA.
TITUS recommends that a Warn on Send Policy is created to prevent OWA users from authoring
messages that they are not able to view. For more information see Section 12.8.1, Configuring
the Warn on Send Policy.
The Reject Policy can prevent the following items from being viewed based on the classification
selected by the user:
Email messages
Drafts
Tasks
Calendar Items
In Exchange 2010, when conversation view is enabled, conversations will be rejected in the
preview pane if any individual message is rejected.
For Exchange 2010 the Preview Pane will always display the Policy warning message when the
Reject/ OWA Prevent Policy is applied. The default Policy warning message is, This action has
been blocked.See Section 13.6, Viewing the Reject settings for information about how to
configure the Reject options. These settings are used in combination with the Reject Policy to
accommodate your organizations business rules.
52
Administration Tool Guide
Note: The Reject Prevent Policy can only be applied to drop-down Controls.
The Reject Policy requires the full Outlook Web App client. Users who sign on using the Outlook
Web App Light client (also called Basic Outlook Web App client) will not be prevented from
seeing certain messages. See Enabling/Disabling OWA Light in this document for more
information.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
2. Enter the text you wish to be displayed when a user attempts to view an email that is
disallowed. The default message is, This action has been blocked.
4. Click on the dropdown button and enter the required message in the text box.
Note: If the Reject settings in Global Options are enabled (see procedure 13.6, Viewing
the Reject settings for more information) and the Reject Policy is applied to a Control
or Control Selection Item, the warning text set in the Global Option overrides the Policy
message.
S/MIME Sign and Encrypt Policies are only applied when the user has logged in to TITUS
Message Classification for Web App using Internet Explorer. In addition the S/MIME add-on
must be present and enabled.
The Administrator can specify that all messages matching a specified Control Selection Item (for
example, CONFIDENTIAL) are automatically encrypted or digitally signed. TITUS Message
Classification for Microsoft Outlook Web App utilizes the S/MIME capabilities of Outlook Web
App to perform the encryption or signing of the email message. This feature requires the
previous installation of email certificates, or the implementation of a public key infrastructure
(PKI) such as the Microsoft Windows Server 2003 PKI or an Entrust PKI.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
54
Administration Tool Guide
This feature can be used to prevent users from sending emails to domains that are not
specifically trusted. Safe Recipients ensures that recipients are in approved email domains for
the selected classification. For example, a safe recipient policy could specify that INTERNAL USE
ONLY email should only be sent to employees within the organization.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
Ignore to ignore when one or more recipients lack the required privileges to receive the
message. The sender does not receive a warning message.
Warn to warn the sender that one or more recipients lack the required privileges to
receive the message. The user is allowed to send the message after viewing the
warning.
Prevent the user from sending a message when one or more recipients lack the required
privileges to receive the message.
4. Click on Domains.
If you choose to check the recipients against the domain to which they belong, you can
define the allowed domains in this field.
You can define a message that is displayed in the warn and prevent situations. The
default message is, One or more recipients lack the required privileges to receive this
message..
56
Administration Tool Guide
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
Before checkbox to place the tag before the subject of the email or task.
After checkbox to place the tag after the subject of the email or task.
You can select Before and After so that the tag appears before and after the subject of
the email or task.
6. Click in the text box beside the Subject Tag option and enter the HTML code or plain
text to create the tag.
If entering more than one subject tag, use spaces to separate the tags, not line breaks or
other control characters.
Or
58
Administration Tool Guide
9. Click the dropdown icon ( ) to select the Field Codes to configure the Subject Labeling
Policy.
The list of Field Codes displayed reflects the Control Definitions that you created in your
Control Configuration and the built in field codes. For more information see Field
Codes.
10. Click on as many of the values as you would like to appear in the Subject Label of emails
and task sent by your organization. You do not have to put a separator between the
values.
You can create as many Subject Labeling policies as required. Two is the most common
multiple construction one before the subject of the email or task and one after the
subject of the email or task.
When the user selects certain classifications, TITUS Message Classification for Microsoft Outlook
Web App can display a warning dialog. As an example, an organization could display a warning
to users every time they send an email from TITUS Message Classification for Microsoft Outlook
Web App with a classification of SECRET.
The Policy Properties box on the Add Policy Group window displays the configuration
items for this Policy Item.
The default message is, Please ensure that the content of this message complies with
required policy for the selected classification level. Do you wish to continue?.
60
Administration Tool Guide
2. Click the plus icon beside Add-in Settings to view the complete list of options.
By default the TITUS Message Classification for Microsoft Outlook Web App is set to Yes.
62
Administration Tool Guide
Once the email has been classified, the text does not appear automatically on future saves and
sends.
2. Click the plus icon to view the complete list of Select Dialog Settings.
1. Click in the text box beside the Select Dialog Text option.
2. Enter the Select Dialog Text required for the Microsoft Outlook Web App users.
2. Enter the Selection Text required for the TITUS Message Classification users.
The Help option allows the Administrator to provide a description of the available Control
Definitions and Control Selection Items to the Outlook Web App users. When enabled, the Help
button launches a web browser and opens a Help Page. This page typically provides information
about the organizations email classification policy. Development of the Intranet web page is a
customer responsibility.
2. Click the plus icon to view the complete list of Help Option settings.
64
Administration Tool Guide
1. Click in the text box beside Help Button ToolTip and enter the required text.
1. Click in the text box beside Help URL and enter the Help URL in the text box.
Note: In TITUS Message Classification for Microsoft Outlook Web App, you can customize these
messages for particular scenarios at the Control Definition level.
2. Click the plus icon to view the complete list of On Downgrade Message Settings.
This message applies only to Control Definitions that have been configured to enable users to
ignore the warning and send the email. For more information see, Selecting the On Downgrade
Action in this document.
The default message is, You are attempting to downgrade the classification level. Are you sure
you want to do this?.
2. Enter the Downgrade Ask Message for the Microsoft Outlook Web App users to read.
66
Administration Tool Guide
This message applies only to Control Definitions that have been configured to enable users to
prevent users from downgrading the email classification level. For more information see,
Selecting the On Downgrade Action in this document.
The default message is, You may not downgrade the classification level from that of the
original.
2. Enter the Downgrade Prevent Message for the TITUS Message Classification for
Microsoft Outlook Web App users to read.
When a user logs into Outlook Web App Light using OWA Light TITUS Message Classification for
Microsoft Outlook Web App does not operate.
TITUS Message Classification for Microsoft Outlook Web App requires that the full Outlook Web
App client (also called Premium Outlook Web App client) is selected by user when they login. If
you are using form-based authentication, any users who are able to change the default option
from the full Outlook Web App client to Outlook Web App Light client will not see TITUS
Message Classification for Microsoft Outlook Web App. If OWA Light is disabled users will not
have the option to select OWA Light when logging in.
68
Administration Tool Guide
From tasks, right click and perform any action (open, Yes
forward and forward as attachment)
From calendar, right click and perform any action (reply, Yes
2. Click the plus icon to view the complete list of Reject Settings.
70
Administration Tool Guide
2. Click on the drop-down arrow and enter the required Reject Message.
This feature is available only in the Ultra Edition of TITUS Message Classification for Microsoft
Web App.
The default file, TMCWA.tl is distributed to users when the conditions associated with the other
.tl files are not satisfied. The default file always exists at the bottom of the list of files.
72
Administration Tool Guide
4. Enter the name of the .tl file you wish to add in the text box and click the Add button.
The .tl files you have added will appear in the Configuration Files list.
Note that the Configuration files are evaluated from top to bottom. The first
configuration file that contains no conditions or contains conditions that are evaluated
as true is applied to the user.
The order of the configuration files can be edited by selecting and right clicking on a file.
The condition must be evaluated as true in order to distribute the TITUS Configuration file to a
user.
The condition created must be based on an Active Directory Security Group type. Conditions
created based on a Distribution Group type will not be evaluated.
Member of Any to create a condition based on the users membership in any of the
listed AD Groups
Member of All to create a condition based on the users membership in all the listed
AD Groups
Not Member of Any to create a condition based on the users lack of membership in
any one of the listed AD Groups
Not Member of All to create a condition based on the users lack of membership in all
the listed AD Groups
74
Administration Tool Guide
Once you have added the Group Conditions they will appear in the Configuration file list.
3. To add an AD Group right click and select Add Group.
4. In the Add AD Group text box add the Active Directory Group name and click the Add
button.
The Condition is applied to the .tl file. In this example only members of the SECRET or
TOP SECRET AD Groups will receive the SECRET_Clearance.tl.
76
Administration Tool Guide
The condition must be evaluated as true in order to distribute the TITUS Configuration file to a
user.
Matches Any to create a condition based on whether or not the user has one of listed
Attributes
Matches All - to create a condition based on whether or not the user has all of the listed
Attributes
Not Matches to create a condition based on whether or not the user does NOT have
one or more of the listed Attributes
Not Matches All to create a condition based on whether or not the user does NOT
have any of the listed Attributes
Once you have added the Attribute Conditions they will appear in the Configuration file
list.
3. To add an AD Attribute right click and select Add Attribute.
4. In the Add AD Attribute Section enter the Active Directory Attribute Name and Value
and click the Add button.
78
Administration Tool Guide
The Condition is applied to the .tl file. In this example only users who do NOT have the
Disabled and Breach AD Attributes will receive the TOP_SECRET_Clearance.tl.
Once you have enabled Portion Marking for the appropriate Controls (Refer to Section 10.1.6 ,
Enabling/Disabling Portion Marking for instructions), you can use the Portion Marking tab to
configure the feature specific options.
The Portion Marking tab is enabled only if you have purchased the Ultra Edition of TITUS
Message Classification.
You can make your Portion Mark string as simple or as complex as required, depending on the
needs of your organization. Consider the following configuration:
80
Administration Tool Guide
You can see that both Classification and Sensitivity can be assigned as Portion Marks. In the case
of Classification, an Alternate Label is also defined as part of the Portion Mark. Looking at the
classification SECRET, we see that the Alternate Label is defined as S.
For Sensitivity, a Prefix character has been defined as a slash (/). This is defined right in the
Portion Marking string.
Before configuring the Portion Marking feature, Portion Marking for the Controls that you want
to use to create Portion Marks must be enabled. In order to enable this for a Control, edit the
control and select yes for the Enable Portion Marking option. For instructions refer to Section
10.1.6, Enabling/Disabling Portion Marking for a Control Definition.
1. Click in the text box beside Enclosing Brackets and select the bracket type that will
enclose the Portion Mark. Select:
[ (square) to select a square bracket to surround the Portion Mark.
( (round) to select a round bracket to surround the Portion Mark.
{ (curly) to select a curly bracket to surround the Portion Mark.
82
Administration Tool Guide
The Portion Marking String defines the values that will appear in the Portion Mark. You can
choose both the Field Code (Classification fields) and indicate any Alternate Labels for the
selected Field Code.
For example, if you have created a Control Definition that you want to display in a Portion Mark
as an abbreviation such as (S), the Portion Marking string would appear as
{{Classification|Alt=1}}.
Refer to Field Codes for more information about the field code options you can use to create a
Portion Mark.
1. Click on Portion Marking String to enable the ellipses button ( ).
3. Click the dropdown icon ( ) to select the Control Definition to include in the Portion
Marking String.
Only the Controls that are enabled for Portion Marking appear in this dropdown list. To
enable a Control for Portion Marking refer to Section 10.1.6, Enabling/Disabling Portion
Marking for a Control Definition.
1. Click in the text box beside Button Tooltip and enter the Tooltip text.
1. Click in the text box beside Dialog Title and enter the Dialog title text.
1. Click in the text box beside Dialog Text and enter the Dialog Text.
84
Administration Tool Guide
2. Click on the Control Definition that you want to add to the classification hierarchy.
3. Drag and drop the Control Definition to the Control Structure pane of the
Administration Tool.
4. If you want a classification to be a Sub-control, then drop the classification on top of the
Control Selection item to which it applies.
1. Drag and drop the Policy Group on top of the Control Definition or Control Selection
item to which it applies.
2. If you place the Policy Group in the incorrect spot, right click on the Policy Group and
select Remove.
Each Control Definition or Control Selection Item can be associated with multiple Policy
Groups. You can also add the same Policy Definition to multiple Control Definitions and
Control Selection Items. For example, you may wish to apply the Visual Markings
Policy Group to all your Control Selection Items. You can also assign Policy Groups at the
Control Definition level. This is a quick way of applying Policy Groups to all the Control
Selection Items under a Control Definition.
86
Administration Tool Guide
2. In the dialog box that appears, navigate to the required directory to save the
Configuration file.
The TITUS Message Classification for Microsoft Outlook Web App configuration
file must be named TMCWA.tl. If the Configuration file is renamed, TITUS
Message Classification for Microsoft Web App will not operate.
This file contains your custom TITUS Message Classification for Microsoft Outlook Web
App settings, and can be loaded into the Administration Tool at any time. This is done by
clicking Open on the File menu.
This feature is available only in the Ultra Edition of TITUS Message Classification for Web App.
The Registry Key is not required on CAS Servers which act as Proxy Clients.
1. Use Registry Editor create the following Registry Key on the Proxy Server:
88
Administration Tool Guide
Some fields, primarily those related to Body Tags, accept simple HTML formatting tags; while
others accept only plain text tags.
The HTML Editor control is used to allow the Administrator to design the output field, possibly
including formatting, and to select available field codes to insert in the field, the content of
which will be dependent on a variety of properties of the message.
This appendix describes the available Field Codes, when and how they may be used, and
samples of the types of outputs expected.
Those field codes that have no replacement are removed from the field. Substitution is
attempted in the order: built-in field codes, then item properties, then user properties.
Field Codes 89
TITUS Message Classification version 3.6
{{SenderName}}
Replaced with the name of the current account user, as returned by Microsoft Web App. Note
that in some cases, if a message has been composed to appear to come from a different person,
the information supplied by Microsoft Web App for this field code may not be accurate.
{{SenderEmail}}
Replaced with the SMTP email address of the current account user, as returned by Microsoft
Web App if it is available. Note that there may be many occasions where Microsoft Web App
does not provide this information, in which case this field code will be omitted.
{{SentDate}}
Replaced with current date. This field code supports the Format modifier as described in a
later section. Default format is the Long Date format as set in the users Regional Settings.
{{SentTime}}
Replaced with current time, formatted according to the Long Time format as set in the users
Regional Settings.
{{Attachments}}
Replaced with a list of attachment display names in a list separated by commas. Will also
(optionally) display one or more of the attachment classification properties (if the property
names match what is used in the message).
90
TITUS Message Classification for Microsoft Outlook Web App Version 3.6
{{Recipients}}
Replaced with a list of recipient names and SMTP email addresses (if available), one per line.
This is a list of individual recipients, which may have been extracted from distribution lists on
the message addressing.
Advanced formatting of the replacement can be done using the Field Code Formatting.
Alt=
Where Alternate Labels have been set for selection items associated with a control, this
formatting tag can be used to specify the index into the list of Alternate Labels. If an index value
falls out of the range of the Alternate Label list, this modifier is ignored.
Example: You have a property called Classification with a value of UNCLASSIFIED, and one
Alternate Label set as UN. A field code of {{Classification|Alt=1}} will be replaced with UN.
Field Codes 91
TITUS Message Classification version 3.6
Format=
The Format field code modifier supports the following values for year/month/day - any other
characters will be left as is. The Format modifier will be ignored for non-date fields.
The default format is equivalent to "yyyy-MM-dd" where yyyy is replaced by the full year (For
example 2014), yy is replaced by a two digit year (For example 14), MMMM is replaced by the
month name (For example January), MMM is replaced by the abbreviation (for example Jan),
MM is replaced by a 2 digit month number (For example 01), dddd is replaced by a day name
(For example. Monday), ddd requires an abbreviation (For example Mon), dd is replaced by a 2
digit day of month number (For example 06).
Note that special characters (such as | and some others) may yield undesired results.
Administrators are encouraged to test their desired formats carefully before deployment.
Example: You have a Date property called Expire On, with a value of 31 December, 2013. A
field code of {{Expire On|Format=yyyy/MMM/dd}} will be replaced with 2013/Dec/31.
Prefix=
Can be used to put some text or HTML formatting codes before the field code value. If the field
code value is empty or missing, the prefix is also omitted. Note, if HTML codes are used, care
must be taken to ensure valid HTML, including closing tags as required.
Example: You have a property name called "Classification" with a value of UNCLASSIFIED. Enter a
field code {{Classification|Prefix=Classification: }}, highlight the whole text including the curly
brackets and then format using the HTML editor, for example select color red, font 10, will result
in "Classification: UNCLASSIFIED" in red with font 10.
Postfix=
Can be used to put some text or HTML formatting codes after the field code value. If the field
code value is empty or missing, the postfix is also omitted. Note, if HTML codes are used, care
must be taken to ensure valid HTML, including closing tags as required.
Example: You have a property name called "Classification" with a value of UNCLASSIFIED. Enter a
field code {{Classification|Postfix= (Classification)}}, highlight the whole text including the curly
brackets and then format using the HTML editor, for example select color red, font 10, will result
in "UNCLASSIFIED (Classification)" in red with font 10.
92
TITUS Message Classification for Microsoft Outlook Web App Version 3.6
TokenPrefix=
Used only for multi-select properties. Can be used to put some text or HTML formatting codes
before each part of the multi-select value. If the field code value is empty or missing, the token
prefixes are also omitted. Note, if HTML codes are used, care must be taken to ensure valid
HTML, including closing tags as required.
Example: You have a multi-select property called Releasability with a value of CAN,US,UK
(three selections). A field code of {{Releasbility|TokenPrefix=REL TO }} will result in REL TO
CAN;REL TO US;REL TO UK.
TokenPostfix=
Used only for multi-select properties. Can be used to put some text or HTML formatting codes
after each part of the multi-select value. If the field code value is empty or missing, the token
postfixes are also omitted. Note, if HTML codes are used, care must be taken to ensure valid
HTML, including closing tags as required.
Example: you have a multi-select property called Releasability with a value of CAN,US,UK
(three selections). A field code of {{Releasbility|TokenPrefix=<b>|TokenPostfix=</b>}} will
result in CAN;US;UK.
TokenSeparator=
Used only for multi-select properties. Can be used to put some text or HTML formatting codes in
between each part of the multi-select value. If the field code value is empty or missing, the
token separators are also omitted.
By default, the TokenSeparator attribute for the control itself will be used. This modifier allows
for a common separator for user-interface purposes, and a different one for use in specific fields
(for example, custom X-headers).
Example: You have a multi-select property called Releasability with a value of CAN,US,UK
(three selections). A field code of {{Releasbility|TokenSeparator=/}} will result in
CAN/US/UK.
Field Codes 93
TITUS Message Classification version 3.6
The TITUS Message Classification for Microsoft Outlook Web App was working but the toolbar
has now disappeared. How do I get it back?
What has likely happened is that a hotfix or service pack has been applied on the Web App
server. Your first option is to try reinstalling our product. If that doesnt work, then you should
remove any Exchange hotfix and then reinstall our product with a supported Exchange
configuration as listed in Supported Microsoft Exchange Platforms.
Users using Web App cannot see classifications sent from Outlook but can see classifications
sent from Web App. Whats going on?
The problem is likely related to the Property Name field setting in the TITUS Message
Classification for Microsoft Outlook Web App Administration tool. If it is not the same as what
was configured for Property Name in the Message Classification for Outlook clients, then
interoperability between the Outlook and Web App classification products will not work
properly.
Why can some people see the toolbar but others can not?
What has likely happened is that the cache on the machines that do not show the toolbar is
using an old version of a file. A quick way to solve this is to remove the stored temporary
internet files from that machine.
Why do special foreign characters such as PROTG turn into PROT=C9G=C9 on the Web App
client?
You have sent a message from the Outlook client using the TITUS Message Classification for
Microsoft Outlook Web App software, which has a classification of PROTG. This classification
is encoded as PROT=C9G=C9 due to the special character . TITUS Message Classification Web
App is unable to decode this, and displays the encoded string.
94
TITUS Message Classification for Microsoft Outlook Web App Version 3.6
Contact Us
General Information
Phone numbers: Mailing address:
General inquiries: +1 613-820-5111 ext. 127 800-343 Preston Street
Toll Free: +1 866-530-5111 Ottawa, ON
Fax: +1 613-820-5154 CANADA
www.titus.com K1S 1N4
General Email:
[email protected]
TITUS EMEA:
[email protected]
Support
Customer Support: Website Support:
[email protected] [email protected]