> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/getting-started/deployment-guides/deploy-account-takeover-resilience-ator/enable-email-redaction.md).

# Enable Sensitive Email Redaction

Sensitive Email Redaction is part of Material Security’s holistic approach to protect sensitive email data at rest. It provides an automated long-tail protection of sensitive content within messages by identifying sensitive categories of email, and redacting those sensitive emails after a configured grace period of time. Should the user need the email after it’s been redacted, they can retrieve it by passing a retrieval authentication challenge. This functionality is designed to enhance data security in the event of a breach, while minimizing disrupting users’ workflows.

## Before You Begin

1. Review the [Sensitive Categories guide](/learn-more/risk-areas/email-data-security/sensitive-categories.md) to understand how this function works and can be applied to emails. Then return here to configure necessary settings.
2. Complete the [Deploy Account Takeover Resilience](/getting-started/deployment-guides/deploy-account-takeover-resilience-ator.md) guide.

## Step One: Set Grace Periods

Grace periods are the amount of time a message will remain unlocked once retrieved[^1]. Once the grace period expires, users must unlock the message again.

Set grace periods at the Global level, then you can set each of your tenants to inherit the same settings or customize that tenant specifically.

{% hint style="success" %}
**Grace Period Optimization**

* Begin with longer grace periods **greater than 6 months**, then slowly decrease them to minimize friction.
* Explicitly create a user group that gets a more lax grace period (e.g. executives)

Starting too short, too quickly can lead to user frustration. Gradually reduce the grace period over time to gauge user adaptation.
{% endhint %}

To set grace periods:

1. From Settings (in the top tool bar) expand **Email Redaction**, then click **Grace Periods:**

<figure><img src="/files/GGFdHIRHvlwCfBnJJ74N" alt="grace periods are located under email redaction in settings" width="227"><figcaption><p>Settings > Email Redaction > Grace Periods</p></figcaption></figure>

2. Configure these three settings:

{% tabs %}
{% tab title="Default Locking Grace Period" %}
The Default Locking Grace Period pertains to [sensitive messages](#user-content-fn-2)[^2] specifically. It sets the amount of time an unlocked sensitive message, for example, an email with a credit card number, will remain in a user's inbox before it's locked again and requires authentication to unlock.

:bulb: [Learn about Material Sensitive Categories here](/learn-more/risk-areas/email-data-security/sensitive-categories.md).

Set the Default Locking Grace Period at the Global level. Tenants inherit the Global setting unless you configure it otherwise.

There may be cases where a specific Sensitive Category requires a shorter or longer locking grace period. Set these in exceptions:

* **Message**: set an exception based on the message's location in sub-folders.
* **Category**: set exceptions based on specific Sensitive Categories, for example you might want to set Social Security Numbers or credit card numbers to a shorter grace period than the default.

You can edit this Grace Period as needed. Changes take effect immediately. In general, we recommend you don't make exceptions at deployment time but rather update them as you get feedback after deployment.

<figure><img src="/files/TuxPvtptFV74eMnWU8JJ" alt="example of a default locking grace period, use the drop downs to choose variants" width="375"><figcaption><p>Settings > Email Redaction > Grace Periods</p></figcaption></figure>
{% endtab %}

{% tab title="Retrieval Grace Period" %}
Retrieval grace periods define how long messages remain in a user's mailbox after they've been retrieved via successful authentication.

Smaller retrieval periods give users just enough time to read an email, but if they're going to need to return to it over a week or a month you should consider a longer period of time.

Once the grace period expires, messages relock.

Choose a **time period** from the drop down, or set a custom period, then click **Save**:

<figure><img src="/files/sFAlPOmtaD5q3bLfAlPZ" alt="example of a retrieval grace period; customize using the drop downs" width="375"><figcaption><p>Settings > Email Redaction > Grace Periods</p></figcaption></figure>
{% endtab %}

{% tab title="Retrieval Challenge Session" %}
Retrieval Challenge Sessions are the amount of time Material awaits before issuing a new challenge after the user successfully authenticates via an MFA challenge. For example, 10 minutes allows users to unlock as many emails as possible in 10 minutes before challenging them again.

We recommend you keep this time period as small as possible.

Choose from an option in the drop down or customize your time limit. If you have a longer session configured in your Identity Provider — that session period takes precedence.

<figure><img src="/files/ThRzefAw4k3zO5zzlU5z" alt="example of a retrieval challenge session; customize using the drop downs" width="375"><figcaption><p>Settings > Email Redaction > Retrieval Challenge Session</p></figcaption></figure>
{% endtab %}
{% endtabs %}

### Grace Period Group and Account Exceptions

Often there are groups or accounts in your organization that require slightly different grace periods based on their roles and work. For example, your finance team probably handles a lot of invoices and you may want to set an exception to the Invoice Sensitive Category only for them. Or maybe you want to set a custom Retrieval Challenge Session for Executives specifically.

You can set Grace Period Exceptions at the Group or Account level in the Explorer:

1. From Settings, click **Back to Workspace**.
2. From the left navigation, click **Explorer**.
3. Click **Groups** or **Accounts**.
4. Next to **Protections**, click the **Edit** icon.
5. Click **Email Data Protection**.
6. Inherit applies the default setting from above. Choose the option to **set a custom or default**, then make your changes and **Save**.

Note, configure Sensitive Category exceptions that **apply to all users** in the **Default Locking Grace Period** screen (see description in [tab](#default-locking-grace-period) above).

<figure><img src="/files/gl75xm7XXyHn4cDtPoGc" alt="moving image navigating to explorer then groups to customize grace periods for groups"><figcaption><p>Customize grace periods for groups in the Explorer</p></figcaption></figure>

{% hint style="success" %}
We recommend you create a user group for executives with a longer grace period than you have set globally.
{% endhint %}

***

## Step Two: Force Unlocks

Occasionally you may need to force unlock an email box, for example to support a litigation-related discovery process or other scenarios when you need to rapidly unlock a portion of messages in an inbox.

Familiarize yourself with this process here:

1. From the Explorer[^3], select the account to unlock messages for.
2. Click **All Actions** (or use the shortcut CMD+K), then select **Force Unlock Messages**.
3. Search for and select the messages to unlock, then click **Force Unlock Messages** again. Note, unlocking a large number of messages can take hours to days.

   <figure><img src="/files/8NR7VZPICNaV4JlwZVkg" alt="force unlock confirmation screen" width="375"><figcaption><p>Force unlock confirmation screen</p></figcaption></figure>
4. Choose how long to leave these messages unlocked before re-locking in the **Re-lock Grace Period.**
5. Optionally, check the box to notify yourself when all the messages were unlocked. You can create additional notifications in Event Subscriptions (click the link in Material to go straight there).
6. Click **Yes, unlock messages**.

{% hint style="warning" %}
**Include Material in your employee** [**offboarding process**](/learn-more/administration/off-board-users.md)

Organizations occasionally need to retrieve copies of email after an employee leaves a company. To support these situations, employee off-boarding must include disabling email redaction and allowing messages to be placed back in the mailbox.

When Email Redaction is enabled for an account, the original copies of sensitive messages are stored in Material’s infrastructure, not the mailbox. Anytime the user or an admin needs to access the messages, they can be restored to the mailbox either via the end user retrieval flow or Admin Force Unlock.

However, if an account has been disabled in Microsoft 365 or Google Workspace, Material can no longer place originals back in the mailbox.

Therefore, it is required that your offboarding flow for employee accounts includes disabling email redaction and allowing all original messages to be placed back in the mailbox before the account is disabled via Microsoft 365 or Google Workspace.

Product Support can work with you to integrate these steps into your existing employee offboarding flow.
{% endhint %}

***

## Step Three: Communicate with Users

Before enabling Email Redaction, let your users know what to expect from the process and how to retrieve sensitive emails. See [Communication Templates](/getting-started/deployment-guides/communication-templates.md) for examples.

***

## Step Four: Enable Email Redaction

Once you've configured the settings above, contact Material Support to enable Email Redaction globally or for the entire tenant.

### **Optionally: Run a Trial Period First**

Optionally, enabled Sensitive Email Redaction for a few accounts or a group first to run a trial. This is a good opportunity to get feedback from users, soft launch the redaction process, and test your communication for a larger, org-wide launch.

1. From the workspace, click **Explorer**.
2. Click **Accounts** or **Groups**.
3. Check the box next an account(s) or group.
4. Click **Edit Settings**.
5. Toggle **Set custom Sensitive Email Redaction** to **On**.

<figure><img src="/files/YNjGcqqAJ7tIakTV2hJt" alt="Email Redaction enabled for a single account or group"><figcaption><p>Email Redaction enabled for a single account or group</p></figcaption></figure>

[^1]: the user has accessed and unlocked an email or its contents through successful authentication

[^2]: Sensitive Categories classify messages as sensitive based on various criteria, for example credit card numbers or encrypted attachments . This way, even if an attacker gets full access to a mailbox, they still can't access the restricted content inside.

[^3]: in the left navigation


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/getting-started/deployment-guides/deploy-account-takeover-resilience-ator/enable-email-redaction.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
