Manage Secure ICAP
You can forward the payload of Realtime DLP violations to on-premises DLP solutions using the secure Internet Content Adaptation Protocol (ICAP). Through ICAP, Secure Access DLP sends the payload that triggers a Realtime rule violation to an on-premises DLP.
To add Secure ICAP integration, define the ICAP server information in Secure Access as described in this topic.
Once you have established an ICAP connection, by default the payload of all active Realtime DLP rule violations will be sent over ICAP. You can disable this on a rule-by-rule basis; see Add a Real Time Rule to the Data Loss Prevention Policy for more information.