> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/connect-your-technology/l-p-integrations/proofpoint/proofpoint-tap-for-mdr-setup-for-workbench.md).

# Proofpoint TAP for MDR Setup for Workbench

The Proofpoint Targeted Attack Protection (TAP) for MDR integration allows us to apply our detection strategy to your Proofpoint TAP alerts, and pull them into the Workbench queue for investigation and remediation.

## Prerequisites <a href="#h_01js00j7a8a01mw4r84x6sw23n" id="h_01js00j7a8a01mw4r84x6sw23n"></a>

1. You must have the [Organization Admin role](/workbench-setup/get-started/add-and-manage-users/user-role-rights.md) in Workbench to set up this integration.
2. You must have permissions to create new service credentials in the TAP Dashboard.

## Step 1: Create the TAP Service Credentials for Expel <a href="#h_01js00j7a8nvk63m884mkg9056" id="h_01js00j7a8nvk63m884mkg9056"></a>

You must create a new service credential set for Expel so that we can access your Proofpoint TAP alerts.

1. [Log in to the TAP Dashboard](https://threatinsight.proofpoint.com/auth/new).
2. Navigate to **Settings > Connected Applications**.
3. Select **Create New Credential**.<br>

   <div align="left"><figure><img src="/files/MeKKGg6oTFk4HVIb1xuO" alt="Proofpoint TAP Create new Credential option on the Connected Applications tab." width="563"><figcaption></figcaption></figure></div>
4. Enter a name for the credential set, then select **Generate**.
5. Copy the **Service Principal** and **Secret** values, and save them to a safe place for use in the next section (these values will not reappear and are not retrievable later).
6. Select **Done**.

## Step 2: Add Proofpoint TAP for MDR as a Security Device in Workbench <a href="#h_01js00j7a81vzrqn3ygkvacnh8" id="h_01js00j7a81vzrqn3ygkvacnh8"></a>

Now that you have granted access to Expel, you can configure the integration in Workbench.

1. [Log in to Workbench](https://workbench.expel.io/auth/login?orig=%2F).
2. In the side menu, navigate to **Organization Settings** > **Security Devices**.
3. Select **Add Security Device**.
4. In the search box, type “Proofpoint” and then select the **Proofpoint TAP for MDR** integratio&#x6E;*.*
5. Complete the fields as follows:
   * **Name** - enter a name that might help you more easily identify this integration, such as “CompanyName TAP MDR”; this name will display in Workbench under the Name column, and is a text string that you can filter on.
   * **Location** - enter the location of your integration, for example “cloud;” this is also a text string that you can filter on, so we recommend being consistent with location naming across your Expel integrations.
   * **Proofpoint TAP service principal** - enter the Service Principal value you saved in [Step 1](#h_01js00j7a8nvk63m884mkg9056).
   * **Proofpoint TAP secret** - enter the Secret value you saved in [Step 1](#h_01js00j7a8nvk63m884mkg9056).
   * Select **Save**.

Your device should be created successfully within a few seconds. A few reminders:

* After your connection is healthy, it will take some time for your device to begin polling and receiving data.
* To check on the status, select the downward arrow for your device in the first column and choose **View details**.
* Polling will happen first; data will be received after that. **You must refresh the page to see updates.**
* If your device does not begin polling within 15 minutes, and does not begin receiving data within 30 minutes, [contact our support team for help](/support/how-to-reach-us.md).
* To check if alerts are coming through, navigate to **Dashboards > Alert Analysis**. Scroll to the device you want to check, and select the **Expel Alerts** tab to reveal more alert information. It can take 36 to 72 hours for alerts to appear after setup, as we [tune your device](/workbench-reference/alerts/how-expel-alerts-work.md#device-tuning).

## Step 3: (Optional) Set Up Auto Email Deletion <a href="#h_01jsq7m96qw55b6v8gsp1nkw6c" id="h_01jsq7m96qw55b6v8gsp1nkw6c"></a>

The first two steps of this guide enable Expel to ingest the Proofpoint TAP alerts and investigate any malicious activity. This optional customer configuration lets us use detection strategy to immediately delete any email that Proofpoint TAP identifies as malicious (referenced in Proofpoint TAP as a "Delivered Message" event) *as soon as we ingest its associated alert*.

This means those emails will be assumed as correctly flagged by Proofpoint TAP as malicious, and then deleted for every email user without a SOC investigation. We will instead focus all of our SOC efforts on other types of Proofpoint TAP alerts. However, the Proofpoint TAP alert that references the deleted email will still be available to our SOC analysts and can be correlated to other suspicious activity where needed.

{% hint style="warning" %}
You must have Microsoft 365 or Google Workspace as your email provider to use this feature.
{% endhint %}

1. Set up appropriate permissions within your email provider by selecting one of the links below for instructions.\
   ***If you have already enabled the Remove Malicious Email auto remediation in support of a different integration, you can skip this step (because you will have already set this part up).***&#x20;
   * [Microsoft 365](/workbench-setup/auto-remediations/remove-malicious-email/microsoft-365-remove-malicious-email.md#step-2-add-an-additional-api-permission): Follow *only* the Step 2 section of this guide, then return to this page and continue to step 2.&#x20;
   * [Google Workspace](/workbench-setup/auto-remediations/remove-malicious-email/google-workspace-formerly-g-suite-remove-malicious-email.md#h_01jh5zgcgw8ekzjnfd2tzwjvat): Follow *only* the Step 1 and Step 2 sections of this guide, then return to this page and continue to step 2.&#x20;
2. Still in Workbench, navigate to **Organization Settings** > **My Organizations**.
3. Select the **Configuration** tab.
4. In Configuration Values, locate and enable the action.
   * In the search field, enter "email" to begin your search.
   * Locate the **Auto-Remediate Suspicious Delivered Email Alerts** configuration value (org.preference.email.auto\_remediate\_delivered).
   * Select the checkbox to enable it.
   * Select **Save**.<br>

     <div align="left"><figure><img src="/files/AsWCUcXZ9moIgR6VQzyo" alt="Workbench Auto-Remediate Suspicious Delivered Email Alerts checkbox." width="563"><figcaption></figcaption></figure></div>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/connect-your-technology/l-p-integrations/proofpoint/proofpoint-tap-for-mdr-setup-for-workbench.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
