The identity associated with the original message—either its initial identity or its final identity determined by the Resolve Party stage of the receive pipeline—is assigned to the error message.
The security mechanisms that restrict delivery of messages to authorized subscribing ports and orchestrations also apply to error messages.
A send port that subscribes to an error message, but is not configured with an appropriate decryption certificate, does not receive error messages that result from messaging failures at or before the decrypt stage of the receive pipeline through which the original message entered BizTalk Server. Instead, the failed messages are placed in the Suspended queue.