This is the correct behavior. The transport layer processes its decryption before it passes the message to the upper level api, for example WCF, so WCF always receives a message with decryption and cannot intercept the process. Migration security outside of WCF. An encrypted message at the transport level is only registered if you use message protection, because in this case the transport layer simply transmits the message, like WCF, to process it.
source share