AD impersonation detection rules

Prev Next

This section describes how to use Active Directory (AD) synchronization to enhance email threat detection and simplify management of sender impersonation detection rules. This is accomplished by an Office 365 app that acquires Microsoft Office 365 AD data for groups in your organization and matches all email sender display names against AD group and user data. Users in your AD groups can be added as watch lists in AD impersonation detection rules. An alert triggered on the ADD Product Series by an AD impersonation rule contains details about the matched AD impersonation rule.

Requirements for configuring AD impersonation detection rules

Office 365 AD impersonation detection is supported with Microsoft Exchange

Online for mailboxes on Exchange Server 2016 or newer.

Limitations for configuring AD impersonation detection rules

In a hybrid environment―with some users in local AD groups―this feature acquires Office 365 AD data for users in groups hosted in the Microsoft Exchange Online cloud solution only. The script does not acquire data for users in local AD groups.

Task list for configuring AD impersonation detection rules

To configure AD impersonation detection rules, complete these tasks in the order specified:

  1. Use the Azure portal to create a Microsoft Office 365 app, register it as an Azure AD v2.0 endpoint, and configure its permissions. See Registering an Office 365 app and configuring permissions.

  2. Use the appliance Web UI or CLI to configure the app to use the synchronization APIs in Microsoft Graph to manage identity synchronization. See Configuring the Office 365 App Authentication.

  3. Use the appliance CLI to enable Office 365 integration. See <title>Enabling Office 365 integration using the CLI</title>.

  4. Use the appliance Web UI to start the AD synchronization script.

    The first time the script runs, it runs continuously to obtain all the group data from Office 365 AD. Thereafter, the script checks Office 365 AD for group and user changes every 24 hours.

    See Starting the AD synchronization script using the Web UI.

  5. Configure AD sender impersonation detection rules by adding users from AD groups.