Configuring Blind carbon copy/Out of band (BCC/OOB) mode

Prev Next

You can integrate blind carbon copy (BCC) mode between O365/EOP and Email Security - Cloud by creating a transport rule and by adding the Internet Protocol (IP) address ranges and domains to an allowlist. The transport rule will BCC all external inbound email to Email Security - Cloud for analysis. Messages from the allowed Email Security - Cloud IP address ranges and domains (such as password reset notifications and alert notifications) will be delivered without the risk of being quarantined by O365.

Important

Due to changes to O365 internal rule processing architecture, content filtering is no longer processed before the BCC rule is triggered. Email Security - Cloud may alert on email that is caught by the O365 spam filter. There is currently no workaround for this situation.

To configure BCC/OOB service:

What you need

  • Administrative access to your O365/EOP account.

  • Administrative access to your Email Security - Cloud instance.

  • The BCC address provided in the Domain Configuration entry in the Email Security - Cloud web portal.

Step 1: Create the BCC transport rule

  1. In the Microsoft Exchange admin center, click Mail flow > Rules.

  2. Click +Add a rule, then select Create a new rule from the drop-down menu.

  3. Enter a name for the rule.

  4. Under the Apply this rule if section, select The sender, then select is external/internal from the drop-down menu.

  5. In the pop-up menu, select Outside of the organization. Click Save.

  6. Click the + button.

  7. Under the new And criteria, select The recipient, then select domain is from the drop-down menu.

  8. Enter the domain that the rule should apply to.

  9. Click Add.

    Note

    If messages from multiple domains will be routed to Email Security - Cloud, repeat this step for all included domains.

  10. Click Save to save the setting.

  11. Under the Do the following section, select Add recipients, then select to the BCC box. A new window appears.

  12. In the User name here field, enter the BCC email address provided in the Domain Configuration entry in the Email Security - Cloud web portal.

  13. Click Save.

  14. Click Next. Leave the rest of the default settings as they are.

  15. Click Next. Verify that the information entered is correct.

  16. Click Finish to save the rule. The screen confirms that the transport rule was created successfully.

  17. Click Done.

Step 2: Add the Email Security - Cloud domain to the allowed list

Note

To ensure that you receive administrative alerts, Trellix recommends adding the domain that sends alerts to the allowed list.

  1. In the Microsoft Exchange admin center, select Other features.

  2. Click the link in the Spam filter row. The Microsoft Defender 365 page opens.

  3. Verify that the “Anti-spam inbound policy (Default)” spam filter's status is "Always on", then click on the policy. A pop-up window appears.

  4. In the pop-up window, click Edit allowed and blocked senders and domains.

  5. Under Domains, select Allow domains.

  6. Click +Add domains and enter fireeyecloud.com as an allowed domain. Click Add domains.

  7. Click Done to save your settings.

  8. Click Save to save the allowed list.