You can integrate Inline mode (without AV/AS) between O365/EOP and Email Security - Cloud by creating mail flow rules, creating partner connectors, and adding the Email Security — Cloud IP ranges and domains to the allowed list in order to route all external inbound email to Email Security — Cloud for analysis. The allowed list enables rules allow clean messages sent from Email Security — Cloud to be delivered without the risk of being quarantined by O365. The mail flow rule and connector route all external inbound email to Email Security — Cloud for analysis. Malicious email is blocked while non-malicious email is re-routed back to O365/EOP for delivery.
You can select the following actions for spam, depending on how spam is treated in O365:
Spam is sent to the Admin Quarantine: When O365 is used in conjunction with the Admin Quarantine, spam is routed to the Admin Quarantine before email is routed to Email Security — Cloud. When spam is released from the Admin Quarantine, it is routed through Email Security — Cloud before delivery to the recipient's mailbox. It is possible that spam released by a user may be quarantined in Email Security — Cloud instead of being delivered to the recipient mailbox. All email is scanned by Email Security — Cloud before the recipient can access the email. Trellix recommends configuring the Admin Quarantine digest when you use this mode.
Spam is sent to the Junk Mail folder: When O365 is used in conjunction with the Junk Mail folder, email is routed through Email Security — Cloud before spam content policies are applied. This means that Email Security — Cloud may alert on spam that ends up in the recipient's Junk Mail folder. All emails are scanned by Email Security — Cloud, but if your organization wants to avoid alerts for emails delivered into the Junk Mail folder, Trellix recommends using the Admin Quarantine.
To configure Inline mode:
What you need
Administrative access to your O365/EOP account.
Administrative access to your Email Security — Cloud instance.
Step 1: Add the Email Security — Cloud domain to the allowed list
Note
To ensure that you receive administrative alerts, Trellix recommends adding the domain that sends alerts to the allowed list.
In the Microsoft Exchange admin center, select Other features.
Click the link in the Spam Filter row. The Microsoft Defender 365 page opens.
Verify the default inbound spam filter's status is "Always on", then click on the policy. A pop-up window appears.
In the pop-up window, click the Edit allowed and blocked senders and domains menu option.
Under Domains, select Allow domains.
Click +Add domains and enter
fireeyecloud.comas an allowed domain. Click Add domains.Click Done to save your settings.
Click Save to save the allowed list.
Step 2: Create the IP allowed list rule
Note
Trellix recommends creating an IP allowed list rule to prevent O365 rate limiting from Email Security - Cloud.
In the Microsoft Exchange admin center, select Other features.
Click the link in the Connection Filter row. The Anti-spam policies page in Microsoft Defender 365 opens.
Select the Connection filter policy.
Click Edit connection filter policy.
Enter the first IP address corresponding with the geographic region of your Email Security — Cloud account in the Always allow messages from the following IP addresses or address range entry box. Repeat this step for the remaining IP addresses.
Email Security — Cloud region
MX records
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save to save the rule configuration.
Step 3: Create an Inbound connector
Note
You must create an inbound connector to O365 in order for O365 to process messages after an Email Security - Cloud scan.
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click +Add a connector button to create a new connector.
Set the Connection from value to Partner organization.
The default Connection to value is Office 365. Click Next.
Enter the connector name and description (optional).
Verify that the Turn it on checkbox is selected. Click Next.
Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
Enter the first sender IP address corresponding with the geographic region of your Email Security - Cloud account. Click the + button. Repeat this step for the remaining IP addresses.
Email Security — Cloud region
MX records
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Next.
Verify that the Reject email messages if they aren't sent over TLS option is selected. Click Next.
Verify that the connector settings have been correctly configured, then click Create connector.
Click Done.
Step 4: Create an Outbound connector
Note
You must create an outbound connector in O365 in order to deliver mail to Email Security - Cloud for scanning.
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click the +Add a connector button to create a new connector.
Set the Connection from value to Office 365.
Set the Connection to value to Partner organization. Click Next.
Enter the connector name and description (optional).
Verify that the Turn it on checkbox is selected. Click Next.
Verify that the Only when I have a transport rule set up that redirects messages to this connector option is selected. Click Next.
Select Route email through these smart hosts.
Enter the first smart host value corresponding with the geographic region of your Email Security - Cloud account. Click the + button. Repeat this step for the remaining smart host values.
Email Security — Cloud region
Smart host
USA
primary.us.email.fireeyecloud.com
alt1.us.email.fireeyecloud.com
alt2.us.email.fireeyecloud.com
alt3.us.email.fireeyecloud.com
EMEA
primary.emea.email.fireeyecloud.com
alt1.emea.email.fireeyecloud.com
alt2.emea.email.fireeyecloud.com
alt3.emea.email.fireeyecloud.com
APJ
primary.ap.email.fireeyecloud.com
alt1.ap.email.fireeyecloud.com
alt2.ap.email.fireeyecloud.com
alt3.ap.email.fireeyecloud.com
USGOV
primary.us.etp.fireeyegov.com
alt1.us.etp.fireeyegov.com
alt2.us.etp.fireeyegov.com
alt3.us.etp.fireeyegov.com
CA
primary.ca.email.fireeyecloud.com
alt1.ca.email.fireeyecloud.com
alt2.ca.email.fireeyecloud.com
alt3.ca.email.fireeyecloud.com
Click Next.
Verify that the Always use Transport Layer Security (TLS) to secure the connection (recommended) option is selected.
Verify that the Issued by a trusted certificate authority (CA) option is selected. Click Next.
Enter the email address that corresponds to the geographic region of your Email Security — Cloud account, then click +.
Email Security — Cloud region
Email address
USA
o365@validate.fireeyecloud.com
EMEA
o365@validate.emea.fireeyecloud.com
APJ
o365@validate.ap.fireeyecloud.com
USGOV
o365@validate.fireeyegov.com
CA
o365@validate.fireeyecloud.com
Click Validate to begin the validation process.
Note
Validation results should indicate that both the connectivity and email tests were successful. If results are not successful, cancel the process and repeat it. If both tests still do not complete successfully, please contact Trellix Customer Support for further help.
Click Next. Review the connector settings. Then click, Create connector.
Step 5: Disable SPF hard fail
You must disable SPF hard fail in O365 in order for Email Security - Cloud to deliver mail to your MTA.
Go to the Microsoft security center. You must be an administrator.
Under Email & collaboration, select Policies & rules.
Click Threat policies.
Under Policies, select Anti-spam.
Select Anti-spam inbound policy (Default).
Click Edit spam threshold and properties.
Under SPF record: hard fail, select Off.
Click Save.
Step 6: Select the spam action options
Note
The supported spam action options are either quarantine message or move message to junk email folder. The quarantine message action configures O365 to use the Admin Quarantine, while the move message to junk email folder action configures O365 to send spam messages to recipients' junk folders. You can configure multiple spam actions depending on spam confidence level, follow Microsoft's recommendations for configuring a junk email folder.
For specific instructions on configuring both spam action options, see Step 6a: Configure the spam action options for admin quarantine and Step 6b: Configure the spam action options for junk email or a combination of actions.
In the Microsoft Exchange admin center, select Other features. Click the link in the Spam Filter row. The Microsoft Defender 365 page opens.
Select the Anti-spam inbound policy (default) and click Edit actions
Under Spam, open the drop-down menu. Select either Quarantine message or Move message to Junk Email folder.
Under High confidence spam, open the drop-down menu. Select either Quarantine message or Move message to Junk Email folder.
Note
Trellix recommends configuring the O365 end user spam quarantine notifications if used in Inline mode so that end users can release messages.
Click Save, then verify that the policy is selected for use.
Step 6a: Configure the spam action options for admin quarantine
Note
Administrators must configure spam filtering settings on O365 in order to preserve the spam filtering process.
This rule is required to handle an edge case where there may be duplicate spam checks run on emails. This can result in messages released from the Admin Quarantine going back to the Admin Quarantine.
Important
This step applies only to the following scenario:
Spam is sent to the Admin Quarantine
To configure spam to be sent to the Junk Email folder or to configure a hybrid of the Admin Quarantine and Junk Email folders, see Step 6b.
In the Microsoft Exchange admin center, click Mail flow > Rules.
Click +Add a rule, then select Create a new rule from the drop-down menu.
Enter a name for the rule.
Note
Use a name that is easy to identify, such as "Email Security - Cloud Return Spam Bypass."
Under the Apply this rule if... section, select The sender > IP address is any of these ranges or exactly matches. A pop-up window appears.
Enter the first IP address corresponding with the geographic region of your Email Security — Cloud account. Click Add. Repeat this step for the remaining IP addresses.
Email Security — Cloud region
IP addresses
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save.
Under the Do the following section, select Modify the message properties > set the spam confidence level (SCL). A pop-up window appears.
Verify that Bypass spam filtering is selected, then click Save.
Important
Do not select Stop processing more rules and do not change any other default settings. Doing so may interfere with how O365 processes spam messages.
Click Save.
Verify that the rule is enabled and has a higher priority than any transport rules or rules with Stop processing more rules selected.
Step 6b: Configure the spam action options for junk email or a combination of actions
This rule is required to allow O365 to detect the original spam classification of email and to update the spam score on return from Email Security — Cloud so that the email will be delivered into the recipient's Junk Email folder.
Important
This step applies only to the following scenarios:
Spam is sent to the recipient's Junk Email folder
A hybrid option of the two spam actions is configured
To configure spam to be sent to the Admin Quarantine, see Step 6a.
In the Microsoft Exchange admin center, click Mail flow > Rules.
Click +Add a rule, then select Create a new rule from the drop-down menu.
Enter a name for the rule.
Under the Apply this rule if section, select The sender > IP address is any of these ranges or exactly matches. A pop-up window appears.
Enter the first IP address corresponding with the geographic region of your Email Security — Cloud account. Click Add. Repeat this step for the remaining IP addresses.
Email Security — Cloud region
IP address(es)
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save.
Next to the Apply this rule if section, click the + button. A new section titled And appears.
Under the And section:
Select The message headers... > matches these text patterns.
Click Enter text, then enter
X-Forefront-Antispam-Report-Untrustedin the specify header name box. Click Save.Click Enter words, then enter
SFV:SPMin the specify words or phrases box. Click Save.
Under the Do the following section, select Modify the message properties > Set the spam confidence level (SCL). A pop-up window appears.
Select 6 from the specify SCL drop-down menu. Click Save.
Click Next.
Important
Do not select Stop processing more rules and do not change any other default settings. Doing so may interfere with how O365 processes spam messages.
Click Next. Review the rule configuration. Click Finish.
Verify the rule is enabled and has a higher priority than any transport rules or rules with Stop processing more rules selected.
Step 7: Create the Inline transport rule
In the Exchange admin center, select Mail flow > Rules.
Click +Add a rule, then select Create a new rule in the drop-down menu.
Enter a name for the rule.
Note
Use a name that is easy to identify, such as "ETP Inline Integration Rule."
Under the Apply this rule if section, select The sender > is external/internal from the drop-down menu. A pop-up window appears.
Select Outside of the organization. Click Save.
Click the + button to the right of the Apply this rule if section. A new section titled And appears.
Under the new And section:
Select The recipient > domain is, then enter a domain.
Important
Enter the domain that you previously configured to process messages in Email Security - Cloud.
Click Add to add the domain to the list.
Click Save.
Under the Do the following section:
Select Redirect the message to > The following connector. A pop-up window appears.
In the pop-up window, select the connector created in Step 4: Create an Outbound connector.
Click Save.
Under the Except if... section:
Important
Adding the exception ensures that emails that have already been scanned by Email Security - Cloud do not get scanned again.
Select The sender > IP address is in any of these ranges or exactly matches. A pop-up window appears.
Enter the first IP address corresponding with the geographic region of your Email Security — Cloud account. Click Add. Repeat this step for the remaining IP addresses.
Email Security — Cloud region
IP addresses
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save.
Click Next.
Important
Do not select Stop processing more rules. Doing so may interfere with how O365 processes messages.
Select header or envelope from the Match sender address in message drop-down menu.
Click Next. Review the rule configuration.
Click Finish.
Verify that the rule is enabled and that it follows the spam bypass rule configured in Step 6: Select the spam action options .