You can integrate inline mode with AV/AS between O365/EOP and Email Security - Cloud by adding the Email Security - Cloud Internet Protocol (IP) ranges and domains to the allowed list, creating an allowed list rule and modifying the domain mail exchanger (MX) records. These steps allow messages sent from Email Security - Cloud to be delivered without the risk of being quarantined by O365. After you change the domain MX records, mail will be routed through Email Security - Cloud before being processed by O365.
Important
Migrate any email allowed and blocked lists currently defined in O365/EOP before you change the domain MX records.
To configure Inline with Hygiene mode:
What you need
Administrative access to your O365/EOP account.
Administrative access to your Email Security - Cloud instance.
Step 1: Add the Email Security - Cloud domain to the allowed list.
In the Microsoft Exchange admin center, select Other features.
Click the link in the Spam filter row. The Microsoft Defender 365 page opens.
Verify that the “Anti-spam inbound policy (Default)” spam filter's status is "Always on", then click on the policy. A pop-up window appears.
In the pop-up window, click Edit allowed and blocked senders and domains.
Under Domains, select Allow domains.
Click +Add domains and enter
fireeyecloud.comas an allowed domain. Click Add domains.Click Done to save your settings.
Click Save to save the allowed list.
Step 2: Create the IP allowlist rule
In the Microsoft Exchange admin center, select Other features. Click the link in the Connection filter row. The Anti-spam policies page in Microsoft Defender 365 opens.
Select Connection filter policy (Default).
Click Edit connection filter policy.
Enter the first IP address corresponding with the geographic region of your Email Security - Cloud account in the Always allow messages from the following IP addresses or address range entry box. Then, enter the remaining IP addresses.
Email Security - Cloud region
MX records
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save to save the rule configuration.
Step 3: Create an Inbound connector
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click +Add a connector to create a new connector.
Set the Connection from value to Partner organization.
The default Connection to value is Office 365. Click Next.
Enter the connector name and description (optional).
Verify that the Turn it on checkbox is selected. Click Next.
Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
Enter the first sender IP address corresponding with the geographic region of your Email Security - Cloud account. Click the + button. Repeat this step for the remaining IP addresses.
Email Security - Cloud region
MX records
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Next.
Verify that the Reject email messages if they aren't sent over TLS option is selected. Click Next.
Note
This option ensures that all email is encrypted in transit.
Verify that the connector settings have been correctly configured, then click Create connector.
Click Done.
Step 4: Disable SPF hard fail
You must disable SPF hard fail in O365 in order for Email Security - Cloud to deliver mail to your MTA.
Go to the Microsoft security center. You must be an administrator.
Under Email & collaboration, select Policies & rules.
Click Threat policies.
Under Policies, select Anti-spam.
Select Anti-spam inbound policy (Default).
Click Edit spam threshold and properties.
Under SPF record: hard fail, select Off.
Click Save.
Step 5: Force email to bypass spam filtering on return from Email Security - Cloud
In the Microsoft Exchange admin center, click Mail flow > Rules.
Click +Add a rule, then select Create a new rule from the drop-down menu.
Enter a name for the rule.
Under the Apply this rule if section, select The sender > IP address is in any of these ranges or exactly matches. A pop-up window appears.
Enter the first sender IP address corresponding with the geographic region of your Email Security — Cloud account. Click Add. Then, repeat for the remaining IP addresses.
Email Security - Cloud region
IP addresses
USA
34.223.36.0/24
3.93.93.0/24
EMEA
3.123.5.0/24
63.34.218.0/24
APJ
3.112.99.0/24
3.112.100.0/24
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Save.
Under the Do the following section, select Modify the message properties > Set the spam confidence level (SCL). A pop-up window appears.
Verify that Bypass spam filtering is selected, then click Save.
Click Next.
Important
Do not select Stop processing more rules and do not change any other default settings. Doing so may interfere with how O365 processes spam messages.
Click Next. Review the rule configuration, then click Finish.
Verify that the rule is enabled and has a higher priority than any transport rules or rules with Stop processing more rules selected.
Step 6: Modify the domain MX records for your domain
Depending on the geographic region of your Email Security - Cloud account, modify the domain MX records for your domain as per the table below.
Detailed steps for changing MX records are beyond the scope of this document. For further assistance, contact your domain registrar or DNS provider.
Important
You might run into an error when you use an O365 built-in MX record validator tool to cross-check the settings on the downstream MTA.
The validator tool usually checks if the MX records are pointing to the O365 mail properties instead of Email Security - Cloud.
If you have configured the MX records in the your internal O365 environment as per the documentation and have confirmed via outside sources that the domain MX records are pointing to the Email Security - Cloud correctly, this error can be ignored.
Email Security - Cloud region | MX records | Priority |
|---|---|---|
USA | primary.us.email.fireeyecloud.com alt1.us.email.fireeyecloud.com alt2.us.email.fireeyecloud.com alt3.us.email.fireeyecloud.com | 10 20 30 40 |
EMEA | primary.emea.email.fireeyecloud.com alt1.emea.email.fireeyecloud.com alt2.emea.email.fireeyecloud.com alt3.emea.email.fireeyecloud.com | 10 20 30 40 |
APJ | primary.ap.email.fireeyecloud.com alt1.ap.email.fireeyecloud.com alt2.ap.email.fireeyecloud.com alt3.ap.email.fireeyecloud.com | 10 20 30 40 |
USGOV | primary.us.etp.fireeyegov.com alt1.us.etp.fireeyegov.com alt2.us.etp.fireeyegov.com alt3.us.etp.fireeyegov.com | 10 20 30 40 |
CA | primary.ca.email.fireeyecloud.com alt1.ca.email.fireeyecloud.com alt2.ca.email.fireeyecloud.com alt3.ca.email.fireeyecloud.com | 10 20 30 40 |
Step 7: Block all non-Email Security - Cloud sender IP addresses
Blocking all non-Email Security - Cloud sender IP addresses ensures that Email Security - Cloud security checks cannot be bypassed. If non-Email Security - Cloud sender IP addresses are not blocked, someone could manually configure an SMTP server to bypass Email Security - Cloud and deliver directly to O365, instead of honoring the MX records. This tactic is used by attackers to bypass existing secure email gateway services and opens you up to risk.
Caution
WARNING: If you have partner organizations or automated senders that use this O365 DNS record directly, their emails will be blocked. Check for such conditions before you follow this procedure.
In the Microsoft Exchange admin center, click Mail flow > Connectors.
Click +Add a connector to create a new connector.
Set the Connection from value to Partner organization.
The default Connection to value is Office 365. Click Next.
Enter the connector name and description (optional).
Verify that the Turn it on checkbox is selected. Click Next.
Select By verifying that the sender domain matches one of the following domains.
In the domain name field, enter *, then click the + button.
Click Next.
Select Reject email messages if they aren't sent from within this IP address range.
Enter the first sender IP address corresponding with the geographic region of your Email Security — Cloud account. Click the + button. Repeat this step for the remaining IP addresses.
Note for multi-domain tenants with outbound scanning: If your Email Security - Cloud tenant hosts multiple associated domains and you have enabled Outbound Email Scanning, you must include both the Inbound and Outbound Trellix IP ranges in this list.
When an email is sent from one domain to another within the same tenant (e.g., Domain A to Domain B), Email Security - Cloud processes the outbound message and routes it back to O365 via its outbound delivery IPs. If this connector only includes Inbound IPs, internal messages between your domains will be rejected.
Email Security - Cloud region
IP addresses
USA
34.223.36.0/24
3.93.93.0/24
Required for Outbound Users:
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
EMEA
3.123.5.0/24
63.34.218.0/24
Required for Outbound Users:
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
APJ
3.112.99.0/24
3.112.100.0/24
Required for Outbound Users:
34.223.9.0/24
34.223.11.128/25
34.223.12.0/25
100.25.99.0/25
100.24.127.128/25
USGOV
15.200.32.0/24
CA
3.97.207.0/24
Click Next.
Click Create connector.
Click Done.