Requirements
- You need to have a LibraCyber for Microsoft 365 valid license or an ISP license. You can check your license from the Licensing & Billing page.
- You need a Graph API access and data for ESG. To create it, please follow the previous Microsoft 365 APIs configuration guide.
Configuration
The configuration process has some steps, please follow them in order they are written.
Domain configuration
- Login to the web UI of your LibraCyber ESG appliance, reach the Relay Configuration page and add the a new record in the table, clicking on the New button in the table toolbar. A dialog appears. Here you have to enter the Domain and the Mail Server (you have to enter the Microsoft 365 destination FQDN for your tenant). The Mail Server address indicates where the LibraCyber ESG should redirect all mail traffic sent to your organization (to your Microsoft 365 server).
- Choose a Recipient Verification method and setup it as explained in the Recipient Verification how to.
- Leave the last four settings as they are, if there are no particular needs.
Connector configuration
Warning: the Microsoft 365 native connector doesn’t support non-365 distribution lists. Microsoft provides a guide to converting them to the new Microsoft 365 format. The above applies only to the User and not to the Valid Recipient List
Warning: the Microsoft 365 native connector doesn’t support public folders. Public folders are deprecated by Microsoft and will never be supported by the Graph API.
- To configure the connector go in the Microsoft 365 integration page on your LibraCyber appliance.
- Create a connector by clicking on the New button from the table toolbar.
- A dialog appears, here you have to insert the information previously retrieved following the Microsoft 365 APIs configuration guide.
- There are 4 additional settings in the 365 Connector:
- Add Group Email to Users (when Yes, ESG imports groups email as user email addresses)
- Create Functional Users for Groups (when Yes, ESG creates a non-licensed and not-accessible user account for each group)
- User quarantine digest (instead of using global configurations, you may force a quarantine digest to be enabled or disabled)
- Import enabled (import users from the connector when the synchronization job runs)
- Click on the Save button on the dialog and click on the Test button related to the just created connector.
- Insert an email address belonging to the domain you are testing and click on the Test button. The test must be successful.
Note: if you receive Insufficient privileges to complete the operation error, wait a few minutes for Azure to clean its cache and retry.
Authentication configuration
- When the test has been completed, scroll down to the bottom of the page and click on the Configure Microsoft 365 Authentication button.
- You will be redirected to the Web Portal Authentication page.
- Find the domain in the table and expand it as shown in the screenshot below.
- Click on the New button from the child table toolbar.
- Select the created connector and click on the Save button.
Choose Default Users Settings
- Once you have created Microsoft 365 connector, you’ll be able to import users in LibraCyber ESG.
- Before running the first import, please make sure to have selected the desired User Defaults settings going in the User Management page > User Defaults
First User Import
- Reach the User Management page and click on the Microsoft 365 Import in the dropdown menu from the table toolbar.