This article addresses configuring Microsoft 365 with LibraCyber ESG as your inbound and/or outbound mail gateway.
You can specify the appliance as an inbound mail gateway through which all incoming mail for your domain passes before reaching your Microsoft 365 account. LibraCyber ESG filters out spam and viruses, and then passes the mail on to the Microsoft 365 mail servers. Use the Inbound Configuration instructions below to configure.
You can likewise specify LibraCyber ESG as the outbound mail gateway through which all mail is sent from your domain via your Microsoft 365 account to the recipient.
As the outbound gateway, LibraCyber ESG processes the mail by filtering out spam and viruses and applying any outbound policies (blocking, encrypting, etc.) before final delivery. By using the configuration described in Outbound Configuration below, you instruct the Microsoft 365 mail servers to pass all outgoing mail from your domain to the appliance.
Preliminary Steps
- You need to have a LibraCyber for Microsoft 365 valid license or an ISP license one.
- If you want to enable outbound mail flow, too, enable 365 trust by going on your LibraCyber ESG Appliance and select Menù System >Mail Transport >Relay Configuration >Trusted Networks and select the option Trust Microsoft Office 365
Inbound Configuration
- Log into the Microsoft 365 Portal with an admin account.
- On the left menu select Show all option.
- Navigate then to Settings > Domains.
- Select your domain from the domain list and click on it.
- Move to DNS records and spot your MX record.
- You MX record should be something like yourdomain-com.mail.protection.outlook.com, your destination mail server.
- Log into the LibraCyber ESG web interface and go to the System > Mail Transport > Relay Configuration > Domain Relay menù.
- Add (or Edit if already present) the your-domain.tld and set the Mail Server field
The Mail Server address indicates where the LibraCyber ESG should direct inbound mail from the Internet (to your Microsoft 365 Exchange server).
Recipient Verification
- Preferred method (from version 4.6): Configure the connector
- Recipient Verification, alternative method:
Alternately in Microsoft 365 you can enable the Directory Based Edge Blocking (DBEB) feature, which is similar to the Valid Recipient list in LibraCyber ESG, and then enable Dynamic Verification in LibraCyber ESG. Instructions can be found here:
Directory Based Edge Blocking (DBEB) feature from Microsoft 365
However, if you have your own external AD/LDAP you can integrate this with LibraCyber ESG to do recipient verification, streaming and authentication of user credentials.
Another solution is to set your domain on Microsoft 365 as Authoritative and always set LibraCyber ESG recipient verification to Dynamic. In addition Microsoft 365 does provide a public POP3 service which you may be able to use for authentication of users accessing the LibraCyber ESG WebUI. To use these services, please contact Microsoft for details.
Domain Antispoofing
Leave Domain Antispoofing setting Standard (SPF) unless you are sure that no one else is sending email with your domain as envelope sender.
Disable Microsoft 365 Spam Checks
Disabling 365 spam checks is not mandatory. We advice to disable spam checks on email delivered by LibraCyber ESG in order to avoid false positives.
- In the Microsoft 365 Portal, to disable internal spam checks for the email analyzed by LibraCyber ESG, create a Transport Rule:
1) Click on Admin Centers and select Exchange from the drop-down in the left panel. 2) On the left side then click Mail Flow link. 3) Under Rules, click the [+] button and select Create New Rule.
4) Give it a Name 5) Look down at the bottom and click More options… 6) Under the Apply this rule if… drop-down, select The sender… -> IP address is in any of these ranges or exactly matches. 7) In the pop-up titled IP address ranges, input the LibraCyber ESG IP address 8) Click [+] and then click OK. 9) Under the *Do the following… section, select Modify the message properties… -> Set the spam confidence level (SCL), and under Specify SCL, select Bypass spam filtering via the drop-down. 10) Click OK, and then click Save to save the new transport rule.
- Do the same under the Connection Filtering section (https://security.microsoft.com/skiplisting).
1) Click on Connection Filter Policy 2) Click the Edit connection filter policy link at the bottom of the popup 3) Add IP into "Always allow messages from the following IP addresses or address range" section 4) Click on Save button on the bottom of the popup
- Do the same under the Skiplist section (https://security.microsoft.com/antispam).
The above setup will permit you to manage correctly connection validations even if you have a 3rd part security solution like LibraCyber ESG; It will also manage correctly forwarding scenario.
Configure an Inbound Connector
The inbound connector can be done in two ways: allowing inbound only from ESG (the right choice for production system) or allowing inbound also from other sources (suggested only when testing).
In the Exchange Admin Center create an Inbound Connector:
1) On the left side client Mail Flow and select Connectors on the top right 2) Under Connectors, click the [+] button. 3) From: Partner Organization - To: Office 365
4) Click Next. 5) Give it a name and click Next 6) Select Use the sender's domain 7) Specify one Sender domain with * (asterisk)
8) Click Next 9) Select the option "Reject email messages if they aren't sent over TLS" 10) Select the option "And require that the subject name on the certificate that the partner uses to authenticate with Office 365 matches this domain name" 11) Enter the hostname of the ESG appliance if this is the only Microsoft365 tenant managed by ESG, otherwise see the paragraph on multitenant configuration. DO NOT ADD WILDCARDS
12) Click Next 13) Review and Create connector
Modifying Your MX Record
To direct your email traffic to LibraCyber ESG you need to update your domain’s “MX records”. The MX records are stored at your domain host and will direct your email to your mail servers. It’s like registering your new address with the post Microsoft so that your mail gets delivered.
The MX record should be updated to point to your LibraCyber ESG appliance.
Further information are available here.
Outbound Configuration
SPF Record
Before going through the configuration steps below please Update the SPF Record for your domain(s)!
Your organization should already have a SPF record for the domain(s) registered with Microsoft 365. When implementing LibraCyber ESG with Microsoft 365, this record must be updated in the DNS zone for the relevant domain to include the following:
Add: include:spf.esvacloud.com (if LibraCyber ESG is deployed in our cloud) Add: include:<customer-spf-record> or a:<ESG-HOSTNAME> or ip4:<ESG-IP-Address> (if LibraCyber ESG is deployed in customer's datacenter)
in both cases include:spf.protection.outlook.com must be present
Example: v=spf1 mx include:spf.protecion.outlook.com include:spf.esvacloud.com -all
Outbound Connector
To configure the outbound mail flow from Microsoft 365 to LibraCyber ESG proceed as follows:
- Log into the Microsoft 365 Portal (https://www.office.com) .
- Click on Admin and select Exchange from the drop-down in the left panel (by clicking on Show all).
- Select mail flow from the left link navigation bar.
- Select the connectors link at the top.
- Create a new connector
- In the From section select Microsoft 365, and in the To section select Partner Organization. Click Next.
- Give the new connector a Name (for example: Microsoft 365 to LibraCyber ESG), optional Description, and decide if the connector should be enabled once it has been saved using the Turn it on checkbox. Click Next.
- Change selection on first bullet Only when I have a transport rule.... and click on next.
- Select the Route email through these smart hosts option, and click the plus icon to add the ip address or FQDN of your LibraCyber ESG Appliance. Click Save, followed by Next.
In a cluster environment be sure to add both nodes IPs.
- Leave the default Always use Transport Layer Security (TLS) to secure the connection (recommended) and Any digital certificate, including self-signed certificates (unless you own a trusted one) set and click Next.
- Verify your settings and click Next.
- Validate the connector by adding an external mail address (not managed by you) and click Save.
Transport Rule
Now we need to create the transport rule that will be linked to the newly created connector:
- Select the rules link at the top.
- Create a new rule giving the name "Route messages to LibraCyber ESG"
- Remember to click on More options link once pop-up rule opens.
- Apply this rule if -> the sender -> is external/internal -> inside the organization.
- Do the following -> Redirect the message to... -> the following connector -> Select the LibraCyber ESG Outbound created before.
- Click on add exception.
- Except if -> the recipient -> is External/Internal -> inside the organization (this will not allow internal messages to be routed through LibraCyber ESG)
- or -> the message properties -> include the message type -> automatic reply
- or The Sender -> IP address in any of these ranges or exactly matches -> LibraCyber ESG IP Address (to avoid loop transport problems)
- finally save the transport rule.
Outbound Mail Flow
Now you have two different scenarios to deliver messages:
- 1) Deliver outgoing messages through LibraCyber ESG IP Address (MSP mode)
In this scenario all outgoing email are delivered to the final destination by your LibraCyber ESG directly, performing MX lookups and using it's own IP address.You have full control and responsibility of the node reputation.
If you opt for this scenario, the configuration finished, and you do not have to perform any other operation.
- 2) Deliver outgoing messages through Microsoft365 IP Address Space (Recommended, not supported for MSP configurations)
In this scenario all outgoing messages are routed back on to Microsoft 365 to be delivered to the final destination. The address space and reputation is managed by Microsoft - Recommended setup for most cases.
If you opt for this scenario you have to configure another 365 inbound connector and then add a smarthost to LibraCyber ESG.
Configure an Inbound Connector for the outbound mail flow
In the Exchange Admin Center, create another Inbound Connector, this connector will be use to receive the outbound mail coming back from ESG:
1) On the left side client Mail Flow and select Connectors on the top right 2) Under Connectors, click the [+] button. 3) From: Your organization's mail server - To: Office 365 4) Click Next. 5) Give it a name and click Next 6) Select By verifying that the subject name on the certificate 7) Specify the hostname of your LibraCyber ESG appliance(s) 8) Click Next 9) Review and Save
Login to your LibraCyber ESG appliance.
-
-
- Click Menu System->Mail Transport->MTA Advanced Configuration->External Smarthost
- Click New
- Enter as Source: @<your-domain>
- Smarthost Address: your 365 MX record (i.e. you-domain-com.mail.protecion.outlook.com)
- Port: 25
- Click Save
-
Import Users and Valid Recipients
LibraCyber Email Security Gateway offers native integration with Microsoft Microsoft 365. In order to retrieve information such users, groups and email addresses from an Microsoft 365 tenant you can follow the instructions here: https://docs.libraesva.com/document/system/authentication/office-365-configuration/
Setup Threat Remediation
LibraCyber ESG supports Email Threat Remediation, a feature to recall delivered messages from user’s mailboxes. To setup this feature please follow this guide: https://docs.libraesva.com/document/threat-remediation/office-365-threat-remediation-settings/
Multitenant configuration
If your ESG manages email for more than one Microsoft365 tenant, every connector must use a different certificate hostname.
With ESG you can create many certificates using LetsEncrypt or load multiple certificate and you can assign each certificate to a different relay.
To create a new certificate for the same ESG the easiest option is to use a third or fourth level domain. For example, if the hostname of ESG is demo.esvacloud.com you can create certificates for sub1.demo.esvacloud.com, sub2.demo.esvacloud.com and so on.
In order to get LetsEncrypt certificates for third or fourth level domains, all you need to do is to create a CNAME record on your DNS where sub1.demo.esvacloud.com points to demo.esvacloud.com. You can also create a wildcard CNAME record where *.demo.esvacloud.com points to demo.esvacloud.com. With a single CNAME record like this you don't need to make additional DNS configurations to generate more certificates.
Once the DNS is configured, in TLS Certificates > Configure Certificates you can go ahead and create the certificates you need:
Once the certificates are generated you can assign one certificate for each Microsoft 365 tenant in the relay table:
All the domains on the same Microsoft365 tenant must share the same TLS certificate and the same hostname of this certificate must be configured in the Microsoft365 tenant connectors.