What is email journaling?
The LibraCyber Archiver can archive the incoming, outgoing and internal emails of all Office 365 users in real-time. To accomplish this, the Office 365 journal function must be configured. This is the only way to ensure that all emails are archived entirely.
Thanks to the journaling functionality, at the time of sending and receiving, a copy of the respective email is created by Office 365. The copy is then attached to a so-called journal report and stored in a special journal mailbox. The journal report contains information about the actual senders and recipients; Office 365 also resolves BCC recipients and distribution lists.
The setup process of fully integrating the Archiver into Office 365 can be separated into three steps listed here:
- Office 365 Journaling - This is the configuration of the real-time import of all email flowing through Office 365, this should be configured first.
- Office 365 Authentication - This is the configuration of authentication and integration into your Azure AD Environment, this is required for the next step to function.
- Office 365 Mailbox Retrieval - This is the final step to improving and completing the archive, this will bulk retrieve the full mailbox data from all selected users.
Before the archiving process can be set up in the LibraCyber Email Archiver, journaling has to be set up for the Office 365 environment.
Configure an SMTP listener on the Archiver
On the LibraCyber Archiver you have to configure an incoming SMTP listener to accept emails sent from the Microsoft 365 journal rule.
- Select menù Archiver->Mail Sources->SMTP Journaling and click on the green [+] to add a new listener:
Select SPF Authentication as shown and enter your Microsoft 365 domain. Select Journaling as type and make it Active.
Configure a journal rule on Microsoft 365
- Log on to your Office 365 tenant through Microsoft Purview Portal https://purview.microsoft.com/ with an admin account.
- Navigate to tab Exchange (legacy) under Settings -> Data Lifecycle Management
- insert not_existing_mailbox@YOUR_DOMAIN as Send undeliverable journal reports to. For example insert not_existing_mailbox@libraesva.com. This domain MUST MATCH the domain specified in the Archiver Listener.
- Navigate to tab Journal Rules under Data Lifecycle Management -> Exchange (legacy) and press "+ New rule"
- Enter archiver@<archiver-FQDN> as the external, non Office 365 email address in the Send journal reports to: field.
- Enter a name for the journal rule
- In the If the message is sent to or received from... select Apply to all messages
- Under Journal the following messages... select All Messages
- Click on Save to activate the rule.
Configure an outbound connector on Microsoft 365
Outgoing mail flow is done through Microsoft 365 directly (Connector).
- Navigate to admin.exchange.microsoft.com
- go to Mail Flow > Connectors section
- Add a new connector
- Select Office 365 as Connection from
- Select Partner organization as Connection to
- Give a name and an optional description to the connector
- Select Only when email messages are sent to these domains as Use of connector and add your Archiver FQDN
- Insert your Archiver FQDN as smart host for Routing
-
Enable Always use TLS and choose Any digital certificate in the Security section
WARNING: If you already have an outbound connector that is used for all the domains on the tenant (such as for the Email Security product), you need to modify the transport rule/connector by adding an exception to "skip" all the outbound messages going to the Archiver-FQDN (example= domain.archiver.esvacloud.com) or the validation will fail. - Insert archiver-validation@<archiver-FQDN> as validation email
- Check that the LibraCyber Email Archiver received the test email:
- In the dashboard click on the "email queue" box
- On the top-right of the page, in the Tenant dropdown, select "No Tenant"
- Once you verified that the test email has been received you can delete it
Alternate configurations
Alternate Microsoft 365 outbound connector configuration
When configuring the Microsoft 365 outbound connector, you can route emails to an external smarthost.
When using this alternate configuration, the listener on the Archiver should be configured with IP as authentication with the IP of the smarthost.
IMAP/POP3 journaling instead of Microsoft 365 journaling
If you want to deliver journal messages to an external mailbox then you have to configure the LibraCyber Archiver to retrieve these messages. Supported protocols are IMAP(S) and POP3(S).
- On the Office 365 Journal rule creation wizard fill Send journal reports to: field with the external mailbox email address you want to send journal messages to
- Complete the journal wizard
- Take note of all the information needed to access the selected external mailbox
- On the LibraCyber Archiver click the menù Archiver->Mail Sources->IMAP/POP3 Journaling
- Click on the green [+] to add a new entry
- Fill in all the information to access the mailbox. Under Type dropdown select Journaling and leave enabled Delete mails after indexing.
- Validate your settings and Save
- Check that emails are pulled into your LibraCyber Archiver.