SlideShare ist ein Scribd-Unternehmen logo
1 von 41
Peter Schmidt
Solution Architect, EG A/S
Exchange Online Protection
Introduction and Architecture
About me
© EG A/S 2
Peter Schmidt
Solution Architect, EG A/S
Expertise:
Office 365, Exchange, Skype for Business,
Microsoft Azure, ADFS, PKI
Microsoft MVP: Exchange, MCM: Exchange
MCSE: Messaging, MCSA: Office 365
MCSE: Server Infrastructure, MCSE: Public Cloud
Contact me:
E-mail: pesch@eg.dk
Blog: www.msdigest.net
Twitter: @petsch
Phone: +45 7260 2775/+45 2080 9436
Agenda
© EG A/S 3
 Introduction to Exchange Online Protection
 EOP Architecture
 Deployment
 Best Practices
 Summary
 Q&A
Introduction to
Exchange Online Protection
Stop viruses and malware
 Multi-engine malware protection
 Continuously evolving anti-spam protection
Protect sensitive data
 Data Loss Prevention features
 Encryption of sensitive email
Common administration console
 Office 365 integration
 Detailed reporting
Enterprise class reliability
 Geographically load-balanced datacenters
 Queuing capabilities to help ensure no mail is lost
 24x7x365 Microsoft Support
 $$$ backed SLA
Exchange Online Protection (EOP)
• Mail Delivery
• 99.999% EOP uptime
• Geo-redundant network
• 24/7 Live phone and web technical support
• Message queuing for 2 days if customer server unresponsive
• Filtering Performance
• 100% known virus detection (active payload)
• 99% spam detection rate
• False positive ratio of less than 1:250,000 messages
EOP Service Level Agreements
EOP Architecture
On-premises server - Inbound and Outbound email filtered through EOP
EOP Conceptual Diagram
Corporate NetworkEOP
Works with any SMTP email platform!
Every Office 365 customer is an EOP customer
Easy transition from EOP stand-alone to Office 365
On-premises server
- Inbound and Outbound email filtered through EOP
EOP Deployment scenarios
6
On Premise
Corporate Network
EOP
O365
Exchange Online
EOP Inbound filtering
Email is routed to EOP DC’s based on MX record resolution
(contoso-com.mail.protection.outlook.com)
IP-based edge blocking
Reputation blocking
Virus
scanning
AV Engine 1
AV Engine 2
AV Engine 3
SPAM protection
Safe Sender/Recipient
Policy enforcement
Custom Rules
Content scanning and Heuristics
Bulk Mail filtering
SPF & Sender ID Filter
Quarantine
*International Spam*
Advanced SPAM management
Customer feedback
False +ve / -ve
Spam analysts
Corporate network
Regular expressions
URL block lists
Envelope blocks
Forefront blocks
Allows/Rejects
Outbound Pool
Outbound Pool
EOP Outbound filtering
High Risk Delivery PoolHigh Score
Outbound Pool
Low ScoreSPAM protection
Content scanning and Heuristics
Advanced SPAM management
Virus
scanning
AV Engine 1
AV Engine 2
AV Engine 3
Policy enforcement
Custom Rules
Quarantine
Spam Analysts
Corporatenetwork
Bulk Delivery Pool
Bulk Mail
Internet
Email Encryption
Anti-spam
• Phishing Campaigns
• Spear Phishing (APT)
• Bulk Mail
• Backscatter
• Malware Distribution
• Image Spam
Different Types of SPAM
1. Connection filtering
Blocks up to 80% of all spam based on IP block/allow lists.
2. Sender-Recipient Filtering
Blocks up to 15% of all spam based on internal lists and sender reputation.
3. Content Filtering
Blocks up to 5% of all spam based on internal lists and heuristics.
Multi-layered anti-spam protection
14
Connection filtering
 Static IP allow/block list
 Opt-in to Microsoft-maintained reputable sender list
Content spam categories
 Obvious spam
 High confidence spam
Content Filtering Actions
 Delete
 Quarantine
 Add X-Header
 Modify Subject
 Redirect
Granular anti-spam filtering controls
15
Block external threats quickly
Advanced fingerprinting technologies that identify and
stop new spam and phishing vectors in real time.
Enable more control
Mark all bulk messages as spam
Block unwanted email based on language or
geographic origin
Block email based on language
Block email based on geography
Effective spam
blocking
• Suspect junk mail by default goes to the Outlook junk mail folder.
• Uses Outlook safe senders and block lists.
• SPAM Quarantine was currently available to administrators only.
End user quarantine rolled out NOW!
• Email Spam Notification for the end-users
Junk mail management
End User Quarantine
• End users can release from quarantine
• Report Spam, not spam
Quarantine
Set Frequency from 1-15 days
End User Spam Notification
False Negatives and False Positives
Outlook Junk Mail Reporting
Tool for missed spam
http://www.microsoft.com/en-
us/download/details.aspx?id=18275
Send spam email as an
attachment to
abuse@messaging.microsoft.com
Send false positive messages
to
false_positive@messaging.microsoft.c
om
Deployment
Standalone
All mailboxes are located on-premises
Purchasable on its own or Part of Exchange Enterprise CAL with Services
Fully hosted
All mailboxes are hosted in the cloud with Microsoft Exchange Online
Exchange Online license
Hybrid
Some mailboxes are hosted in Exchange Online, and some mailboxes on-premises
Exchange Online license
EOP deployment scenarios
Overview of the deployment process
Step 1: Verify prerequisites
Step 2: Configure mail flow (connectors)
Step 3: Add and validate domains
Step 4: Customize spam and policy settings
Step 5: Enable mail flow
Step 6: Monitor and fine tune
Applicable to all scenarios
 Office 365 Tenant – name.onmicrosoft.com
 EOP licenses (ExO or EOP Standalone)
 Domain to migrate
 Modern web browser to access the Office 365 portal
Applicable to Standalone or Hybrid scenarios
 Inbound and outbound public IP addresses
 Open port 25 to Exchange Online Protection IP Addresses
 Information on TLS policy, attachment handling, junk folder use, etc.
 DirSync may require additional hardware
Prerequisites
Standalone
 Create EOP outbound connector to deliver mail on-premises
 Create EOP inbound connector to accept mail from on-premises
 Create on-premises send connector to send outgoing mail to EOP
Hybrid
 Hybrid mail flow is best configured using the Hybrid Configuration Wizard
Optional for all scenarios
 Create connectors for forced TLS to third party
 Create connectors for customized mail routing
Configure mail flow
On-Prem Mail
Environment
Exchange Online
Protection
Outbound Connector
Inbound Connector
Outbound TLS
Connector
Inbound TLS
Connector
EOP connectors between on-premises and EOP need to be created
*Additional connectors can be created between EOP and partners to force TLS
Partner
Environment
Configure mail flow (connectors)
With EOP (Fabrikam uses EOP)
TLS scenario
Prior to EOP (Fabrikam uses EOP)
Contoso FabrikamCert CN = mail.contoso.com
Cert CN = mail.fabrikam.com
Contoso EOP FabrikamCert CN = mail.contoso.com
Cert CN = mail.protection.outlook.com
Cert CN = mail.protection.outlook.com
Cert CN = mail.fabrikam.com
Configure mail flow (connectors)
On-Prem Mail
APAC
Exchange Online
Protection
On-Prem Mail
AMER
On-Prem Mail
EMEA
Outbound
Connector 1
Outbound
Connector 3
Outbound
Connector 2
Inbound
Connector 1
Policies
Anti-spam, anti-malware and
DLP controls integrated into
the Exchange Admin Center
and Office 365.
• What it does
• Blocks messages to invalid recipients at the EOP edge
• Beneficial to organizations with on-premises mailboxes
• Configuration
• The EAC exposes two domain types.
• Authoritative - All email for unknown recipients is rejected. Setting this domain type enables DBEB
• Internal relay - Email is delivered to recipients in your org or relayed to another email server
• To enable DBEB, set the domain to be AUTHORITATIVE.
Directory Based Edge Blocking
Reporting
Reporting
Provides a clear view on spam filtering
and malware attacks
E-mail Protection Reports
Excel Workbook available to enable self-
service analysis
Connects to the reporting web service
Data can be refreshed from within the
workbook at any time
Drill through from recent summary data to
the underlying detailed information
• Goals
• Is the service operating as expected?
• Make adjustments to rules or settings as needed
• Evaluate effectiveness of spam settings
• Tools
• Reports (Office 365 Portal or Mail Protection Reports for Office 365)
• Submitting spam and false positive messages to Microsoft
• Junk Mail Reporting Tool for Outlook
Monitor and fine tune
Best Practices
• Do this
• Use a test domain, subdomain or low volume domain for trying different service features
• Disable EOP inbound connector (type is on-prem) until you are ready to use it
• Use the Remote Connectivity Analyzer to troubleshoot
• Restrict inbound SMTP access to allow ONLY from EOP IP ranges
• Enable Microsoft’s IP Safe List in the Connection Filter
• When creating safe / black lists, use IP first, and if not possible, then use the domain
• Don’t do this
• Daisy chain services
• Use EOP for sending bulk mail
• Enable all Content Filter Advanced Options out of the box
• Safe list your own domain
Best practices
Telnet is your friend
Telnet can be used to test mail flow from EOP to your on-prem environment.
This allows verifying mail flow will work before doing the MX cutover.
Test mail flow before MX change
You do/type this Server responds with this
telnet tenantDomainMXRecordHere 25 220
helo your_sending_server_fqdn 250
mail from: you@domain.invalid 250 Sender OK
rcpt to: recipient@contoso.com 250 Recipient OK
data followed by the enter key Server provides directions on how to
enter data.
subject: Enter the subject and hit enter
twice
Enter the body text. To finish the message,
type a period on a line by itself and hit
enter.
250 Message queued for delivery.
• Quarantine
• Online viewer only supports up to 500 messages
• More can be viewed via PowerShell Get-QuarantineMessage Cmdlet
• Can only release in bulk through Release-QuarantineMessage Cmdlet
• Limits
• Max message size for EOP delivering to stand-alone customers is 150 MB
• Max 100 Transport Rules per tenant – DLP policies consume part of this quota
• Max of 900 domains per tenant
• EOP outbound connectors use round robin for delivery
Known Issues & Limitations
No Am
APAC
EMEA
Mail is ALWAYS processed ONLY in your region!
PRC
• Protection against unknown malware and viruses by analyzing attachment
behavior in a hypervisor environment before delivering them
• Real time, time-of-click protection against malicious URLs that are not yet
known by EOP
• Rich reporting and tracing of URL click throughs
• 2$ / month per user
Advanced Threat Protection
EOP Architecture
Test drive it
Know the limitations of EOP
Summary
Questions !
© EG A/S 41

Weitere ähnliche Inhalte

Was ist angesagt?

TechNet Webcast: Exchange 2010 Overview
TechNet Webcast: Exchange 2010 OverviewTechNet Webcast: Exchange 2010 Overview
TechNet Webcast: Exchange 2010 OverviewMicrosoft TechNet
 
Topsec Technology Cloud Arena Final
Topsec Technology   Cloud Arena   FinalTopsec Technology   Cloud Arena   Final
Topsec Technology Cloud Arena Finalniallmmackey
 
Mail store server4 manual-en
Mail store server4 manual-enMail store server4 manual-en
Mail store server4 manual-enguest8e6971
 
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASS
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASSECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASS
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASSEuropean Collaboration Summit
 
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)Harold Wong
 
How vaultastic works
How vaultastic worksHow vaultastic works
How vaultastic worksVaultastic
 
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...Vaultastic
 
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...European Collaboration Summit
 
Webinar: Discover how Vaultastic integrates with your existing email infrastr...
Webinar: Discover how Vaultastic integrates with your existing email infrastr...Webinar: Discover how Vaultastic integrates with your existing email infrastr...
Webinar: Discover how Vaultastic integrates with your existing email infrastr...Vaultastic
 

Was ist angesagt? (16)

ema
emaema
ema
 
TechNet Webcast: Exchange 2010 Overview
TechNet Webcast: Exchange 2010 OverviewTechNet Webcast: Exchange 2010 Overview
TechNet Webcast: Exchange 2010 Overview
 
Don't Get Phished!
Don't Get Phished!Don't Get Phished!
Don't Get Phished!
 
Spamtitan_brochure_V3
Spamtitan_brochure_V3Spamtitan_brochure_V3
Spamtitan_brochure_V3
 
Mail
MailMail
Mail
 
Topsec Technology Cloud Arena Final
Topsec Technology   Cloud Arena   FinalTopsec Technology   Cloud Arena   Final
Topsec Technology Cloud Arena Final
 
Mail store server4 manual-en
Mail store server4 manual-enMail store server4 manual-en
Mail store server4 manual-en
 
O365 to cisco cloud guide
O365 to cisco cloud guideO365 to cisco cloud guide
O365 to cisco cloud guide
 
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASS
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASSECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASS
ECS19 - Mustafa Toroman, Sasa Kranjac - SOUP TO NUTS: MICROSOFT AZURE POWERCLASS
 
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 15 Of 24)
24 Hours Of Exchange Server 2007 ( Part 15 Of 24)
 
ECS19 - Jussi Roine - Microsoft 365 Deep Dive
ECS19 - Jussi Roine - Microsoft 365 Deep DiveECS19 - Jussi Roine - Microsoft 365 Deep Dive
ECS19 - Jussi Roine - Microsoft 365 Deep Dive
 
How vaultastic works
How vaultastic worksHow vaultastic works
How vaultastic works
 
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...
Featured Webinar: Why Cloud Archiving is Best Suited for On Premise Mail Serv...
 
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...
ECS19 - Johan Delimon - Keep your Skype for Business Hybrid working like a ch...
 
Webinar: Discover how Vaultastic integrates with your existing email infrastr...
Webinar: Discover how Vaultastic integrates with your existing email infrastr...Webinar: Discover how Vaultastic integrates with your existing email infrastr...
Webinar: Discover how Vaultastic integrates with your existing email infrastr...
 
Proxy Presentation
Proxy PresentationProxy Presentation
Proxy Presentation
 

Andere mochten auch

What's new in Exchange Online - Microsoft Office 365 - Atidan
What's new in Exchange Online - Microsoft Office 365 - AtidanWhat's new in Exchange Online - Microsoft Office 365 - Atidan
What's new in Exchange Online - Microsoft Office 365 - AtidanDavid J Rosenthal
 
Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...ITProceed
 
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...Microsoft Private Cloud
 
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft Private Cloud
 
Microsoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsDavid J Rosenthal
 
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...Motty Ben Atia
 
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?GWAVA
 
Tips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineTips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineSteve Goodman
 
Office 365: Migrating Your Business to Office 365!
Office 365: Migrating Your Business to Office 365!Office 365: Migrating Your Business to Office 365!
Office 365: Migrating Your Business to Office 365!Michael Frank
 
Office 365 Mail migration strategies
Office 365 Mail migration strategiesOffice 365 Mail migration strategies
Office 365 Mail migration strategiesFulvio Salanitro
 
Office 365 Migration Planning
Office 365 Migration PlanningOffice 365 Migration Planning
Office 365 Migration PlanningCredera
 
Exchange Online Protection
Exchange Online Protection Exchange Online Protection
Exchange Online Protection GWAVA
 

Andere mochten auch (14)

What's new in Exchange Online - Microsoft Office 365 - Atidan
What's new in Exchange Online - Microsoft Office 365 - AtidanWhat's new in Exchange Online - Microsoft Office 365 - Atidan
What's new in Exchange Online - Microsoft Office 365 - Atidan
 
Overview of Microsoft Exchange Online
Overview of Microsoft Exchange OnlineOverview of Microsoft Exchange Online
Overview of Microsoft Exchange Online
 
Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...
 
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
 
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
 
Microsoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform Options
 
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
 
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?
GWAVACon 2015: Microsoft MVP - What's new in Exchange Server 2016?
 
Tips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineTips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange Online
 
Office 365: Migrating Your Business to Office 365!
Office 365: Migrating Your Business to Office 365!Office 365: Migrating Your Business to Office 365!
Office 365: Migrating Your Business to Office 365!
 
Office 365 Mail migration strategies
Office 365 Mail migration strategiesOffice 365 Mail migration strategies
Office 365 Mail migration strategies
 
Office 365 migration
Office 365 migrationOffice 365 migration
Office 365 migration
 
Office 365 Migration Planning
Office 365 Migration PlanningOffice 365 Migration Planning
Office 365 Migration Planning
 
Exchange Online Protection
Exchange Online Protection Exchange Online Protection
Exchange Online Protection
 

Ähnlich wie CoLabora - Exchange Online Protection - June 2015

24 Hours Of Exchange Server 2007 ( Part 13 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 13 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 13 Of 24)
24 Hours Of Exchange Server 2007 ( Part 13 Of 24)Harold Wong
 
La seguridad sí importa: Windows Live & IE9
La seguridad sí importa: Windows Live & IE9La seguridad sí importa: Windows Live & IE9
La seguridad sí importa: Windows Live & IE9Eventos Creativos
 
Technical Background Overview Ppt
Technical Background Overview PptTechnical Background Overview Ppt
Technical Background Overview PptAntonio Ieranò
 
TechNet Webcast: Exchange 2010 Outlook Web Access
TechNet Webcast: Exchange 2010 Outlook Web AccessTechNet Webcast: Exchange 2010 Outlook Web Access
TechNet Webcast: Exchange 2010 Outlook Web AccessMicrosoft TechNet
 
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosGina Montgomery, V-TSP
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)webhostingguy
 
10135 a 05
10135 a 0510135 a 05
10135 a 05Bố Su
 
Ironport Data Loss Prevention
Ironport Data Loss PreventionIronport Data Loss Prevention
Ironport Data Loss Preventiondkaya
 
E-Mail - Technical Overview
E-Mail - Technical OverviewE-Mail - Technical Overview
E-Mail - Technical OverviewVenkatesh Iyer
 
Exchange 2007 Overview Son Vu
Exchange 2007 Overview Son VuExchange 2007 Overview Son Vu
Exchange 2007 Overview Son Vuvncson
 
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)Harold Wong
 
CensorNet MailSafe
CensorNet MailSafeCensorNet MailSafe
CensorNet MailSafetlloyduk
 
What You Need to Know About Email Authentication
What You Need to Know About Email AuthenticationWhat You Need to Know About Email Authentication
What You Need to Know About Email AuthenticationKurt Andersen
 
Improving email reliability
Improving email reliabilityImproving email reliability
Improving email reliabilityAntti Siiskonen
 
B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2BCamp
 
Abaca: The World's Most Effective Spam Filter
Abaca: The World's Most Effective Spam FilterAbaca: The World's Most Effective Spam Filter
Abaca: The World's Most Effective Spam FilterJohn Jefferies
 
10135 a 06
10135 a 0610135 a 06
10135 a 06Bố Su
 
An Effective Spam Protection System
An Effective Spam Protection SystemAn Effective Spam Protection System
An Effective Spam Protection SystemApollo_n
 

Ähnlich wie CoLabora - Exchange Online Protection - June 2015 (20)

KVH MailScan MX
KVH MailScan MXKVH MailScan MX
KVH MailScan MX
 
24 Hours Of Exchange Server 2007 ( Part 13 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 13 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 13 Of 24)
24 Hours Of Exchange Server 2007 ( Part 13 Of 24)
 
La seguridad sí importa: Windows Live & IE9
La seguridad sí importa: Windows Live & IE9La seguridad sí importa: Windows Live & IE9
La seguridad sí importa: Windows Live & IE9
 
Technical Background Overview Ppt
Technical Background Overview PptTechnical Background Overview Ppt
Technical Background Overview Ppt
 
EmailTracing.ppt
EmailTracing.pptEmailTracing.ppt
EmailTracing.ppt
 
TechNet Webcast: Exchange 2010 Outlook Web Access
TechNet Webcast: Exchange 2010 Outlook Web AccessTechNet Webcast: Exchange 2010 Outlook Web Access
TechNet Webcast: Exchange 2010 Outlook Web Access
 
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
 
Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)Symantec AntiSpam Complete Overview (PowerPoint)
Symantec AntiSpam Complete Overview (PowerPoint)
 
10135 a 05
10135 a 0510135 a 05
10135 a 05
 
Ironport Data Loss Prevention
Ironport Data Loss PreventionIronport Data Loss Prevention
Ironport Data Loss Prevention
 
E-Mail - Technical Overview
E-Mail - Technical OverviewE-Mail - Technical Overview
E-Mail - Technical Overview
 
Exchange 2007 Overview Son Vu
Exchange 2007 Overview Son VuExchange 2007 Overview Son Vu
Exchange 2007 Overview Son Vu
 
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
 
CensorNet MailSafe
CensorNet MailSafeCensorNet MailSafe
CensorNet MailSafe
 
What You Need to Know About Email Authentication
What You Need to Know About Email AuthenticationWhat You Need to Know About Email Authentication
What You Need to Know About Email Authentication
 
Improving email reliability
Improving email reliabilityImproving email reliability
Improving email reliability
 
B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the Inbox
 
Abaca: The World's Most Effective Spam Filter
Abaca: The World's Most Effective Spam FilterAbaca: The World's Most Effective Spam Filter
Abaca: The World's Most Effective Spam Filter
 
10135 a 06
10135 a 0610135 a 06
10135 a 06
 
An Effective Spam Protection System
An Effective Spam Protection SystemAn Effective Spam Protection System
An Effective Spam Protection System
 

Mehr von CoLaboraDK

Managing enterprise applications, permissions, and consent in Azure Active Di...
Managing enterprise applications, permissions, and consent in Azure Active Di...Managing enterprise applications, permissions, and consent in Azure Active Di...
Managing enterprise applications, permissions, and consent in Azure Active Di...CoLaboraDK
 
Secure Communication with Office 365
Secure Communication with Office 365Secure Communication with Office 365
Secure Communication with Office 365CoLaboraDK
 
OneDrive for Business - Summer update
OneDrive for Business - Summer updateOneDrive for Business - Summer update
OneDrive for Business - Summer updateCoLaboraDK
 
Azure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSOAzure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSOCoLaboraDK
 
CoLabora - Hybrid inside out - Nov 2015
CoLabora - Hybrid inside out - Nov 2015CoLabora - Hybrid inside out - Nov 2015
CoLabora - Hybrid inside out - Nov 2015CoLaboraDK
 
CoLabora - Identity in a World of Cloud - november 2015
CoLabora - Identity in a World of Cloud - november 2015CoLabora - Identity in a World of Cloud - november 2015
CoLabora - Identity in a World of Cloud - november 2015CoLaboraDK
 
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLaboraDK
 
CoLabora - Skype for Business upgrade
CoLabora - Skype for Business upgradeCoLabora - Skype for Business upgrade
CoLabora - Skype for Business upgradeCoLaboraDK
 
CoLabora - Protecting Company data using EMS - June 2015
CoLabora - Protecting Company data using EMS - June 2015CoLabora - Protecting Company data using EMS - June 2015
CoLabora - Protecting Company data using EMS - June 2015CoLaboraDK
 
CoLabora - Identity in a World of Cloud - June 2015
CoLabora - Identity in a World of Cloud - June 2015CoLabora - Identity in a World of Cloud - June 2015
CoLabora - Identity in a World of Cloud - June 2015CoLaboraDK
 

Mehr von CoLaboraDK (10)

Managing enterprise applications, permissions, and consent in Azure Active Di...
Managing enterprise applications, permissions, and consent in Azure Active Di...Managing enterprise applications, permissions, and consent in Azure Active Di...
Managing enterprise applications, permissions, and consent in Azure Active Di...
 
Secure Communication with Office 365
Secure Communication with Office 365Secure Communication with Office 365
Secure Communication with Office 365
 
OneDrive for Business - Summer update
OneDrive for Business - Summer updateOneDrive for Business - Summer update
OneDrive for Business - Summer update
 
Azure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSOAzure PTA vs ADFS vs Desktop SSO
Azure PTA vs ADFS vs Desktop SSO
 
CoLabora - Hybrid inside out - Nov 2015
CoLabora - Hybrid inside out - Nov 2015CoLabora - Hybrid inside out - Nov 2015
CoLabora - Hybrid inside out - Nov 2015
 
CoLabora - Identity in a World of Cloud - november 2015
CoLabora - Identity in a World of Cloud - november 2015CoLabora - Identity in a World of Cloud - november 2015
CoLabora - Identity in a World of Cloud - november 2015
 
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange ArchivingCoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
CoLabora Nov 2015 - Ofice 365 Compliance and Exchange Archiving
 
CoLabora - Skype for Business upgrade
CoLabora - Skype for Business upgradeCoLabora - Skype for Business upgrade
CoLabora - Skype for Business upgrade
 
CoLabora - Protecting Company data using EMS - June 2015
CoLabora - Protecting Company data using EMS - June 2015CoLabora - Protecting Company data using EMS - June 2015
CoLabora - Protecting Company data using EMS - June 2015
 
CoLabora - Identity in a World of Cloud - June 2015
CoLabora - Identity in a World of Cloud - June 2015CoLabora - Identity in a World of Cloud - June 2015
CoLabora - Identity in a World of Cloud - June 2015
 

Kürzlich hochgeladen

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesBoston Institute of Analytics
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 

CoLabora - Exchange Online Protection - June 2015

  • 1. Peter Schmidt Solution Architect, EG A/S Exchange Online Protection Introduction and Architecture
  • 2. About me © EG A/S 2 Peter Schmidt Solution Architect, EG A/S Expertise: Office 365, Exchange, Skype for Business, Microsoft Azure, ADFS, PKI Microsoft MVP: Exchange, MCM: Exchange MCSE: Messaging, MCSA: Office 365 MCSE: Server Infrastructure, MCSE: Public Cloud Contact me: E-mail: pesch@eg.dk Blog: www.msdigest.net Twitter: @petsch Phone: +45 7260 2775/+45 2080 9436
  • 3. Agenda © EG A/S 3  Introduction to Exchange Online Protection  EOP Architecture  Deployment  Best Practices  Summary  Q&A
  • 5. Stop viruses and malware  Multi-engine malware protection  Continuously evolving anti-spam protection Protect sensitive data  Data Loss Prevention features  Encryption of sensitive email Common administration console  Office 365 integration  Detailed reporting Enterprise class reliability  Geographically load-balanced datacenters  Queuing capabilities to help ensure no mail is lost  24x7x365 Microsoft Support  $$$ backed SLA Exchange Online Protection (EOP)
  • 6. • Mail Delivery • 99.999% EOP uptime • Geo-redundant network • 24/7 Live phone and web technical support • Message queuing for 2 days if customer server unresponsive • Filtering Performance • 100% known virus detection (active payload) • 99% spam detection rate • False positive ratio of less than 1:250,000 messages EOP Service Level Agreements
  • 8. On-premises server - Inbound and Outbound email filtered through EOP EOP Conceptual Diagram Corporate NetworkEOP
  • 9. Works with any SMTP email platform! Every Office 365 customer is an EOP customer Easy transition from EOP stand-alone to Office 365 On-premises server - Inbound and Outbound email filtered through EOP EOP Deployment scenarios 6 On Premise Corporate Network EOP O365 Exchange Online
  • 10. EOP Inbound filtering Email is routed to EOP DC’s based on MX record resolution (contoso-com.mail.protection.outlook.com) IP-based edge blocking Reputation blocking Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 SPAM protection Safe Sender/Recipient Policy enforcement Custom Rules Content scanning and Heuristics Bulk Mail filtering SPF & Sender ID Filter Quarantine *International Spam* Advanced SPAM management Customer feedback False +ve / -ve Spam analysts Corporate network Regular expressions URL block lists Envelope blocks Forefront blocks Allows/Rejects
  • 11. Outbound Pool Outbound Pool EOP Outbound filtering High Risk Delivery PoolHigh Score Outbound Pool Low ScoreSPAM protection Content scanning and Heuristics Advanced SPAM management Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 Policy enforcement Custom Rules Quarantine Spam Analysts Corporatenetwork Bulk Delivery Pool Bulk Mail Internet Email Encryption
  • 13. • Phishing Campaigns • Spear Phishing (APT) • Bulk Mail • Backscatter • Malware Distribution • Image Spam Different Types of SPAM
  • 14. 1. Connection filtering Blocks up to 80% of all spam based on IP block/allow lists. 2. Sender-Recipient Filtering Blocks up to 15% of all spam based on internal lists and sender reputation. 3. Content Filtering Blocks up to 5% of all spam based on internal lists and heuristics. Multi-layered anti-spam protection 14
  • 15. Connection filtering  Static IP allow/block list  Opt-in to Microsoft-maintained reputable sender list Content spam categories  Obvious spam  High confidence spam Content Filtering Actions  Delete  Quarantine  Add X-Header  Modify Subject  Redirect Granular anti-spam filtering controls 15
  • 16. Block external threats quickly Advanced fingerprinting technologies that identify and stop new spam and phishing vectors in real time. Enable more control Mark all bulk messages as spam Block unwanted email based on language or geographic origin Block email based on language Block email based on geography Effective spam blocking
  • 17. • Suspect junk mail by default goes to the Outlook junk mail folder. • Uses Outlook safe senders and block lists. • SPAM Quarantine was currently available to administrators only. End user quarantine rolled out NOW! • Email Spam Notification for the end-users Junk mail management
  • 18. End User Quarantine • End users can release from quarantine • Report Spam, not spam Quarantine
  • 19. Set Frequency from 1-15 days End User Spam Notification
  • 20. False Negatives and False Positives Outlook Junk Mail Reporting Tool for missed spam http://www.microsoft.com/en- us/download/details.aspx?id=18275 Send spam email as an attachment to abuse@messaging.microsoft.com Send false positive messages to false_positive@messaging.microsoft.c om
  • 22. Standalone All mailboxes are located on-premises Purchasable on its own or Part of Exchange Enterprise CAL with Services Fully hosted All mailboxes are hosted in the cloud with Microsoft Exchange Online Exchange Online license Hybrid Some mailboxes are hosted in Exchange Online, and some mailboxes on-premises Exchange Online license EOP deployment scenarios
  • 23. Overview of the deployment process Step 1: Verify prerequisites Step 2: Configure mail flow (connectors) Step 3: Add and validate domains Step 4: Customize spam and policy settings Step 5: Enable mail flow Step 6: Monitor and fine tune
  • 24. Applicable to all scenarios  Office 365 Tenant – name.onmicrosoft.com  EOP licenses (ExO or EOP Standalone)  Domain to migrate  Modern web browser to access the Office 365 portal Applicable to Standalone or Hybrid scenarios  Inbound and outbound public IP addresses  Open port 25 to Exchange Online Protection IP Addresses  Information on TLS policy, attachment handling, junk folder use, etc.  DirSync may require additional hardware Prerequisites
  • 25. Standalone  Create EOP outbound connector to deliver mail on-premises  Create EOP inbound connector to accept mail from on-premises  Create on-premises send connector to send outgoing mail to EOP Hybrid  Hybrid mail flow is best configured using the Hybrid Configuration Wizard Optional for all scenarios  Create connectors for forced TLS to third party  Create connectors for customized mail routing Configure mail flow
  • 26. On-Prem Mail Environment Exchange Online Protection Outbound Connector Inbound Connector Outbound TLS Connector Inbound TLS Connector EOP connectors between on-premises and EOP need to be created *Additional connectors can be created between EOP and partners to force TLS Partner Environment Configure mail flow (connectors)
  • 27. With EOP (Fabrikam uses EOP) TLS scenario Prior to EOP (Fabrikam uses EOP) Contoso FabrikamCert CN = mail.contoso.com Cert CN = mail.fabrikam.com Contoso EOP FabrikamCert CN = mail.contoso.com Cert CN = mail.protection.outlook.com Cert CN = mail.protection.outlook.com Cert CN = mail.fabrikam.com
  • 28. Configure mail flow (connectors) On-Prem Mail APAC Exchange Online Protection On-Prem Mail AMER On-Prem Mail EMEA Outbound Connector 1 Outbound Connector 3 Outbound Connector 2 Inbound Connector 1
  • 29. Policies Anti-spam, anti-malware and DLP controls integrated into the Exchange Admin Center and Office 365.
  • 30. • What it does • Blocks messages to invalid recipients at the EOP edge • Beneficial to organizations with on-premises mailboxes • Configuration • The EAC exposes two domain types. • Authoritative - All email for unknown recipients is rejected. Setting this domain type enables DBEB • Internal relay - Email is delivered to recipients in your org or relayed to another email server • To enable DBEB, set the domain to be AUTHORITATIVE. Directory Based Edge Blocking
  • 32. Reporting Provides a clear view on spam filtering and malware attacks E-mail Protection Reports Excel Workbook available to enable self- service analysis Connects to the reporting web service Data can be refreshed from within the workbook at any time Drill through from recent summary data to the underlying detailed information
  • 33. • Goals • Is the service operating as expected? • Make adjustments to rules or settings as needed • Evaluate effectiveness of spam settings • Tools • Reports (Office 365 Portal or Mail Protection Reports for Office 365) • Submitting spam and false positive messages to Microsoft • Junk Mail Reporting Tool for Outlook Monitor and fine tune
  • 35. • Do this • Use a test domain, subdomain or low volume domain for trying different service features • Disable EOP inbound connector (type is on-prem) until you are ready to use it • Use the Remote Connectivity Analyzer to troubleshoot • Restrict inbound SMTP access to allow ONLY from EOP IP ranges • Enable Microsoft’s IP Safe List in the Connection Filter • When creating safe / black lists, use IP first, and if not possible, then use the domain • Don’t do this • Daisy chain services • Use EOP for sending bulk mail • Enable all Content Filter Advanced Options out of the box • Safe list your own domain Best practices
  • 36. Telnet is your friend Telnet can be used to test mail flow from EOP to your on-prem environment. This allows verifying mail flow will work before doing the MX cutover. Test mail flow before MX change You do/type this Server responds with this telnet tenantDomainMXRecordHere 25 220 helo your_sending_server_fqdn 250 mail from: you@domain.invalid 250 Sender OK rcpt to: recipient@contoso.com 250 Recipient OK data followed by the enter key Server provides directions on how to enter data. subject: Enter the subject and hit enter twice Enter the body text. To finish the message, type a period on a line by itself and hit enter. 250 Message queued for delivery.
  • 37. • Quarantine • Online viewer only supports up to 500 messages • More can be viewed via PowerShell Get-QuarantineMessage Cmdlet • Can only release in bulk through Release-QuarantineMessage Cmdlet • Limits • Max message size for EOP delivering to stand-alone customers is 150 MB • Max 100 Transport Rules per tenant – DLP policies consume part of this quota • Max of 900 domains per tenant • EOP outbound connectors use round robin for delivery Known Issues & Limitations
  • 38. No Am APAC EMEA Mail is ALWAYS processed ONLY in your region! PRC
  • 39. • Protection against unknown malware and viruses by analyzing attachment behavior in a hypervisor environment before delivering them • Real time, time-of-click protection against malicious URLs that are not yet known by EOP • Rich reporting and tracing of URL click throughs • 2$ / month per user Advanced Threat Protection
  • 40. EOP Architecture Test drive it Know the limitations of EOP Summary