SlideShare a Scribd company logo
1 of 41
Online Conference
June 17th and 18th 2015
WWW.COLLAB365.EVENTS
How to deploy Exchange Online
Protection
WWW.COLLAB365.EVENTS
Peter Schmidt
EG A/S, Denmark
Email : pesch@eg.dk
Twitter : @petsch
Blog : www.msdigest.net
https://dk.linkedin.com/in/petsch
• Cloud and Infrastructure
Architect
• 15+ years of experience
with Exchange Server
• Microsoft Certified
Master: Exchange
• Microsoft MVP: Exchange
WWW.COLLAB365.EVENTS
Introduction
EOP Architecture
Antispam and Deployment
Reporting and Best Practice
Summary
and Q&A
Agenda
WWW.COLLAB365.EVENTS
Introduction to
Exchange Online Protection
WWW.COLLAB365.EVENTS
Stop viruses and malware
 Multi-engine malware protection
 Continuously evolving anti-spam protection
Protect sensitive data
 Data Loss Prevention features
 Encryption of sensitive email
Common administration console
 Office 365 integration
 Detailed reporting
Enterprise class reliability
 Geographically load-balanced datacenters
 Queuing capabilities to help ensure no mail is lost
 24x7x365 Microsoft Support
 $$$ backed SLA
Exchange Online Protection (EOP)
WWW.COLLAB365.EVENTS
EOP Service Level Agreements (SLA)
• Mail Delivery
• 99.999% EOP uptime
• Geo-redundant network
• 24/7 Live phone and web technical support
• Message queuing for 2 days if customer server
unresponsive
WWW.COLLAB365.EVENTS
EOP Architecture
WWW.COLLAB365.EVENTS
• On-premises server - Inbound and Outbound
email filtered through EOP
EOP Conceptual Diagram
CorporateNetworkEOP
WWW.COLLAB365.EVENTS
• Works with any SMTP email platform!
• Every Office 365 customer is an EOP customer
• Easy transition from EOP stand-alone to Office 365
• On-premises server
• - Inbound and Outbound email filtered through EOP
EOP Deployment scenarios
6
OnPremise
CorporateNetwork
EOP
O365
ExchangeOnline
WWW.COLLAB365.EVENTS
EOP Inbound filtering
Email is routed to EOP DC’s based on MX record resolution
(contoso-com.mail.protection.outlook.com)
IP-based edge blocking
Reputation blocking
Virus
scanning
AV Engine 1
AV Engine 2
AV Engine 3
SPAM protection
Safe Sender/Recipient
Policy enforcement
Custom Rules
Content scanning and Heuristics
Bulk Mail filtering
SPF & Sender ID Filter
Quarantine
*International Spam*
Advanced SPAM management
Customer feedback
False +ve / -ve
Spam analysts
Corporatenetwork
Regular expressions
URL block lists
Envelope blocks
Forefront blocks
Allows/Rejects
WWW.COLLAB365.EVENTS
Outbound Pool
Outbound Pool
EOP Outbound filtering
High Risk Delivery PoolHigh Score
Outbound Pool
Low ScoreSPAM protection
Content scanning and Heuristics
Advanced SPAM management
Virus
scanning
AV Engine 1
AV Engine 2
AV Engine 3
Policy enforcement
Custom Rules
Quarantine
Spam Analysts
Corporatenetwork
Bulk Delivery Pool
Bulk Mail
Internet
Email Encryption
WWW.COLLAB365.EVENTS
Anti-spam
WWW.COLLAB365.EVENTS
• Phishing Campaigns
• Spear Phishing (APT)
• Bulk Mail
• Backscatter
• Malware Distribution
• Image Spam
Different Types of SPAM
WWW.COLLAB365.EVENTS
• 1. Connection filtering
– Blocks up to 80% of all spam based on IP block/allow lists.
• 2. Sender-Recipient Filtering
– Blocks up to 15% of all spam based on internal lists and sender reputation.
• 3. Content Filtering
– Blocks up to 5% of all spam based on internal lists and heuristics.
Multi-layered anti-spam protection
14
WWW.COLLAB365.EVENTS
• Connection filtering
 Static IP allow/block list
 Opt-in to Microsoft-maintained reputable sender list
• Content spam categories
 Obvious spam
 High confidence spam
• Content Filtering Actions
 Delete
 Quarantine
 Add X-Header
 Modify Subject
 Redirect
Granular anti-spam filtering controls
15
WWW.COLLAB365.EVENTS
•Block external threats quickly
–Advancedfingerprintingtechnologiesthatidentifyand
stopnewspamandphishingvectorsin realtime.
•Enable more control
–Markallbulkmessagesasspam
–Blockunwantedemailbasedonlanguageorgeographic
origin
•Effective spam
blocking
Block email based on language
Block email based on geography
WWW.COLLAB365.EVENTS
• Suspect junk mail by default goes to the Outlook junk mail folder.
• Uses Outlook safe senders and block lists.
• SPAM Quarantine was currently available to administrators only.
End user quarantine rolled out NOW!
• Email Spam Notification for the end-users
Junk mail management
WWW.COLLAB365.EVENTS
• End User Quarantine
• End users can release
from quarantine
• Report Spam, not
spam
Quarantine
WWW.COLLAB365.EVENTS
• Set Frequency from 1-15 days
End User Spam Notification
WWW.COLLAB365.EVENTS
False Negatives and False Positives
• Outlook Junk Mail
Reporting Tool for missed
spam
• http://www.microsoft.com/en-
us/download/details.aspx?id=18275
• Send spam email as an
attachment to
abuse@messaging.microsoft.com
• Send false positive
messages to
false_positive@messaging.micros
oft.com
WWW.COLLAB365.EVENTS
Deployment
WWW.COLLAB365.EVENTS
• Standalone
All mailboxes are located on-premises
• Purchasable on its own or Part of Exchange Enterprise CAL with Services
• Fully hosted
• All mailboxes are hosted in the cloud with Microsoft Exchange Online
Exchange Online license
Hybrid
Some mailboxes are hosted in Exchange Online, and some mailboxes on-premises
• Exchange Online license
EOP deployment scenarios
WWW.COLLAB365.EVENTS
Overview of the deployment process
Step 1: Verify prerequisites
Step 2: Configure mail flow (connectors)
Step 3: Add and validate domains
Step 4: Customize spam and policy settings
Step 5: Enable mail flow
Step 6: Monitor and fine tune
WWW.COLLAB365.EVENTS
Applicable to all scenarios
 Office 365 Tenant – name.onmicrosoft.com
 EOP licenses (ExO or EOP Standalone)
 Domain to migrate
 Modern web browser to access the Office 365 portal
Applicable to Standalone or Hybrid scenarios
 Inbound and outbound public IP addresses
 Open port 25 to Exchange Online Protection IP Addresses
 Information on TLS policy, attachment handling, junk folder use, etc.
 DirSync may require additional hardware
Prerequisites
WWW.COLLAB365.EVENTS
Standalone
 Create EOP outbound connector to deliver mail on-premises
 Create EOP inbound connector to accept mail from on-premises
 Create on-premises send connector to send outgoing mail to EOP
Hybrid
 Hybrid mail flow is best configured using the Hybrid Configuration Wizard
Optional for all scenarios
 Create connectors for forced TLS to third party
 Create connectors for customized mail routing
Configure mail flow
WWW.COLLAB365.EVENTS
On-Prem Mail
Environment
Exchange Online
Protection
Outbound Connector
Inbound Connector
Outbound TLS
Connector
Inbound TLS
Connector
EOP connectors between on-premises and EOP need to be created
Additional connectors can be created between EOP and partners to force TLS
Partner
Environment
Configure mail flow (connectors)
WWW.COLLAB365.EVENTS
• With EOP (Fabrikam uses EOP)
TLS scenario
• Prior to EOP (Fabrikam uses EOP)
Contoso FabrikamCert CN = mail.contoso.com
Cert CN = mail.fabrikam.com
Contoso EOP FabrikamCert CN = mail.contoso.com
Cert CN = mail.protection.outlook.com
Cert CN = mail.protection.outlook.com
Cert CN = mail.fabrikam.com
WWW.COLLAB365.EVENTS
Configure mail flow (connectors)
On-Prem Mail
APAC
Exchange Online
Protection
On-Prem Mail
AMER
On-Prem Mail
EMEA
Outbound
Connector 1
Outbound
Connector 3
Outbound
Connector 2
Inbound
Connector 1
WWW.COLLAB365.EVENTS
• What it does
• Blocks messages to invalid recipients at the EOP edge
• Beneficial to organizations with on-premises mailboxes
• Configuration
• The EAC exposes two domain types.
• Authoritative - All email for unknown recipients is rejected. Setting this domain type enables DBEB
• Internal relay - Email is delivered to recipients in your org or relayed to another email server
• To enable DBEB, set the domain to be AUTHORITATIVE.
Directory Based Edge Blocking
WWW.COLLAB365.EVENTS
Reporting
WWW.COLLAB365.EVENTS
Reporting
• Provides a clear view on
spam filtering and malware
attacks
• E-mail Protection Reports
– Excel Workbook available to enable self-service
analysis
– Connects to the reporting web service
– Data can be refreshed from within the workbook
at any time
– Drill through from recent summary data to the
underlying detailed information
WWW.COLLAB365.EVENTS
• Goals
• Is the service operating as expected?
• Make adjustments to rules or settings as needed
• Evaluate effectiveness of spam settings
• Tools
• Reports (Office 365 Portal or Mail Protection Reports for Office 365)
• Submitting spam and false positive messages to Microsoft
• Junk Mail Reporting Tool for Outlook
Monitor and fine tune
WWW.COLLAB365.EVENTS
Best Practices
WWW.COLLAB365.EVENTS
• Do this
• Use a test domain, subdomain or low volume domain for trying different service features
• Disable EOP inbound connector (type is on-prem) until you are ready to use it
• Use the Remote Connectivity Analyzer to troubleshoot
• Restrict inbound SMTP access to allow ONLY from EOP IP ranges
• Enable Microsoft’s IP Safe List in the Connection Filter
• When creating safe / black lists, use IP first, and if not possible, then use the domain
• Don’t do this
• Daisy chain services
• Use EOP for sending bulk mail
• Enable all Content Filter Advanced Options out of the box
• Safe list your own domain
Best practices
WWW.COLLAB365.EVENTS
Telnet is your friend
Test mail flow before MX change
You do/type this Server responds with this
telnet tenantDomainMXRecordHere 25 220
helo your_sending_server_fqdn 250
mail from: you@domain.invalid 250 Sender OK
rcpt to: recipient@contoso.com 250 Recipient OK
data followed by the enter key Server provides directions on
how to enter data.
subject: Enter the subject and hit
enter twice
Enter the body text. To finish the
message, type a period on a line by
itself and hit enter.
250 Message queued for
delivery.
Quit 221 Service closing
transmission channel
WWW.COLLAB365.EVENTS
• Quarantine
• Online viewer only supports up to 500 messages
• More can be viewed via PowerShell Get-QuarantineMessage Cmdlet
• Can only release in bulk through Release-QuarantineMessage Cmdlet
• Limits
• Max message size for EOP delivering to stand-alone customers is 150 MB
• Max 100 Transport Rules per tenant – DLP policies consume part of this quota
• Max of 900 domains per tenant
• EOP outbound connectors use round robin for delivery
Known Issues & Limitations
WWW.COLLAB365.EVENTS
No Am
APAC
EMEA
Mail is ALWAYS processed ONLY in your region!
PRC
WWW.COLLAB365.EVENTS
• Protection against unknown malware and viruses by analyzing attachment
behavior in a hypervisor environment before delivering them
• Real time, time-of-click protection against malicious URLs that are not yet
known by EOP
• Rich reporting and tracing of URL click throughs
• 2$ / month per user
Advanced Threat Protection
WWW.COLLAB365.EVENTS
• EOP Architecture
• Test drive it
• Know the limitations of EOP
Summary
WWW.COLLAB365.EVENTS
Questions
Feel free to contact me on:
• @petsch
• peter@msdigest.net
• www.msdigest.net
WWW.COLLAB365.EVENTS
Stay tuned for more great sessions …

More Related Content

What's hot

Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and ComplianceDavid J Rosenthal
 
Microsoft Azure Information Protection
Microsoft Azure Information Protection Microsoft Azure Information Protection
Microsoft Azure Information Protection Syed Sabhi Haider
 
Microsoft Information Protection.pptx
Microsoft Information Protection.pptxMicrosoft Information Protection.pptx
Microsoft Information Protection.pptxChrisaldyChandra
 
Institucional proofpoint
Institucional proofpointInstitucional proofpoint
Institucional proofpointvoliverio
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewDavid J Rosenthal
 
Microsoft Office 365
Microsoft Office 365Microsoft Office 365
Microsoft Office 365Novosco
 
DLP Data leak prevention
DLP Data leak preventionDLP Data leak prevention
DLP Data leak preventionAriel Evans
 
Microsoft 365 Business - Presented by Razor Technology
Microsoft 365 Business - Presented by Razor TechnologyMicrosoft 365 Business - Presented by Razor Technology
Microsoft 365 Business - Presented by Razor TechnologyDavid J Rosenthal
 
Microsoft office 365
Microsoft office 365Microsoft office 365
Microsoft office 365AlOmourAli
 
Microsoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelMicrosoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelDavid J Rosenthal
 
Information Security Awareness
Information Security Awareness Information Security Awareness
Information Security Awareness SnapComms
 
Data Loss Threats and Mitigations
Data Loss Threats and MitigationsData Loss Threats and Mitigations
Data Loss Threats and MitigationsApril Mardock CISSP
 
Threat Hunting - Moving from the ad hoc to the formal
Threat Hunting - Moving from the ad hoc to the formalThreat Hunting - Moving from the ad hoc to the formal
Threat Hunting - Moving from the ad hoc to the formalPriyanka Aash
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDrew Madelung
 

What's hot (20)

Azure information protection
Azure information protectionAzure information protection
Azure information protection
 
Data Leakage Prevention (DLP)
Data Leakage Prevention (DLP)Data Leakage Prevention (DLP)
Data Leakage Prevention (DLP)
 
Office 365 Security Best Practices
Office 365 Security Best PracticesOffice 365 Security Best Practices
Office 365 Security Best Practices
 
Microsoft 365 Security and Compliance
Microsoft 365 Security and ComplianceMicrosoft 365 Security and Compliance
Microsoft 365 Security and Compliance
 
Microsoft Azure Information Protection
Microsoft Azure Information Protection Microsoft Azure Information Protection
Microsoft Azure Information Protection
 
Mail flow in Exchange Online
Mail flow in Exchange OnlineMail flow in Exchange Online
Mail flow in Exchange Online
 
Microsoft Information Protection.pptx
Microsoft Information Protection.pptxMicrosoft Information Protection.pptx
Microsoft Information Protection.pptx
 
DMARC Overview
DMARC OverviewDMARC Overview
DMARC Overview
 
Institucional proofpoint
Institucional proofpointInstitucional proofpoint
Institucional proofpoint
 
Microsoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security OverviewMicrosoft 365 Compliance and Security Overview
Microsoft 365 Compliance and Security Overview
 
Microsoft Office 365
Microsoft Office 365Microsoft Office 365
Microsoft Office 365
 
DLP Data leak prevention
DLP Data leak preventionDLP Data leak prevention
DLP Data leak prevention
 
Microsoft 365 Business - Presented by Razor Technology
Microsoft 365 Business - Presented by Razor TechnologyMicrosoft 365 Business - Presented by Razor Technology
Microsoft 365 Business - Presented by Razor Technology
 
Microsoft office 365
Microsoft office 365Microsoft office 365
Microsoft office 365
 
Microsoft Defender and Azure Sentinel
Microsoft Defender and Azure SentinelMicrosoft Defender and Azure Sentinel
Microsoft Defender and Azure Sentinel
 
Information Security Awareness
Information Security Awareness Information Security Awareness
Information Security Awareness
 
Data Loss Threats and Mitigations
Data Loss Threats and MitigationsData Loss Threats and Mitigations
Data Loss Threats and Mitigations
 
Security Awareness Training by Fortinet
Security Awareness Training by FortinetSecurity Awareness Training by Fortinet
Security Awareness Training by Fortinet
 
Threat Hunting - Moving from the ad hoc to the formal
Threat Hunting - Moving from the ad hoc to the formalThreat Hunting - Moving from the ad hoc to the formal
Threat Hunting - Moving from the ad hoc to the formal
 
Deep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss PreventionDeep dive into Microsoft Purview Data Loss Prevention
Deep dive into Microsoft Purview Data Loss Prevention
 

Viewers also liked

CoLabora - Exchange Online Protection - June 2015
CoLabora - Exchange Online Protection - June 2015 CoLabora - Exchange Online Protection - June 2015
CoLabora - Exchange Online Protection - June 2015 CoLaboraDK
 
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...Microsoft Private Cloud
 
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft Private Cloud
 
Microsoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsDavid J Rosenthal
 
EMS×Windows10×Office 365で実現するセキュリティ強化
EMS×Windows10×Office 365で実現するセキュリティ強化EMS×Windows10×Office 365で実現するセキュリティ強化
EMS×Windows10×Office 365で実現するセキュリティ強化Mari Miyakawa
 
The Future of Exchange (Online)
The Future of Exchange (Online)The Future of Exchange (Online)
The Future of Exchange (Online)Joel Brda
 
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...Bruno Lopes
 
Windows 7 Seminar - Acend Corporate Learning
Windows 7 Seminar - Acend Corporate LearningWindows 7 Seminar - Acend Corporate Learning
Windows 7 Seminar - Acend Corporate LearningAcend Corporate Learning
 
Extending The Enterprise With Office 365
Extending The Enterprise With Office 365Extending The Enterprise With Office 365
Extending The Enterprise With Office 365Richard Harbridge
 
Microsoft Exchange 2010 Upgrade Seminar March 2010
Microsoft Exchange 2010 Upgrade   Seminar March 2010Microsoft Exchange 2010 Upgrade   Seminar March 2010
Microsoft Exchange 2010 Upgrade Seminar March 2010hagestadwt
 
Nathan Winters The Future Of Email Exchange And Online Services
Nathan Winters   The Future Of Email Exchange And Online ServicesNathan Winters   The Future Of Email Exchange And Online Services
Nathan Winters The Future Of Email Exchange And Online ServicesNathan Winters
 
Exchange online real world migration challenges
Exchange online real world migration challengesExchange online real world migration challenges
Exchange online real world migration challengesSteve Goodman
 
Sistemas flexíveis de produção
Sistemas flexíveis de produçãoSistemas flexíveis de produção
Sistemas flexíveis de produçãoJoemille Leal
 
Tips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineTips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineSteve Goodman
 
When To Use What In Office 365 (Enterprise User Guidance)
When To Use What In Office 365 (Enterprise User Guidance)When To Use What In Office 365 (Enterprise User Guidance)
When To Use What In Office 365 (Enterprise User Guidance)Richard Harbridge
 
Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...ITProceed
 
Microsoft Exchange 2013 Introduction
Microsoft Exchange 2013 IntroductionMicrosoft Exchange 2013 Introduction
Microsoft Exchange 2013 IntroductionMotty Ben Atia
 
Better together: Enterprise Vault.cloud and Microsoft Office 365
Better together: Enterprise Vault.cloud and Microsoft Office 365Better together: Enterprise Vault.cloud and Microsoft Office 365
Better together: Enterprise Vault.cloud and Microsoft Office 365proutley
 

Viewers also liked (20)

CoLabora - Exchange Online Protection - June 2015
CoLabora - Exchange Online Protection - June 2015 CoLabora - Exchange Online Protection - June 2015
CoLabora - Exchange Online Protection - June 2015
 
Overview of Microsoft Exchange Online
Overview of Microsoft Exchange OnlineOverview of Microsoft Exchange Online
Overview of Microsoft Exchange Online
 
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...Microsoft Forefront - Secure Messaging &  Online Protection for Exchange Over...
Microsoft Forefront - Secure Messaging & Online Protection for Exchange Over...
 
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
Microsoft India – Unified Communications Exchange Server 2010 Information Pro...
 
Microsoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform OptionsMicrosoft Exchange 2013 Platform Options
Microsoft Exchange 2013 Platform Options
 
EMS×Windows10×Office 365で実現するセキュリティ強化
EMS×Windows10×Office 365で実現するセキュリティ強化EMS×Windows10×Office 365で実現するセキュリティ強化
EMS×Windows10×Office 365で実現するセキュリティ強化
 
The Future of Exchange (Online)
The Future of Exchange (Online)The Future of Exchange (Online)
The Future of Exchange (Online)
 
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...
Exchange Server e a Retenção de Litígio Local e na Nuvem (Litigation e InPlac...
 
Windows 7 Seminar - Acend Corporate Learning
Windows 7 Seminar - Acend Corporate LearningWindows 7 Seminar - Acend Corporate Learning
Windows 7 Seminar - Acend Corporate Learning
 
Extending The Enterprise With Office 365
Extending The Enterprise With Office 365Extending The Enterprise With Office 365
Extending The Enterprise With Office 365
 
Microsoft Exchange 2010 Upgrade Seminar March 2010
Microsoft Exchange 2010 Upgrade   Seminar March 2010Microsoft Exchange 2010 Upgrade   Seminar March 2010
Microsoft Exchange 2010 Upgrade Seminar March 2010
 
Nathan Winters The Future Of Email Exchange And Online Services
Nathan Winters   The Future Of Email Exchange And Online ServicesNathan Winters   The Future Of Email Exchange And Online Services
Nathan Winters The Future Of Email Exchange And Online Services
 
Exchange online real world migration challenges
Exchange online real world migration challengesExchange online real world migration challenges
Exchange online real world migration challenges
 
Sistemas flexíveis de produção
Sistemas flexíveis de produçãoSistemas flexíveis de produção
Sistemas flexíveis de produção
 
Tips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange OnlineTips and Tricks for Migrating to Exchange Online
Tips and Tricks for Migrating to Exchange Online
 
When To Use What In Office 365 (Enterprise User Guidance)
When To Use What In Office 365 (Enterprise User Guidance)When To Use What In Office 365 (Enterprise User Guidance)
When To Use What In Office 365 (Enterprise User Guidance)
 
Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...Office Track: Information Protection and Control in Exchange Online/On Premis...
Office Track: Information Protection and Control in Exchange Online/On Premis...
 
Microsoft Exchange 2013 Introduction
Microsoft Exchange 2013 IntroductionMicrosoft Exchange 2013 Introduction
Microsoft Exchange 2013 Introduction
 
Office 365
Office 365Office 365
Office 365
 
Better together: Enterprise Vault.cloud and Microsoft Office 365
Better together: Enterprise Vault.cloud and Microsoft Office 365Better together: Enterprise Vault.cloud and Microsoft Office 365
Better together: Enterprise Vault.cloud and Microsoft Office 365
 

Similar to How to deploy Exchange Online Protection

Top 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
Top 15 Exchange Questions that Senior Admin ask - Jaap WesseliusTop 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
Top 15 Exchange Questions that Senior Admin ask - Jaap WesseliusKemp
 
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...European Collaboration Summit
 
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosGina Montgomery, V-TSP
 
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...European Collaboration Summit
 
B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2BCamp
 
Zimbra APxJ Partner Summit 2017 - Showcase
Zimbra APxJ Partner Summit 2017 - ShowcaseZimbra APxJ Partner Summit 2017 - Showcase
Zimbra APxJ Partner Summit 2017 - ShowcaseZimbra
 
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...Amazon Web Services
 
Oleksandr Khotemskyi - Serverless architecture and how to apply it in Automa...
Oleksandr Khotemskyi  - Serverless architecture and how to apply it in Automa...Oleksandr Khotemskyi  - Serverless architecture and how to apply it in Automa...
Oleksandr Khotemskyi - Serverless architecture and how to apply it in Automa...Web Tech Fun
 
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...Dakiry
 
Email as a datasource for applications
Email as a datasource for applicationsEmail as a datasource for applications
Email as a datasource for applicationsContext.IO
 
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...Amazon Web Services
 
Enterprise Messaging with RabbitMQ.pdf
Enterprise Messaging with RabbitMQ.pdfEnterprise Messaging with RabbitMQ.pdf
Enterprise Messaging with RabbitMQ.pdfOrtus Solutions, Corp
 
Exchange 2013 Architecture Poster
Exchange 2013 Architecture PosterExchange 2013 Architecture Poster
Exchange 2013 Architecture PosterRian Yulian
 
Domino Fitness. Time for a Health Check
Domino Fitness. Time for a Health CheckDomino Fitness. Time for a Health Check
Domino Fitness. Time for a Health CheckJared Roberts
 
Office 365 Incident Response 2019 B-Sides Orlando
Office 365 Incident Response 2019 B-Sides OrlandoOffice 365 Incident Response 2019 B-Sides Orlando
Office 365 Incident Response 2019 B-Sides OrlandoAlex Parsons
 
Unit 3 - Protocols and Client-Server Applications - IT
Unit 3 - Protocols and Client-Server Applications - ITUnit 3 - Protocols and Client-Server Applications - IT
Unit 3 - Protocols and Client-Server Applications - ITDeepraj Bhujel
 
Improving email reliability
Improving email reliabilityImproving email reliability
Improving email reliabilityAntti Siiskonen
 
O365con14 - migrating your e-mail to the cloud
O365con14 - migrating your e-mail to the cloudO365con14 - migrating your e-mail to the cloud
O365con14 - migrating your e-mail to the cloudNCCOMMS
 

Similar to How to deploy Exchange Online Protection (20)

Top 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
Top 15 Exchange Questions that Senior Admin ask - Jaap WesseliusTop 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
Top 15 Exchange Questions that Senior Admin ask - Jaap Wesselius
 
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
 
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud ScenariosTake a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
Take a Leap into the Connected Cloud; 3 Trending Hybrid Cloud Scenarios
 
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...
ECS19 - Paul Collinge - Transforming enterprise network connectivity in a clo...
 
B2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the InboxB2B Email Deliverability - Getting to the Inbox
B2B Email Deliverability - Getting to the Inbox
 
Zimbra APxJ Partner Summit 2017 - Showcase
Zimbra APxJ Partner Summit 2017 - ShowcaseZimbra APxJ Partner Summit 2017 - Showcase
Zimbra APxJ Partner Summit 2017 - Showcase
 
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...
AWS re:Invent 2016: How Netflix Achieves Email Delivery at Global Scale with ...
 
SkyConnect
SkyConnectSkyConnect
SkyConnect
 
Oleksandr Khotemskyi - Serverless architecture and how to apply it in Automa...
Oleksandr Khotemskyi  - Serverless architecture and how to apply it in Automa...Oleksandr Khotemskyi  - Serverless architecture and how to apply it in Automa...
Oleksandr Khotemskyi - Serverless architecture and how to apply it in Automa...
 
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...
Олександр Хотемський:”Serverless архітектура та її застосування в автоматизац...
 
Email as a datasource for applications
Email as a datasource for applicationsEmail as a datasource for applications
Email as a datasource for applications
 
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...
AWS re:Invent 2016: Stop Managing Email Infrastructure: Move to Amazon WorkMa...
 
Enterprise Messaging with RabbitMQ.pdf
Enterprise Messaging with RabbitMQ.pdfEnterprise Messaging with RabbitMQ.pdf
Enterprise Messaging with RabbitMQ.pdf
 
Exchange 2013 Architecture Poster
Exchange 2013 Architecture PosterExchange 2013 Architecture Poster
Exchange 2013 Architecture Poster
 
Domino Fitness. Time for a Health Check
Domino Fitness. Time for a Health CheckDomino Fitness. Time for a Health Check
Domino Fitness. Time for a Health Check
 
KVH MailScan MX
KVH MailScan MXKVH MailScan MX
KVH MailScan MX
 
Office 365 Incident Response 2019 B-Sides Orlando
Office 365 Incident Response 2019 B-Sides OrlandoOffice 365 Incident Response 2019 B-Sides Orlando
Office 365 Incident Response 2019 B-Sides Orlando
 
Unit 3 - Protocols and Client-Server Applications - IT
Unit 3 - Protocols and Client-Server Applications - ITUnit 3 - Protocols and Client-Server Applications - IT
Unit 3 - Protocols and Client-Server Applications - IT
 
Improving email reliability
Improving email reliabilityImproving email reliability
Improving email reliability
 
O365con14 - migrating your e-mail to the cloud
O365con14 - migrating your e-mail to the cloudO365con14 - migrating your e-mail to the cloud
O365con14 - migrating your e-mail to the cloud
 

Recently uploaded

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 

Recently uploaded (20)

Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 

How to deploy Exchange Online Protection

  • 1. Online Conference June 17th and 18th 2015 WWW.COLLAB365.EVENTS How to deploy Exchange Online Protection
  • 2. WWW.COLLAB365.EVENTS Peter Schmidt EG A/S, Denmark Email : pesch@eg.dk Twitter : @petsch Blog : www.msdigest.net https://dk.linkedin.com/in/petsch • Cloud and Infrastructure Architect • 15+ years of experience with Exchange Server • Microsoft Certified Master: Exchange • Microsoft MVP: Exchange
  • 3. WWW.COLLAB365.EVENTS Introduction EOP Architecture Antispam and Deployment Reporting and Best Practice Summary and Q&A Agenda
  • 5. WWW.COLLAB365.EVENTS Stop viruses and malware  Multi-engine malware protection  Continuously evolving anti-spam protection Protect sensitive data  Data Loss Prevention features  Encryption of sensitive email Common administration console  Office 365 integration  Detailed reporting Enterprise class reliability  Geographically load-balanced datacenters  Queuing capabilities to help ensure no mail is lost  24x7x365 Microsoft Support  $$$ backed SLA Exchange Online Protection (EOP)
  • 6. WWW.COLLAB365.EVENTS EOP Service Level Agreements (SLA) • Mail Delivery • 99.999% EOP uptime • Geo-redundant network • 24/7 Live phone and web technical support • Message queuing for 2 days if customer server unresponsive
  • 8. WWW.COLLAB365.EVENTS • On-premises server - Inbound and Outbound email filtered through EOP EOP Conceptual Diagram CorporateNetworkEOP
  • 9. WWW.COLLAB365.EVENTS • Works with any SMTP email platform! • Every Office 365 customer is an EOP customer • Easy transition from EOP stand-alone to Office 365 • On-premises server • - Inbound and Outbound email filtered through EOP EOP Deployment scenarios 6 OnPremise CorporateNetwork EOP O365 ExchangeOnline
  • 10. WWW.COLLAB365.EVENTS EOP Inbound filtering Email is routed to EOP DC’s based on MX record resolution (contoso-com.mail.protection.outlook.com) IP-based edge blocking Reputation blocking Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 SPAM protection Safe Sender/Recipient Policy enforcement Custom Rules Content scanning and Heuristics Bulk Mail filtering SPF & Sender ID Filter Quarantine *International Spam* Advanced SPAM management Customer feedback False +ve / -ve Spam analysts Corporatenetwork Regular expressions URL block lists Envelope blocks Forefront blocks Allows/Rejects
  • 11. WWW.COLLAB365.EVENTS Outbound Pool Outbound Pool EOP Outbound filtering High Risk Delivery PoolHigh Score Outbound Pool Low ScoreSPAM protection Content scanning and Heuristics Advanced SPAM management Virus scanning AV Engine 1 AV Engine 2 AV Engine 3 Policy enforcement Custom Rules Quarantine Spam Analysts Corporatenetwork Bulk Delivery Pool Bulk Mail Internet Email Encryption
  • 13. WWW.COLLAB365.EVENTS • Phishing Campaigns • Spear Phishing (APT) • Bulk Mail • Backscatter • Malware Distribution • Image Spam Different Types of SPAM
  • 14. WWW.COLLAB365.EVENTS • 1. Connection filtering – Blocks up to 80% of all spam based on IP block/allow lists. • 2. Sender-Recipient Filtering – Blocks up to 15% of all spam based on internal lists and sender reputation. • 3. Content Filtering – Blocks up to 5% of all spam based on internal lists and heuristics. Multi-layered anti-spam protection 14
  • 15. WWW.COLLAB365.EVENTS • Connection filtering  Static IP allow/block list  Opt-in to Microsoft-maintained reputable sender list • Content spam categories  Obvious spam  High confidence spam • Content Filtering Actions  Delete  Quarantine  Add X-Header  Modify Subject  Redirect Granular anti-spam filtering controls 15
  • 16. WWW.COLLAB365.EVENTS •Block external threats quickly –Advancedfingerprintingtechnologiesthatidentifyand stopnewspamandphishingvectorsin realtime. •Enable more control –Markallbulkmessagesasspam –Blockunwantedemailbasedonlanguageorgeographic origin •Effective spam blocking Block email based on language Block email based on geography
  • 17. WWW.COLLAB365.EVENTS • Suspect junk mail by default goes to the Outlook junk mail folder. • Uses Outlook safe senders and block lists. • SPAM Quarantine was currently available to administrators only. End user quarantine rolled out NOW! • Email Spam Notification for the end-users Junk mail management
  • 18. WWW.COLLAB365.EVENTS • End User Quarantine • End users can release from quarantine • Report Spam, not spam Quarantine
  • 19. WWW.COLLAB365.EVENTS • Set Frequency from 1-15 days End User Spam Notification
  • 20. WWW.COLLAB365.EVENTS False Negatives and False Positives • Outlook Junk Mail Reporting Tool for missed spam • http://www.microsoft.com/en- us/download/details.aspx?id=18275 • Send spam email as an attachment to abuse@messaging.microsoft.com • Send false positive messages to false_positive@messaging.micros oft.com
  • 22. WWW.COLLAB365.EVENTS • Standalone All mailboxes are located on-premises • Purchasable on its own or Part of Exchange Enterprise CAL with Services • Fully hosted • All mailboxes are hosted in the cloud with Microsoft Exchange Online Exchange Online license Hybrid Some mailboxes are hosted in Exchange Online, and some mailboxes on-premises • Exchange Online license EOP deployment scenarios
  • 23. WWW.COLLAB365.EVENTS Overview of the deployment process Step 1: Verify prerequisites Step 2: Configure mail flow (connectors) Step 3: Add and validate domains Step 4: Customize spam and policy settings Step 5: Enable mail flow Step 6: Monitor and fine tune
  • 24. WWW.COLLAB365.EVENTS Applicable to all scenarios  Office 365 Tenant – name.onmicrosoft.com  EOP licenses (ExO or EOP Standalone)  Domain to migrate  Modern web browser to access the Office 365 portal Applicable to Standalone or Hybrid scenarios  Inbound and outbound public IP addresses  Open port 25 to Exchange Online Protection IP Addresses  Information on TLS policy, attachment handling, junk folder use, etc.  DirSync may require additional hardware Prerequisites
  • 25. WWW.COLLAB365.EVENTS Standalone  Create EOP outbound connector to deliver mail on-premises  Create EOP inbound connector to accept mail from on-premises  Create on-premises send connector to send outgoing mail to EOP Hybrid  Hybrid mail flow is best configured using the Hybrid Configuration Wizard Optional for all scenarios  Create connectors for forced TLS to third party  Create connectors for customized mail routing Configure mail flow
  • 26. WWW.COLLAB365.EVENTS On-Prem Mail Environment Exchange Online Protection Outbound Connector Inbound Connector Outbound TLS Connector Inbound TLS Connector EOP connectors between on-premises and EOP need to be created Additional connectors can be created between EOP and partners to force TLS Partner Environment Configure mail flow (connectors)
  • 27. WWW.COLLAB365.EVENTS • With EOP (Fabrikam uses EOP) TLS scenario • Prior to EOP (Fabrikam uses EOP) Contoso FabrikamCert CN = mail.contoso.com Cert CN = mail.fabrikam.com Contoso EOP FabrikamCert CN = mail.contoso.com Cert CN = mail.protection.outlook.com Cert CN = mail.protection.outlook.com Cert CN = mail.fabrikam.com
  • 28. WWW.COLLAB365.EVENTS Configure mail flow (connectors) On-Prem Mail APAC Exchange Online Protection On-Prem Mail AMER On-Prem Mail EMEA Outbound Connector 1 Outbound Connector 3 Outbound Connector 2 Inbound Connector 1
  • 29. WWW.COLLAB365.EVENTS • What it does • Blocks messages to invalid recipients at the EOP edge • Beneficial to organizations with on-premises mailboxes • Configuration • The EAC exposes two domain types. • Authoritative - All email for unknown recipients is rejected. Setting this domain type enables DBEB • Internal relay - Email is delivered to recipients in your org or relayed to another email server • To enable DBEB, set the domain to be AUTHORITATIVE. Directory Based Edge Blocking
  • 31. WWW.COLLAB365.EVENTS Reporting • Provides a clear view on spam filtering and malware attacks • E-mail Protection Reports – Excel Workbook available to enable self-service analysis – Connects to the reporting web service – Data can be refreshed from within the workbook at any time – Drill through from recent summary data to the underlying detailed information
  • 32. WWW.COLLAB365.EVENTS • Goals • Is the service operating as expected? • Make adjustments to rules or settings as needed • Evaluate effectiveness of spam settings • Tools • Reports (Office 365 Portal or Mail Protection Reports for Office 365) • Submitting spam and false positive messages to Microsoft • Junk Mail Reporting Tool for Outlook Monitor and fine tune
  • 34. WWW.COLLAB365.EVENTS • Do this • Use a test domain, subdomain or low volume domain for trying different service features • Disable EOP inbound connector (type is on-prem) until you are ready to use it • Use the Remote Connectivity Analyzer to troubleshoot • Restrict inbound SMTP access to allow ONLY from EOP IP ranges • Enable Microsoft’s IP Safe List in the Connection Filter • When creating safe / black lists, use IP first, and if not possible, then use the domain • Don’t do this • Daisy chain services • Use EOP for sending bulk mail • Enable all Content Filter Advanced Options out of the box • Safe list your own domain Best practices
  • 35. WWW.COLLAB365.EVENTS Telnet is your friend Test mail flow before MX change You do/type this Server responds with this telnet tenantDomainMXRecordHere 25 220 helo your_sending_server_fqdn 250 mail from: you@domain.invalid 250 Sender OK rcpt to: recipient@contoso.com 250 Recipient OK data followed by the enter key Server provides directions on how to enter data. subject: Enter the subject and hit enter twice Enter the body text. To finish the message, type a period on a line by itself and hit enter. 250 Message queued for delivery. Quit 221 Service closing transmission channel
  • 36. WWW.COLLAB365.EVENTS • Quarantine • Online viewer only supports up to 500 messages • More can be viewed via PowerShell Get-QuarantineMessage Cmdlet • Can only release in bulk through Release-QuarantineMessage Cmdlet • Limits • Max message size for EOP delivering to stand-alone customers is 150 MB • Max 100 Transport Rules per tenant – DLP policies consume part of this quota • Max of 900 domains per tenant • EOP outbound connectors use round robin for delivery Known Issues & Limitations
  • 37. WWW.COLLAB365.EVENTS No Am APAC EMEA Mail is ALWAYS processed ONLY in your region! PRC
  • 38. WWW.COLLAB365.EVENTS • Protection against unknown malware and viruses by analyzing attachment behavior in a hypervisor environment before delivering them • Real time, time-of-click protection against malicious URLs that are not yet known by EOP • Rich reporting and tracing of URL click throughs • 2$ / month per user Advanced Threat Protection
  • 39. WWW.COLLAB365.EVENTS • EOP Architecture • Test drive it • Know the limitations of EOP Summary
  • 40. WWW.COLLAB365.EVENTS Questions Feel free to contact me on: • @petsch • peter@msdigest.net • www.msdigest.net
  • 41. WWW.COLLAB365.EVENTS Stay tuned for more great sessions …