🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Configure SCG for Exchange Online (Route all Emails)

Prev Next

This document describes the steps to create Outbound and Inbound Connectors in Exchange Online by using the Exchange Admin Center or via PowerShell.  Provisioning all emails via Secure Mail Gateway means for every email sent out of your Exchange, a Trusted Share could be created. At a high level, the steps involved are:

REQUIREMENT:

The Person performing these steps must have an administrator role assignment of Exchange Administator in the destination M365 tenant

Outbound Connector: M365 to eShare

  1. Login to Exchange Admin Center and navigate to ‘Mail Flow‘ > ‘Connectors’ page.

  2. Select the ‘+ Add a new connector’ button.

  3. In the ‘New connector’ pane:

    1. In ‘Connection from’ section, select ‘Office 365’.

    2. In ‘Connection to‘ section, select ‘Partner Connector‘.

    3. Select the ‘Next’ button.

  1. In ‘Connector name’ pane:

    1. Enter a ‘Name’ and ‘Description’ for the connector (ex. M365 to eShare SCG).

    2. Leave ‘Turn it on option‘.

    3.  Select the ‘Next’ button.

  1. In ‘Use of connector’ pane

    1. Select ‘Only when email messages are sent to these domains’ option.

    2. Enter a * into the dialog box below and select the + button to add.

    3. Select the ‘Next’ button.

  1. In the ‘Routing’ pane:

    1. Input the IP address or the DNS smart host name provided to you by eShare, and select ‘+’ to add it.

    2. Select the ‘Next’ button.

  1. In ‘Security restrictions’ pane:

    1. Select ‘Always use Transport Layer Security (TLS) to secure the connection’ option.

    2. Select ‘Any digital certificate, including self-signed certificates’ option and select ‘Next’.

    3. Select the ‘Next’ button.

  2. In ‘Validation email’ pane, input an external email address, select the ‘+’ button, then select ‘Validate’ to allow Exchange Online to validate the newly provisioned connector. After validation is completed, select the ‘Next’ button.

  1. In ‘Review connector’ pane, review the settings, and select ‘Create connector’ to create & save it. Select ‘Done’ to close the pane.

Inbound Connector - eShare to M365

  1. Login to Exchange Admin Center and navigate to ‘Mail Flow‘ > ‘Connectors’ page.

  2. Select the ‘+ Add a new connector’ button.

  3. In the ‘New connector’ pane:

    1. In ‘Connection from’ section, select ‘Office 365’.

    2. In ‘Connection to‘ section, select ‘Partner organization‘.

    3. Select the ‘Next’ button.

  1. In the ‘Connector name’ pane:

    1. Input a ‘Name’.

    2. Input a ‘Description’.

    3. Leave ‘Turn it on’ option enabled.

    4. Select the ‘Next’ button.

  1. In ‘Authenticating sent email’ pane:

    1. Select the second option, input the IP address provided by eShare

    2. Select the ‘+’ button, followed by the ‘Next’ button.

  1. In ‘Security Restrictions’ pane:

    1. Select ‘Reject email messages if they aren’t sent over TLS’

    2. Select the ‘Next’ button.

  1. In ‘Review connector’ pane, review settings and select ‘Create connector’ button.

  1. Select ‘Done’ to close the pane. The newly created connectors are displayed in ‘Mail flow’ > ‘Connectors’ page.

Create Connectors (Powershell)

Instead of the Exchange Admin Center, the connectors for eShare may be created using Exchange Online PowerShell. Running the PowerShell cmdlets shown below require Exchange Online PowerShell V2 module. To install necessary pre-requisites, please visit: https://docs.microsoft.com/en-us/powershell/exchange/exchange-online-powershell-v2?view=exchange-ps#install-and-maintain-the-exo-v2-module

  1. In PowerShell, run the below command to load EXO V2 module

Import-Module ExchangeOnlineManagement
  1. Connect to Exchange Online as Exchange Administrator

Connect-ExchangeOnline -UserPrincipalName myadminuser@myorgdomain.com
  1. Run the below command to verify connection to Exchange Online

Get-Mailbox
  1. Run the command below to create an outbound partner connector. Note: Change values for -name, -comment as desired. Value for -SmartHosts will be provided by eShare

New-OutboundConnector -Name "M365 to eShare SCG" -RecipientDomains * -TlsSettings 	EncryptionOnly -SmartHosts <IP/FQDN> -ConnectorType Partner -IsTransportRuleScoped $false -TestMode $False -Enabled $true -UseMXRecord $False
  1. Run the below command to create Inbound Connector. Note: Change values for -name and -command as desired. Value for -SenderIPAddress will be provided by eShare

New-InboundConnector -Name "eShare SCG to M365" -SenderDomains * -SenderIPAddresses "insert_ip_address" -ConnectorType Partner -RestrictDomainsToIPAddresses $true
  1. Verify the connectors are created as required by reviewing them in Exchange Admin Center or by running the following commands. Note: Update connector names as applicable

Get-OutboundConnector "M365 to eShare SCG" | Format-list
Get-InboundConnector "eShare SCG to M365" | Format-list
  1. Run the following command to validate the Outbound Connector. Note: Update connector name as applicable.

Validate-OutboundConnector -Identity "M365 to eShare SCG" -Recipients user@externaldomain.com,user@publicemaildomain.com
  1. After successful validation, disconnect from Exchange Online PowerShell by running the below command

Disconnect-ExchangeOnline