This document describes the steps to create Outbound and Inbound Connectors in Exchange Online by using the Exchange Admin Center or via PowerShell. Provisioning all emails via Secure Mail Gateway means for every email sent out of your Exchange, a Trusted Share could be created. At a high level, the steps involved are:
REQUIREMENT:
The Person performing these steps must have an administrator role assignment of Exchange Administator in the destination M365 tenant
Outbound Connector: M365 to eShare
Login to Exchange Admin Center and navigate to ‘Mail Flow‘ > ‘Connectors’ page.
Select the ‘+ Add a new connector’ button.
In the ‘New connector’ pane:
In ‘Connection from’ section, select ‘Office 365’.
In ‘Connection to‘ section, select ‘Partner Connector‘.
Select the ‘Next’ button.

In ‘Connector name’ pane:
Enter a ‘Name’ and ‘Description’ for the connector (ex. M365 to eShare SCG).
Leave ‘Turn it on option‘.
Select the ‘Next’ button.
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A24%3A27Z&se=2026-10-01T08%3A37%3A27Z&sr=c&sp=r&sig=KXMUXjpiegkqi7w1aGThnf4Cl%2BjhefO4iz05st0%2FrxY%3D)
In ‘Use of connector’ pane
Select ‘Only when email messages are sent to these domains’ option.
Enter a * into the dialog box below and select the + button to add.
Select the ‘Next’ button.

In the ‘Routing’ pane:
Input the IP address or the DNS smart host name provided to you by eShare, and select ‘+’ to add it.
Select the ‘Next’ button.
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A24%3A27Z&se=2026-10-01T08%3A37%3A27Z&sr=c&sp=r&sig=KXMUXjpiegkqi7w1aGThnf4Cl%2BjhefO4iz05st0%2FrxY%3D)
In ‘Security restrictions’ pane:
Select ‘Always use Transport Layer Security (TLS) to secure the connection’ option.
Select ‘Any digital certificate, including self-signed certificates’ option and select ‘Next’.
Select the ‘Next’ button.
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A24%3A27Z&se=2026-10-01T08%3A37%3A27Z&sr=c&sp=r&sig=KXMUXjpiegkqi7w1aGThnf4Cl%2BjhefO4iz05st0%2FrxY%3D)
In ‘Validation email’ pane, input an external email address, select the ‘+’ button, then select ‘Validate’ to allow Exchange Online to validate the newly provisioned connector. After validation is completed, select the ‘Next’ button.

In ‘Review connector’ pane, review the settings, and select ‘Create connector’ to create & save it. Select ‘Done’ to close the pane.
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A24%3A27Z&se=2026-10-01T08%3A37%3A27Z&sr=c&sp=r&sig=KXMUXjpiegkqi7w1aGThnf4Cl%2BjhefO4iz05st0%2FrxY%3D)
Inbound Connector - eShare to M365
Login to Exchange Admin Center and navigate to ‘Mail Flow‘ > ‘Connectors’ page.
Select the ‘+ Add a new connector’ button.
In the ‘New connector’ pane:
In ‘Connection from’ section, select ‘Office 365’.
In ‘Connection to‘ section, select ‘Partner organization‘.
Select the ‘Next’ button.

In the ‘Connector name’ pane:
Input a ‘Name’.
Input a ‘Description’.
Leave ‘Turn it on’ option enabled.
Select the ‘Next’ button.

In ‘Authenticating sent email’ pane:
Select the second option, input the IP address provided by eShare
Select the ‘+’ button, followed by the ‘Next’ button.
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A24%3A27Z&se=2026-10-01T08%3A37%3A27Z&sr=c&sp=r&sig=KXMUXjpiegkqi7w1aGThnf4Cl%2BjhefO4iz05st0%2FrxY%3D)
In ‘Security Restrictions’ pane:
Select ‘Reject email messages if they aren’t sent over TLS’
Select the ‘Next’ button.

In ‘Review connector’ pane, review settings and select ‘Create connector’ button.

Select ‘Done’ to close the pane. The newly created connectors are displayed in ‘Mail flow’ > ‘Connectors’ page.
Create Connectors (Powershell)
Instead of the Exchange Admin Center, the connectors for eShare may be created using Exchange Online PowerShell. Running the PowerShell cmdlets shown below require Exchange Online PowerShell V2 module. To install necessary pre-requisites, please visit: https://docs.microsoft.com/en-us/powershell/exchange/exchange-online-powershell-v2?view=exchange-ps#install-and-maintain-the-exo-v2-module
In PowerShell, run the below command to load EXO V2 module
Import-Module ExchangeOnlineManagementConnect to Exchange Online as Exchange Administrator
Connect-ExchangeOnline -UserPrincipalName myadminuser@myorgdomain.comRun the below command to verify connection to Exchange Online
Get-MailboxRun the command below to create an outbound partner connector. Note: Change values for -name, -comment as desired. Value for -SmartHosts will be provided by eShare
New-OutboundConnector -Name "M365 to eShare SCG" -RecipientDomains * -TlsSettings EncryptionOnly -SmartHosts <IP/FQDN> -ConnectorType Partner -IsTransportRuleScoped $false -TestMode $False -Enabled $true -UseMXRecord $FalseRun the below command to create Inbound Connector. Note: Change values for -name and -command as desired. Value for -SenderIPAddress will be provided by eShare
New-InboundConnector -Name "eShare SCG to M365" -SenderDomains * -SenderIPAddresses "insert_ip_address" -ConnectorType Partner -RestrictDomainsToIPAddresses $trueVerify the connectors are created as required by reviewing them in Exchange Admin Center or by running the following commands. Note: Update connector names as applicable
Get-OutboundConnector "M365 to eShare SCG" | Format-list
Get-InboundConnector "eShare SCG to M365" | Format-listRun the following command to validate the Outbound Connector. Note: Update connector name as applicable.
Validate-OutboundConnector -Identity "M365 to eShare SCG" -Recipients user@externaldomain.com,user@publicemaildomain.comAfter successful validation, disconnect from Exchange Online PowerShell by running the below command
Disconnect-ExchangeOnline