🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Configure SCG for Exchange Online (Transport Rule Method)

Prev Next

This document describes the steps to create the eShare Outbound Connector, Inbound Connector, and Sample Transport rules in Exchange Online by using the Exchange Admin Center or by via PowerShell. Provisioning this rule means Trusted Shares via Secure Mail Gateway are only created when the rule is matched. Before you implement these steps, we advise you to go through the SCG logic. At a high level, the steps involved are:

REQUIREMENT:

The Person performing these steps must have an administrator role assignment of Exchange Administator in the destination M365 tenant

Outbound Connector - M365 to eShare

  1. Login to Exchange Admin Center and navigate to ‘Mail Flow‘ > ‘Connectors’ page.

  2. Select the ‘+ Add a new connector’ button.

  3. In the ‘New connector’ pane:

    1. In ‘Connection from’ section, select ‘Office 365’.

    2. In ‘Connection to‘ section, select ‘Your organization’s mail server‘.

    3. Select the ‘Next’ button.

  1. In ‘Connector name’ pane: 

    1. Enter a ‘Name’ and ‘Description’ for the connector (ex. Connector for eShare SCG).

    2. Leave ‘Turn it on option‘ and ‘Retain internal Exchange email headers‘ (recommended) options enabled.

    3. Select the ‘Next’ button.

  1. In ‘Use of connector’ pane 

    1. Select ‘Only when I have a transport rule set up that redirects messages to this connector’ option.

    2. Select the ‘Next’ button.

  1. In the ‘Routing’ pane:

    1. Input the IP address or the DNS smart host name provided to you by eShare, and select ‘+’ to add it. 

    2. Select the ‘Next’ button.

  1. In ‘Security restrictions’ pane:

    1. Select ‘Always use Transport Layer Security (TLS) to secure the connection’ option. 

    2. Select ‘Any digital certificate, including self-signed certificates’ option and select ‘Next’. 

    3. Select the ‘Next’ button.

  1. In ‘Validation email’ pane, input an external email address, select the ‘+’ button, then select ‘Validate’ to allow Exchange Online to validate the newly provisioned connector. After validation is completed, select the ‘Next’ button.

  1. In ‘Review connector’ pane, review the settings, and select ‘Create connector’ to create & save it. Select ‘Done’ to close the pane.

Inbound Connector: eShare to M365

  1. In ‘Mail flow’ > ‘Connector’ page, select the ‘+ Add a new connector’ button.

  2. In the ‘New connector’ pane:

    1. In ‘Connection from’, select ‘Your organization’s mail server’.

    2. Select the ‘Next’ button.

  1. In the ‘Connector name’ pane:

    1. Input a ‘name’.

    2. Input a ‘description’.

  2. Leave ‘Turn it on’ and ‘Retain internal Exchange mail header (recommended)’ options enabled.

  3. Select the ‘Next’ button.

  1. In ‘Authenticating sent email’ pane:

    1. Select the second option, input the IP address provided by eShare

    2. Select the ‘+’ button, followed by the ‘Next’ button.

  1. In ‘Review connector’ pane, review settings and select ‘Create connector’ button.

  1. Select ‘Done’ to close the pane. The newly created connectors are displayed in ‘Mail flow’ > ‘Connectors’ page.

Create Connectors (Powershell)

Instead of the Exchange Admin Center, the connectors for eShare may be created using Exchange Online PowerShell. Running the PowerShell cmdlets shown below require Exchange Online PowerShell V2 module. To install necessary pre-requisites, please visit: https://docs.microsoft.com/en-us/powershell/exchange/exchange-online-powershell-v2?view=exchange-ps#install-and-maintain-the-exo-v2-module

  1. In PowerShell, run the below command to load EXO V2 module.

Import-Module ExchangeOnlineManagement
  1. Connect to Exchange Online as Exchange Administrator.

Connect-ExchangeOnline -UserPrincipalName myadmin@myorgdomain.com
  1. Run the below command to verify connection to Exchange Online

Get-Mailbox
  1. Run the below command to create Outbound Connector. Note: Change values for -name, -comment as desired. Value for -SmartHosts will be provided by eShare.

New-OutboundConnector -Name "M365 to eShare SCG" -TlsSettings EncryptionOnly -UseMx $False -Comment "Connector to route emails from Exchange Online to eShare secure mail gateway" -AllAcceptedDomains $False -ConnectorType OnPremises -IsTransportRuleScoped $True -SmartHosts "insert_ip_address"
  1. To create a partner connector, run the following command.

New-OutboundConnector -Name "M365 to eShare SCG" -RecipientDomains * -TlsSettings 	EncryptionOnly -SmartHosts 13.77.229.101 -ConnectorType Partner -IsTransportRuleScoped $false -	TestMode $False -Enabled $true -UseMXRecord $False
  1. Run the below command to create Inbound Connector. Note: Change values for -name and -command as desired. Value for -SenderIPAddress will be provided by eShare.

New-InboundConnector -Name "eShare SCG to M365" -SenderDomains * -SenderIPAddresses "insert_ip_address" -ConnectorType onPremises -RestrictDomainsToIPAddresses $true
  1. Verify the connectors are created as required by reviewing them in Exchange Admin Center or by running the following commands. Note: Update connector names as applicable.

Get-OutboundConnector "M365 to eShare SCG" | Format-list
Get-InboundConnector "eShare SCG to M365" | Format-list
  1. Run the following command to validate the Outbound Connector. (Note: Update connector name as applicable).

Validate-OutboundConnector -Identity "M365 to eShare SCG" -Recipients user@externaldomain.com,user@publicemaildomain.com
  1. After successful validation, disconnect from Exchange Online PowerShell by running the below command.

Disconnect-ExchangeOnline

Create Transport Rules

Note: This is only a sample mail flow rule, the mail flow rules to be created in your tenant may vary depending on your requirements and use cases you intend to support with eShare.

  1. Go to ‘Mail Flow’, select ‘Rules‘.

  2. Select the ‘+Add a rule’ icon and select ‘Create a new rule’.

  3. Enter a suitable name for the rule (ex. Outbound mails to eShare Email Appliance)

  4. Apply this rule if:

    1. Select ‘The sender’ -> is ‘external/internal’.

    2. Select ‘Inside the organization’ and click ‘OK’.

  5. Select the ‘Add Condition’

    1. Select ‘The recipient‘ -> is ‘external/internal’.

    2. Select ‘Outside the organization’ and click OK

  6. Select the ‘Add Condition’

    1. Select ‘The subject or body‘ -> is ‘subject includes any of these words’.

    2. Add the keyword ‘[secure]’ word found in a Subject

  7. Do the following:

    1. Select ‘Redirect the message to’ -> ‘the following connector’

    2. Select the connector you created first sending mail to eShare Appliance

  8. Except if…

    1. Select ‘Add exception’, select ‘The message headers…’ -> ‘Matches these text paterns…’.

    2. Add the message header ‘x-secure-processor’, and enter word ‘eflsmg’.

  9. Select the ‘Save’ button to complete creating the Transport Rule.

  10. Edit the newly created mail flow rule. Enable ‘Stop processing more rules’ and select ‘Save’ to update the rule.

Your Exchange configuration is now complete. Mails originating from your organization to recipients outside will be passed through eShare Secure Email Appliance for processing.

Create Transport Rules (Powershell)

Instead of the Exchange Admin Center, the mail flow rules for eShare may be created using Exchange Online PowerShell. Running the PowerShell cmdlets shown below require Exchange Online PowerShell V2 module. To install necessary pre-requisites, please visit: https://docs.microsoft.com/en-us/powershell/exchange/exchange-online-powershell-v2?view=exchange-ps#install-and-maintain-the-exo-v2-module

  1. In PowerShell, run the below command to load EXO V2 module.

Import-Module ExchangeOnlineManagement
  1. Connect to Exchange Online as Exchange Administrator.

Connect-ExchangeOnline -UserPrincipalName myadmin@myorgdomain.com
  1. Run the below command to verify connection to Exchange Online.

Get-Mailbox
  1. Rule to route emails with certain x-headers to eShare.

New-TransportRule -Name "Emails with eShare X-Header" -FromScope InOrganization -SentToScope NotInOrganization -HeaderContainsMessageHeader "x-smg" -HeaderContainsWords "[attachments]", "[securemail]" -ExceptIfHeaderContainsMessageHeader "x-secure-processor" -ExceptIfHeaderContainsWords "smg" -ExceptIfSenderIpRanges "<SMG_IP_Address>" -RouteMessageOutboundConnector "M365 to eShare SCG" -StopRuleProcessing $True -Mode Enforce -Enabled $false
  1. Rule to route email with certain keywords in subject to eShare.

New-TransportRule -Name "Emails with eShare Keywords" -FromScope InOrganization -SentToScope NotInOrganization -SubjectContainsWords "[attachments]", "[securemail]" -ExceptIfHeaderContainsMessageHeader "x-secure-processor" -ExceptIfHeaderContainsWords "smg" -ExceptIfSenderIpRanges "<SMG_IP_Address>" -RouteMessageOutboundConnector "M365 to eShare SCG" -StopRuleProcessing $True -Mode Enforce -Enabled $false
  1. Rule to route emails with attachments over 2 MB to eShare.

New-TransportRule -Name "Emails with attachments over 2 MB" -FromScope InOrganization -SentToScope NotInOrganization -AttachmentSizeOver "2 MB" -SetHeaderName "x-smg" -SetHeaderValue "[attachments]" -ExceptIfHeaderContainsMessageHeader "x-secure-processor" -ExceptIfHeaderContainsWords "smg" -ExceptIfSenderIpRanges "<SMG_IP_Address>" -RouteMessageOutboundConnector "M365 to eShare SCG" -StopRuleProcessing $True -Mode Enforce
  1. Rule to route emails with MIP labels to eShare.

New-TransportRule -Name "Emails with MIP Label" -FromScope InOrganization -SentToScope NotInOrganization -HeaderContainsMessageHeader "msip_labels" -HeaderContainsWords "MSIP_Label_^[0-9A-Fa-f]{8}(?:-[0-9A-Fa-f]{4}){3}-[0-9A-Fa-f]{12}$_Enabled=true" -SetHeaderName "x-smg" -SetHeaderValue "[secure-attachment]" -ExceptIfHeaderContainsMessageHeader "x-secure-processor" -ExceptIfHeaderContainsWords "smg" -ExceptIfSenderIpRanges "<SMG_IP_Address>" -RouteMessageOutboundConnector "M365 to eShare SCG" -StopRuleProcessing $True -Mode Enforce