Protect communications Multi-engine anti-malware and enhanced spam filtering to help protect your email environment from threats Enforce policy Flexible.

Slides:



Advertisements
Similar presentations
1 Effective, secure and reliable hosted security and continuity solution.
Advertisements

Comprehensive protection Multi-engine antivirus Continuously evolving anti-spam protection Policy enforcement Enterprise class reliability Geographically.
Microsoft ® Exchange Online Advanced Security Name Title Microsoft Corporation.
Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of servers Across dozens of.
On-premises Exchange Online Protection Office 365 Directory Sync ADFS (optional) Single sign on Secure mail flow Existing environment.
Module 6 Implementing Messaging Security. Module Overview Deploying Edge Transport Servers Deploying an Antivirus Solution Configuring an Anti-Spam Solution.
Curtis Parker | December 2010 | Microsoft Corporation.
Course 201 – Administration, Content Inspection and SSL VPN Filtering
Microsoft Ignite /16/2017 1:30 PM
Connector- Based Customer Delivery Pool Mailbox (On-premises) Mailbox or Application (On-premises) Higher Risk High Risk Delivery Pool Resolve.
Fact check True or False: Over half of the messages received today in Exchange Online are spam True. About 67 % of all messages are spam True or False:
What’s New in WatchGuard XCS 10.0 Update 3 WatchGuard Training.
Understanding Microsoft Forefront Online Protection for Exchange Robert Gillies Solution Architect Microsoft Corporation EXL201.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Exchange Online Office 365 Overview & InfrastructureLync Online Administration.
Security challenges Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of.
Office 365 SMTP Relay June Relay Method Send to rcpts in domain Relay to Internet via O365 Configuration Requirements Requires Authentication.
SIM334. Internet Comprehensive Protection Multi-Engine Antivirus and Multi layered continuously evolving Anti-spam In the Leader’s quadrant in the.
Configuring Hybrid Exchange the Easy Way
What’s New in Exchange Online. Disclaimer This presentation contains preliminary information that may be changed substantially prior to final commercial.
Service Life CycleScenarioEXOLYOSPOOffice365 (suite wide) BuyProvisioning Licenses Storage ConsumeDevice – Software Device – Connections User.
Message Trace Office 365 May 2013.
TechEd /20/2017 2:02 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Norman SecureTide Powerful cloud solution to stop spam and threats before it reaches your network.
SIM331 High-accuracy spam filtering Multiple virus-scanning engines Hub Transport Mailbox External About 90% of is junk Tuned for enterprise.
Clinton Ho Program Manager Microsoft Corporation SESSION CODE: SIA311.
Copyright© Microsoft Corporation Speaker:Engagement consultant Title of presentation:Assessment of the Environment Length of presentation: 45 minutes Audience:Customer.
CensorNet Ltd An introduction to CensorNet Mailsafe Presented by: XXXXXXXX Product Manager Tel: XXXXXXXXXXXXX.
SIM309. Connection Analysis (IP-based edge blocks) Reputation Analysis Connection Filtering Protect businesses from receiving –borne viruses.
SMTP PROTOCOL CONFIGURATION AND MANAGEMENT Chapter 8.
Using Windows Firewall and Windows Defender
Securing Microsoft® Exchange Server 2010
Module 6: Manage and Configure Messaging. Configuring Internet Mail Using Small Business Server (SBS) 2008 Console Configuring Protection Configuring.
MEC /22/2017 5:53 AM © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Client X CronLab Spam Filter Technical Training Presentation 19/09/2015.
Exchange Online Protection. About Speaker Prabhat Nigam Microsoft MVP: Exchange Server MCSE: Messaging 2013, MCITP 2010/2007, MS Ex – Microsoft Exchange.
Module 2 Designing Microsoft® Exchange Server 2010 Integration with the Current Infrastructure.
Module 9 Configuring Messaging Policy and Compliance.
Module 6 Planning and Deploying Messaging Security.
Norman Protection Powerful and flexible Protection Gateway.
Alex Nikolayev Program Manager Identity and Security Division Microsoft Corporation SESSION CODE: SIA324 Cristian Mora Product Manager Identity and Security.
Network and Perimeter Security Paula Kiernan Senior Consultant Ward Solutions.
Virtual techdays INDIA │ august 2010 virtual techdays INDIA │ august 2010 Moving/Co-existing your messaging platform to the cloud with Exchange.
Module 5 Managing Message Transport. Module Overview Overview of Message Transport Configuring Message Transport.
Module 7: Managing Message Transport. Overview Introduction to Message Transport Implementing Message Transport.
Module 5 Managing Message Transport. Module Overview Overview of Message Transport Configuring Message Transport.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Module 5 Planning and Deploying Message Transport in Microsoft® Exchange Server 2010.
Module 7 Planning and Deploying Messaging Compliance.
“SaaS secure web and gateways frequently provide efficiency and cost advantages, and a growing number of offerings are delivering an improved.
Understanding Microsoft Forefront Online Protection for Exchange Nathan Winters Microsoft Corporation EXL201.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
Implementing Microsoft Exchange Online with Microsoft Office 365
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Microsoft Exchange Server 2013 Security Mick Tomlinson– Technical Instructor New Horizons.
Secure Services Shared Hosted MS Exchange 2010.
Scott Schnoll Senior Content Developer Microsoft Corporation Securing Your Exchange Deployment.
Information explosion 1.4X 44X Protect communications.
Fighting Spam in an Exchange Environment Tzahi Kolber IT Supervisor - Polycom Israel.
On-premises Exchange Online Protection Office 365 Directory Sync Secure mail flow Existing environment.
Office 365 Migration Challenges Drew St. John 2016 Redmond Summit | Identity Without Boundaries May 24, 2016 Consultant
How to Implement Exchange Online Protection (EOP)
Securing the Network Perimeter with ISA 2004
9/4/2018 6:45 PM Secure your Office 365 environment with best practices recommended for political campaigns Ethan Chumley Campaign Technology Advisor Civic.
9/14/2018 2:22 AM THR2026 Set up secure and efficient collaboration for your organization with Office 365 Joe Davies Senior Content Developer Brenda Carter.
Real Microsoft Exam Questions and Answers
Migrating to Office 365 from Google mail and exchange
06 | Planning Exchange Online and Configuring DNS Records
Office 365 Security & Compliance: Exchange Online Protection
10 | Implementing Directory Synchronization
Presentation transcript:

Protect communications Multi-engine anti-malware and enhanced spam filtering to help protect your environment from threats Enforce policy Flexible tools for policy enforcement that provide the right level of control Streamlined management Flexible administration of anti-spam, anti-malware and policy rules

SPAM Protection Outlook Safe Sender/Recipient Content scanning Bulk Mail filtering Content Filter Advanced Options Customer Feedback False Positive/Negatives Customer Feedback False Positive/Negatives Corporate Network Policy Quarantine Policy Quarantine Edge Blocks is routed to EOP DC’s based on MX record resolution IP-based edge blocking URL Block lists Policy Enforcement Custom Rules Allows/Rejects SPAM Quarantine SPAM Quarantine Spam Analysts Virus Scanning AV Engine 1 AV Engine 2 AV Engine 3

NDR Delivery Pool Bulk Delivery Pool Outbound Pool Higher Risk Delivery Pool Higher Risk Outbound Pool Normal Score SPAM Protection Content scanning and Heuristics Content Filter Advanced Options Virus Scanning AV Engine 1 AV Engine 2 AV Engine 3 Policy Enforcement Custom Rules Quarantine Corporate Network Internet Encryption Spam Analysts

Step 1: Verify prerequisites Step 2: Configure mail flow (connectors) Step 3: Add and validate domains Step 4: Customize spam and policy settings Step 5: Enable mail flow Step 6: Monitor and fine tune

Exchange Server 2013 Exchange Online EOP Stand Alone

On-Prem Mail Environment Exchange Online Protection Partner Environment

On-Prem Mail APAC Exchange Online Protection On-Prem Mail AMER On-Prem Mail EMEA

Spam and policy customization

Spam and policy customization (ESN)

EOP and the Junk Mail folder Two rules Two rules need to be added to the on premise environment. Set-OrganizationConfig –SCLJunkThreshold 4 New-TransportRule "NameForRule" -HeaderContainsMessageHeader "X-Forefront-Antispam-Report" - HeaderContainsWords "SFV:SPM" -SetSCL 6 New-TransportRule "NameForRule" -HeaderContainsMessageHeader "X-Forefront-Antispam-Report" - HeaderContainsWords "SFV:SKS" -SetSCL 6 End users need to be educated about the use of the Junk Mail folder in Outlook

Enable mail flow DNS changes MX record (domain-suffix.mail.protection.outlook.com) SPF record (v=spf1 include:spf.protection.outlook.com –all) Do not change CNAME DNS entries for stand alone customers On-premise changes Create smart host from on premise environment to EOP Restrict on premises firewall to only accept port 25 traffic from EOPEOP

Monitor and fine tune Goals Is the service operating as expected? Make adjustments to rules or settings as needed Evaluate effectiveness of spam settings Tools Reports (Office 365 Portal or Mail Protection Reports for Office 365) Submitting spam and false positive messages to Microsoft Junk Mail Reporting ToolJunk Mail Reporting Tool for Outlook

Do this Use a test domain, subdomain or low volume domain for trying different service features Create O365 connectors before adding domains Use the Remote Connectivity Analyzer to troubleshootRemote Connectivity Analyzer Restrict inbound SMTP access to allow ONLY from EOP IP rangesEOP IP ranges Don’t do this Daisy chain services Use EOP for sending bulk mail Enable all Content Filter Advanced Options out of the box

Automated user/group management Ease of administration for CBRs or other rules based on user address Synchronize Outlook safe/block sender lists On-premisesExchange Online Protection Office 365 Directory Sync

Educate users Avoid using links in s to access secure online services Do not respond to requests for sensitive information via Unsubscribe from legitimate bulk mail – e.g. known online retailers Use the Junk mail reporting tool to submit spam samplesJunk mail Resources to help educate users – Outlook Phishing Detection, Crabby Office LadyOutlook Phishing DetectionCrabby Office Lady Publish an SPF record (Sender Policy Framework) Include EOP IPs and on-premises public IPs Use the Microsoft Configuration WizardMicrosoft Configuration Wizard Turn on the SPF check Content Filter Advanced Options

Other considerations Enable the Bulk Mail Content Filter Advanced Options Utilize Regular Expression (Reg-Ex) capability of ETRs to fine tune filtering of bulk mail e.g. Header field name match “List-Unsubscribe” sets SCL to 6 More details posted on Terry Zink’s Cyber Security BlogTerry Zink’s Cyber Security Blog Scope Inbound Allow rules by IP where possible Avoid safe-listing own domains - this by-passes the SPF check and negates the check’s effectiveness

Prevent Spam Notification Delivery to DLs Use DirSync and a custom Content Filter Apply custom Content Filter to that OU or OUs with “Enable end-user spam notifications” de-selected Block using Transport rule on-premises: Create a contact object (e.g. EOP ESN) with the address of In PowerShell: Get-DistributionGroup -ResultSize Unlimited -IgnoreDefaultScope | where { !$_.RejectMessagesFrom - and !$_.RejectMessagesFromDLMembers } | Set-DistributionGroup -IgnoreDefaultScope - RejectMessagesFrom " EOP ESN"

Coming soon - end user access to Spam Quarantine  End users manage spam via end user spam quarantine notifications which may be scheduled for daily delivery  Administrator only access to quarantine Viewer only supports up to 500 messages More can be viewed via PowerShell Get-QuarantineMessage CmdletGet-QuarantineMessage Can only release in bulk through Release-QuarantineMessage CmdletRelease-QuarantineMessage Limits Max message size for EOP delivering to stand-alone customers is 150 MB Max message size for EOP delivering to Office 365 hosted mailboxes is 35 MB Max 100 Transport Rules per tenant – DLP policies consume part of this quota

Failover configuration Using a second MX record to accomplish failover Contoso.com has 3 on-premises IPs: Site A , Site B , Site C Contoso.com wants mail to route to Site A but if it is down wants mail to go to Site B, and Site C as last resort. contoso.com MX preference = 10 contoso-com.mail.protection.outlook.com (routes all mail for contoso.com) onprem.contoso.com MX preference = 10 mail-a.contoso.com onprem.contoso.com MX preference = 20 mail-b.contoso.com onprem.contoso.com MX preference = 30 mail-c.contoso.com mail-a.contoso.com A mail-b.contoso.com A mail-c.contoso.com A *Specify onprem.contoso.com in the outbound connector smart host field

Match Sub-domains DKIM for inbound Support for IPV6

What they offer Exchange Online Protection implementation and configuration assistance 1 – 5 days of engagement over a period of 90 days Administrator training on Exchange Online Protection Advise customer on service best practices Eligibility Net new customers who purchase seats EOP stand alone, O365D Exception basis for O365 Hybrid How to Engage an IPM Contact your Technical Account Manager for more information.

SessionTitleTimingRoom SPR.202Encryption in ExchangeTue 10:45 AM - 12:00 PMBallroom E SPR.201 Eliminate the Regulatory Compliance NightmareTue 9:00 AM-10:15 AMMR 19ab SPR.UN.305 Exchange Online Protection: Notes from the fieldWed 10:15 AM – 11:30 AMBallroom G SPR.UN.304 Experts Unplugged: EOP & Encryption Wed 8:30-9:45 AM Wed 1:00-2:15 PM MR 18d MR 17b SPR.401 Extending Data Loss Prevention For Your BusinessWed 4:45 PM- 6:00 PMMR 18bc SPR.203 Protect your Organization with Exchange Online Protection (EOP)Mon 4:30 PM - 5:45 PMMR 18bc SPR.301 So how does Microsoft handle my spam?Tue 4:45 PM – 6:00 PMMR 19ab SPR.401Using Connectors & Mail RoutingWed 2:45 PM - 4:00 PMMR 18bc ARC.304 Exchange Server 2013 Transport ArchitectureTues 9:00 AM - 10:15 AMBallroom F EDC.302 Advanced Data Loss Prevention in ExchangeTues 1:30 PM-2:45 PMBallroom F EDC.UN.301 Experts Unplugged: Data Loss Prevention Tue 3:00 PM-4:15 PM Wed 10:15 AM-11:30 AM MR 18d MR 13ab EDC.204 Data Loss Prevention in Exchange, Outlook, OWAMon 2:45 Pm-4:00PMMR 18bc MNG.304 Reporting On O365 Mail flow and Mailbox DataWed 1:00 PM-2:15 PMMR 17a