SIM309. Connection Analysis (IP-based edge blocks) Reputation Analysis Connection Filtering Protect businesses from receiving email–borne viruses.

Slides:



Advertisements
Similar presentations
Unified. Simplified. Unified Communications Launch 2007.
Advertisements

Comprehensive protection Multi-engine antivirus Continuously evolving anti-spam protection Policy enforcement Enterprise class reliability Geographically.
Microsoft ® Exchange Online Advanced Security Name Title Microsoft Corporation.
Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of servers Across dozens of.
On-premises Exchange Online Protection Office 365 Directory Sync ADFS (optional) Single sign on Secure mail flow Existing environment.
Module 6 Implementing Messaging Security. Module Overview Deploying Edge Transport Servers Deploying an Antivirus Solution Configuring an Anti-Spam Solution.
Curtis Parker | December 2010 | Microsoft Corporation.
Security and Organizational Governance Anand Lakshminarayanan Senior Product Manager Microsoft Corporation.
Unified. Simplified. Unified Communications Launch 2007.
Microsoft Ignite /16/2017 1:30 PM
Forefront Online Protection for Exchange Renato Francesco Giorgini Evangelist IT Pro
Fact check True or False: Over half of the messages received today in Exchange Online are spam True. About 67 % of all messages are spam True or False:
What’s New in WatchGuard XCS 10.0 Update 3 WatchGuard Training.
Understanding Microsoft Forefront Online Protection for Exchange Robert Gillies Solution Architect Microsoft Corporation EXL201.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Exchange Online Office 365 Overview & InfrastructureLync Online Administration.
Security challenges Used by many 100,000s of customers Used by many 10,000,000s of users Processing Billions of s a day Using Thousands of.
Office 365 SMTP Relay June Relay Method Send to rcpts in domain Relay to Internet via O365 Configuration Requirements Requires Authentication.
Active Directory Integration with Microsoft Office 365 Ross Adams & Jono Luk Program Managers Microsoft Corporation OSP321.
SIM205. (On-Premises) Storage Servers Networking O/S Middleware Virtualization Data Applications Runtime You manage Infrastructure (as a Service)
Exchange 2010 Overview Name Title Group. What You Tell Us Communication overload Globally distributed customers and partners High cost of communications.
Agenda Next Generation Antispam Protection Forefront Overview Forefront Security for Exchange Server Forefront Online Security for Exchange Hybrid Software.
SIM334. Internet Comprehensive Protection Multi-Engine Antivirus and Multi layered continuously evolving Anti-spam In the Leader’s quadrant in the.
Protect communications Multi-engine anti-malware and enhanced spam filtering to help protect your environment from threats Enforce policy Flexible.
Configuring Hybrid Exchange the Easy Way
EXL302-R. Storage Management Balance mailbox size demands with available storage resources Reduce the proliferation of.PST files stored outside of IT.
FOPE Edge Virus* Policy Spam EXCHANGE ONLINE Mailboxes INTERNET Mail is sent outbound FOPE filters outbound mail FOPE delivers to.
Message Trace Office 365 May 2013.
TechEd /20/2017 2:02 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Norman SecureTide Powerful cloud solution to stop spam and threats before it reaches your network.
SIM331 High-accuracy spam filtering Multiple virus-scanning engines Hub Transport Mailbox External About 90% of is junk Tuned for enterprise.
1 SMTP Transport Configuration SMTP Configurations and Virtual Servers Customizing the SMTP Service.
Clinton Ho Program Manager Microsoft Corporation SESSION CODE: SIA311.
SIM 320. Contoso customer premises AD MS Online Directory Sync Identity Services Provisioning platform Provisioning platform Lync Online Lync Online.
Copyright© Microsoft Corporation Speaker:Engagement consultant Title of presentation:Assessment of the Environment Length of presentation: 45 minutes Audience:Customer.
CensorNet Ltd An introduction to CensorNet Mailsafe Presented by: XXXXXXXX Product Manager Tel: XXXXXXXXXXXXX.
SMTP PROTOCOL CONFIGURATION AND MANAGEMENT Chapter 8.
Securing Microsoft® Exchange Server 2010
Module 6: Manage and Configure Messaging. Configuring Internet Mail Using Small Business Server (SBS) 2008 Console Configuring Protection Configuring.
IT:Network:Applications.  How messaging servers work  Initial tips for success Exchange management  Server roles  Exchange Server Management  Message.
Exchange Online Protection. About Speaker Prabhat Nigam Microsoft MVP: Exchange Server MCSE: Messaging 2013, MCITP 2010/2007, MS Ex – Microsoft Exchange.
Module 2 Designing Microsoft® Exchange Server 2010 Integration with the Current Infrastructure.
Module 9 Configuring Messaging Policy and Compliance.
Module 6 Planning and Deploying Messaging Security.
Norman Protection Powerful and flexible Protection Gateway.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Alex Nikolayev Program Manager Identity and Security Division Microsoft Corporation SESSION CODE: SIA324 Cristian Mora Product Manager Identity and Security.
Virtual techdays INDIA │ august 2010 virtual techdays INDIA │ august 2010 Moving/Co-existing your messaging platform to the cloud with Exchange.
Customers Security in Context Microsoft & Office 365 / Azure Cloud Security Engagement Framework & References Real World application Frameworks.
Module 5 Managing Message Transport. Module Overview Overview of Message Transport Configuring Message Transport.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Module 5 Planning and Deploying Message Transport in Microsoft® Exchange Server 2010.
OSP325 ScenarioUse Directory Synchronization? Initial on-boarding/bulk Provisioning of users only* No Identity FederationYes Long-term.
Module 7 Planning and Deploying Messaging Compliance.
“SaaS secure web and gateways frequently provide efficiency and cost advantages, and a growing number of offerings are delivering an improved.
Understanding Microsoft Forefront Online Protection for Exchange Nathan Winters Microsoft Corporation EXL201.
Copyright ©2015 WatchGuard Technologies, Inc. All Rights Reserved WatchGuard Training WatchGuard XCS What’s New in version 10.1.
Unified. Simplified. Unified Communications Launch 2007.
Implementing Microsoft Exchange Online with Microsoft Office 365
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter One Introduction to Exchange Server 2003.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Scott Schnoll Senior Content Developer Microsoft Corporation Securing Your Exchange Deployment.
VIRTUAL SERVERS Chapter 7. 2 OVERVIEW Exchange Server 2003 virtual servers Virtual servers in a clustering environment Creating additional virtual servers.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.
On-premises Exchange Online Protection Office 365 Directory Sync Secure mail flow Existing environment.
Exchange Deployment Planning Services Forefront for Exchange On-Premises.
Threat Management Gateway
Migrating to Office 365 from Google mail and exchange
06 | Planning Exchange Online and Configuring DNS Records
Office 365 Security & Compliance: Exchange Online Protection
Presentation transcript:

SIM309

Connection Analysis (IP-based edge blocks) Reputation Analysis Connection Filtering Protect businesses from receiving –borne viruses and other malicious code with scan engines and heuristic detection Multiple engine support AntiVirus Anti-spam filter can detect all types of spam before they reach the corporate network NDR Backscatter Support Anti-Spam Policy rules to regulate flow for compliance Policy-based encryption (for EHE subscribers) Enhanced RegEx support Policy

Every Exchange Online (BPOS)/Office 365 customer is a FOPE customer! Office 365 Protect on-premises or hosted implementations Is server agnostic Standalone Protect on-premises Exchange servers and integrates FPE/FOPE policies (On-prem/Cloud Policies) Hybrid Protection Live EDU (This CY 2011) Others

Edge Blocking End User Quarantine Administrator Console Corporate Network Messaging Administrator Employees Inbound Filtered About 90% of is junk Outbound Filtered Also incorporates technology from… External Senders/ Recipients Exchange Server Anti-spam Antivirus Policy Automatic Spooling * Encryption * Requires additional Exchange Hosted Encryption License Active Directory FOPE Directory Synchronization Tool Multilayer spam and virus protection and policy enforcement Legitimate Junk Policy rules regulate flow for compliance and message control

ProductFOPE Admin Center Access FOPE Admin Center Login Method Use FOPE Admin Center to configure domains and change IP addresses Virus Scanning, Edge Blocking, Anti-Spam, Message Hygiene Use FOPE Connectors for complex scenarios Directory Synchronization Method FOPE StandaloneYesFOPE credentialsYes Yes, for certain scenarios FOPE Directory Synchronization Tool Office 365 Beta or Professionals and Small Businesses NoN/ANoNoYesNoNone Office 365 Beta for enterprises or education YesSingle sign-on via FOPE link in Exchange Control Panel NoYes Office 365 Directory Synchronization Tool sign-on via FOPE link in Exchange Control Panel NoYes Outlook Live Directory Synchronization Tool Business Productivity Online Suite – Standard Yes, limited access by request to Technical Support FOPE credentialsNoYesNoExchange Online Directory Synchronization Tool Business Productivity Online Suite – Dedicated YesFOPE credentialsYes Exchange Online Directory Synchronization Tool Note: For Microsoft Office 365 Beta customers, antivirus scanning is performed by Forefront Protection 2010 for Exchange Server (FPE) on the Exchange Online servers rather than by FOPE

Antivirus and anti-spam protection for Exchange Server 2010/2007 Server Roles On-Premises Software Online Anti MalwareAnti-spamManagement Forefront Online Protection for Exchange Symantec Authentium Kaspersky Inbound Messaging Hygiene Stop Foreign Spam Outbound Spam Mitigation Anti-spam Feedback Loop Message Tracing IT Admin Improvements Forefront Protection 2010 for Exchange Server MS AV + AntiSpyware Kaspersky Authentium Virus Buster Norman Internal mail filtering Industry-leading 3 rd party content filtering Forefront Protection Server Management Console SMTP Exchange Server Edge Role Hub Role Mailbox Role Internet

Source IP Source Domain Reject non Source IP Opportunistic TLS Forced TLS Spam Connection Policy Opportunistic TLS Forced TLS Smart host MX Destination domain

Secure inbound and outbound mail with TLS Validated with CA certificates Forced TLS Redirect all or part of your outbound mail to flow through an on-premises server Apply additional processing Outbound Smart Host Add partners to a safe list Mail from those organizations bypass FOPE IP filtering Optionally, skip FOPE spam and policy filtering Inbound Safe Listing

Business Partner FOPE woodgrovebank.com contoso.com Opportunistic TLS is on by default for Office 365 customers (no action is required to enable it) TLS can be forced for inbound connections, outbound connections, or both FOPE attempts to set up a TLS connection If TLS cannot be established, is not sent/received Virus scanning is performed by FPE for Exchange Online mailboxes Forced TLS can be configured using the methods shown here Value Proposition Maintain secure and trusted communication channel with partners Avoid interception/ eavesdropping

FOPE From: To: From: To: service.contoso.com FOPE routes outbound to smart host for custom mail process or delivery Virus scanning is performed by FPE for Exchange Online mailboxes INTERNET Value Proposition Use DLP or encryption appliances from third parties Perform custom processing or address rewrite Maintain “total mail control” during coexistence (inbound and outbound mail is all routed through on-prem server contoso.com

FOPE From: To: From: To: contoso.com fabrikam.com Safe-listed Partner Value Proposition Reduce the chance of false positives (legitimate from trusted partner being flagged as spam)

All mailboxes hosted in the cloud with Exchange Online Fully Hosted Scenario Some mailboxes hosted in the cloud with Exchange Online Some mailboxes hosted on-premises MX record points to FOPE FOPE subscriptions are required for on-premises users Current FOPE Customer: Shared Address Space with On- Premises Relay Scenario (MX Points to FOPE) Some mailboxes hosted in the cloud with Exchange Online Some mailboxes hosted on-premises MX record points to on-premises Shared Address Space with On- Premises Relay Scenario (MX Points to On-Premises) Some mailboxes hosted in the cloud with Exchange Online Some mailboxes hosted on-premises MX record points to FOPE FOPE subscriptions are required for on-premises users Non-FOPE Customer: Shared Address Space with On- Premises Relay Scenario (MX Points to FOPE)

FOPE EXCHANGE ONLINE INTERNET Mail is sent outbound Virus scanning is performed by FPE on Exchange Online servers FOPE filters as outbound FOPE delivers to Internet Contoso signs up for Exchange Online Exchange Online has provisioned tenant in FOPE Mail sent to FOPE FOPE filters inbound mail Virus scanning is performed by FPE on Exchange Online servers Mail is delivered to the recipient’s mailbox Inbound From: To: Inbound From: To: Outbound From: To: Outbound From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE INTERNET MX points to FOPE for spam processing, filtering, and scanning Mail is routed to on-premises server, and if mailbox does not exist on- premises, mail is routed back to FOPE FOPE forwards mail to hosted mailbox Virus scanning is performed by FPE for Exchange Online mailboxes Inbound From: To: Inbound From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE INTERNET Scanning by Forefront Protection for Exchange on Microsoft Exchange Online mail hubs Delivery to FOPE for scanning Delivered to on-premises Exchange server Custom processing on premises Outbound delivery to FOPE Delivery to Internet Outbound From: To: Outbound From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE Hosted mailbox sends mail outbound Delivery to FOPE (virus scanning disabled by default; policy rules dependent on customer configuration) Delivery to on-premises mailbox Outbound From: To: Outbound From: To:

On-Premises EXCHANGE ONLINE FOPE INTERNET MX points to on premises for initial filtering Custom filtering, archival etc. done on- premises Cloud mail is re-directed to FOPE where it is filtered Delivered to Exchange Online Virus scanning is performed by FPE for Exchange Online mailboxes Inbound From: To: Inbound From: To:

On-Premises EXCHANGE ONLINE FOPE INTERNET Hosted mailbox sends mail outbound Virus scanning is performed by FPE for Exchange Online mailboxes Filtered by FOPE Delivered to on-premises Custom processing on-premises Delivery by on-premises Outbound From: To: Outbound From: To:

EXCHANGE ONLINE FOPE On-Premises MX points to on-premises for initial filtering Custom processing on-premises Delivery to FOPE Filtering skipped Delivery to Exchange Online by FOPE Intra Org From: To: Intra Org From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE INTERNET MX points to FOPE for spam processing, filtering, and scanning Mail is routed to Exchange Online, and if mailbox does not exist in the Exchange Online, mail is routed back to FOPE FOPE forwards mail to On-Premise Exchange Virus scanning is performed by FPE for Exchange Online and mailboxes Inbound From: To: Inbound From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE INTERNET Scanning by Forefront Protection for Exchange on Microsoft Exchange Online mail hubs Delivery to FOPE for scanning Delivered to Internet Directly (Could also direct outbound back to on-premises Exchange server) Outbound From: To: Outbound From: To:

On-Premises Exchange EXCHANGE ONLINE FOPE Hosted mailbox sends mail outbound Delivery to FOPE (virus scanning disabled by default; policy rules dependent on customer configuration) Delivery to on-premises mailbox Outbound From: To: Outbound From: To:

31

demo

Sessions On-Demand & CommunityMicrosoft Certification & Training Resources Resources for IT ProfessionalsResources for Developers Connect. Share. Discuss.

Scan the Tag to evaluate this session now on myTechEd Mobile