Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions public/__redirects
Original file line number Diff line number Diff line change
Expand Up @@ -496,6 +496,9 @@
/cloudflare-one/email-security/directories/manage-ms-directories/manage-groups-directory/ /cloudflare-one/email-security/directories/manage-integrated-directories/manage-groups-directory/ 301
/cloudflare-one/email-security/directories/manage-ms-directories/manage-users-directory/ /cloudflare-one/email-security/directories/manage-integrated-directories/manage-users-directory/ 301
/cloudflare-one/email-security/setup/partner-domain-tls/ /cloudflare-one/email-security/setup/pre-delivery-deployment/partner-domain-tls/ 301
/cloudflare-one/email-security/setup/pre-delivery-deployment/prerequisites/office365-email-security-mx/ /cloudflare-one/email-security/setup/pre-delivery-deployment/prerequisites/microsoft365-email-security-mx/ 301
/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/ /cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/ 301
/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/office365-journaling/ /cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/m365-journaling/ 301

# firewall
/firewall/api/cf-lists/ /waf/tools/lists/lists-api/ 301
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ sidebar:

import { GlossaryTooltip, Render } from "~/components"

Once you have chosen a [domain to scan](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#connect-your-domains), Email Security allows you to monitor the traffic scanned from your email inboxes.
Once you have chosen a domain to scan, Email Security allows you to monitor the traffic scanned from your email inboxes.

:::note
With Email Security, you can enable logs to send detection data to an endpoint of your choice. Refer to [Enable Email Security logs](/cloudflare-one/insights/logs/enable-logs/) for more information.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -172,7 +172,7 @@ To move messages:
* **Inbox**: Move messages to the primary email folder.
* **Junk email**: Move messages to the junk or spam folder.
* **Trash**: Move messages to the trash or deleted items email folder.
* **Soft delete (user recoverable)**: Move messages to the user's Deleted Items folder. This option is for Microsoft O365 only.
* **Soft delete (user recoverable)**: Move messages to the user's Deleted Items folder. This option is for Microsoft 365 only.
* **Hard delete (admin recoverable)**: Delete messages from a user's inbox.
4. Select **Save**.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ After creating your policy, you can modify or reorder your policies in **Email S

## 2. DLP Assist add-in

The Data Loss Prevention (DLP) Assist add-in allows Microsoft O365 users to deploy a DLP solution for free using Cloudflare's Email Security.
The Data Loss Prevention (DLP) Assist add-in allows Microsoft 365 users to deploy a DLP solution for free using Cloudflare's Email Security.

To set up DLP Assist add-in:

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ To start a free scan:
1. Log in to [Zero Trust](https://one.dash.cloudflare.com/).
2. Select **Email Security** > **Overview**.
3. Select **Start a free scan** > **Generate report**.
4. Enable your [Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#enable-microsoft-integration).
4. Enable your [Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration).
5. Generate Retro Scan report:
- **Connect domains**: Select at least one domain from your integration.
- **Select current solution**: Select the email security tool you are currently using.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Before you start the onboarding process, you will have to:

When you choose post-delivery deployment, Cloudflare scans emails **after** they reach a users' inbox.

If you are a Microsoft 365 user, this is done via [Microsoft's Graph API](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/) or [journaling](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/office365-journaling/).
If you are a Microsoft 365 user, this is done via [Microsoft's Graph API](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/) or [journaling](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/m365-journaling/).

If you are a [Google Workspace](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/gmail-bcc-setup/) or [Microsoft Exchange](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/bcc-microsoft-exchange/) user, this is done via BCC.

Expand Down Expand Up @@ -106,7 +106,7 @@ Follow the below checklist to ensure your email environment is set up correctly:

| Step | Post-delivery | Pre-delivery |
|---------------------------------------------------------------------------------------------------------|---------------|--------------|
| Authorize integration ([Graph API](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#enable-microsoft-integration) or [Google Workspace](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/)) | Required[^1] | Required [^2] |
| Authorize integration ([Graph API](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration) or [Google Workspace](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/)) | Required[^1] | Required [^2] |
| Associate an integration with an MX/Inline domain | | Required |
| Add/verify domains | Required | Required |
| [Update MX records/connector](/cloudflare-one/email-security/setup/pre-delivery-deployment/mx-inline-deployment-setup/), then allow Cloudflare [egress IPs](/cloudflare-one/email-security/setup/pre-delivery-deployment/egress-ips/) on downstream mail server | | Required |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ sidebar:

import { Render } from "~/components"

This guide will instruct you through setting up Microsoft Office 365 with Email Security via the Cloudflare dashboard.
This guide will instruct you through setting up Microsoft 365 with Email Security via the Cloudflare dashboard.

## Prerequisites

Expand All @@ -24,10 +24,10 @@ To use Email Security, you will need to have:
- If you have not associated any integration:
- Select **Set up**.
- Choose **MS Graph API** > **Authorize**.
- Refer to [Enable Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#enable-microsoft-integration) to continue the onboarding process.
- Refer to [Enable Microsoft integration](#enable-microsoft-integration) to continue the onboarding process.
- If you have associated an integration, but have not connected a domain:
- Select **Connect a domain**.
- Choose **MS Graph API**. Refer to [Connect your domains](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#connect-your-domains) to connect your domain(s).
- Choose **MS Graph API**. Refer to [Connect your domains](#connect-your-domains) to connect your domain(s).

### Enable Microsoft integration

Expand All @@ -42,7 +42,7 @@ To enable Microsoft integration:
- Select **Complete Email Security set up** where you will be able to connect your domains and configure auto-moves.
- Select **Continue to Email Security**.

Continue with [Connect your domains](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#connect-your-domains) for the next steps.
Continue with [Connect your domains](#connect-your-domains) for the next steps.

### Connect your domains

Expand Down
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
---
title: Office 365 journaling setup
title: Microsoft 365 journaling setup
pcx_content_type: how-to
sidebar:
order: 2
---

import { GlossaryTooltip, Render } from "~/components"

When you receive an email, the email lands on your Microsoft O365 inbox, and then Email Security receives a copy of that email. The following email flow shows how this works:
When you receive an email, the email lands on your Microsoft 365 inbox, and then Email Security receives a copy of that email. The following email flow shows how this works:

![Email flow when setting up Office 365 with Email Security.](~/assets/images/email-security/deployment/api-setup/journaling/Email_Security_MS365_Journaling_Diagram.png)
![Email flow when setting up Microsoft 365 with Email Security.](~/assets/images/email-security/deployment/api-setup/journaling/Email_Security_MS365_Journaling_Diagram.png)

To enable Microsoft 365 journaling deployment:

Expand All @@ -20,9 +20,9 @@ To enable Microsoft 365 journaling deployment:
5. Select **BCC/Journaling**.
6. Select **Integrate with MS** > **Authorize**.

## Integrate with Microsoft O365
## Integrate with Microsoft 365

To integrate with Microsoft O365:
To integrate with Microsoft 365:

1. **Name integration**: Add your integration name, then select **Continue**.
2. **Authorize integration**:
Expand All @@ -33,7 +33,7 @@ To integrate with Microsoft O365:
- Select **Complete Email Security set up** where you will be able to connect your domains and configure auto-moves.
- Select **Continue to Email Security**.

Continue with [**Connect your domains**](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/office365-journaling/#connect-your-domains) for the next steps.
Continue with [Connect your domains](#connect-your-domains) for the next steps.

### Connect your domains

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,8 +35,8 @@ On the **Set up Email Security** page:

If you do not have domains with Cloudflare, the dashboard will display two options:

* Add a domain to Cloudflare.
* Enter domain manually.
- Add a domain to Cloudflare.
- Enter domain manually.

### Add a domain to Cloudflare

Expand All @@ -58,6 +58,6 @@ To enable auto-move events, you will have to connect and associate an integratio

1. Go to **Settings** > **Domain management** > **Domains** > Select **View**.
2. On the **Domain management** page, locate your domain, select the three dots, then select **Associate an integration**.
3. Select **Connect an integration**. Follow the steps to [enable the Microsoft Office 365 integration](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/office365-journaling/#integrate-with-microsoft-o365).
3. Select **Connect an integration**. Follow the steps to [enable the Microsoft 365 integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration).
4. Select the three dots, then select **Associate an integration**. Select the integration, then select **Associate**.
5. Now that your domain has an associated integration, enable [auto-move events](/cloudflare-one/email-security/auto-moves/) on your domain.
Original file line number Diff line number Diff line change
Expand Up @@ -11,15 +11,14 @@ Setting up egress IPs allows Cloudflare to deliver emails to your inbox.

Refer to this page for reference on what IP subnet mask ranges to use.

:::caution[Additional information for O365]
:::caution[Additional information for Microsoft 365]

Office 365 does not support IPv6 addresses nor the following IPv4 subnet mask ranges:
Microsoft 365 does not support IPv6 addresses nor the following IPv4 subnet mask ranges:

* `104.30.32.0/19`
* `134.195.26.0/23`

If you use Office 365, you will have to use the broken down `/24` subnet mask IP addresses. Refer to [Office 365 `/24` addresses](#office-365-24-addresses) for a list of supported IPv4 addresses.
- `104.30.32.0/19`
- `134.195.26.0/23`

If you use Microsoft 365, you will have to use the broken down `/24` subnet mask IP addresses. Refer to [Microsoft 365 `/24` addresses](#microsoft-365-24-addresses) for a list of supported IPv4 addresses.

:::

Expand Down Expand Up @@ -47,9 +46,9 @@ If you use Office 365, you will have to use the broken down `/24` subnet mask IP
35.157.195.63
```

## Office 365 `/24` addresses
## Microsoft 365 `/24` addresses

Use these IPv4 addresses for Office 365, instead of the `/19` and `/23` subnets:
Use these IPv4 addresses for Microsoft 365, instead of the `/19` and `/23` subnets:

```txt
104.30.32.0/24
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ To associate an integration:
2. Select **SaaS Integrations** > **Connect an integration**.
3. Select an application: Choose between **Google Workspace CASB + EMAIL**, or **Microsoft CASB + EMAIL**.
- Refer to [Enable Gmail BCC integration](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/bcc-setup/gmail-bcc-setup/enable-gmail-integration/#1-create-a-service-account-in-your-gcp-project) if you select **Google Workspace CASB + EMAIL**.
- Refer to [Enable Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/office365-api/#enable-microsoft-integration) if you select **Microsoft CASB + EMAIL**.
- Refer to [Enable Microsoft integration](/cloudflare-one/email-security/setup/post-delivery-deployment/api/m365-api/#enable-microsoft-integration) if you select **Microsoft CASB + EMAIL**.
4. After you have associated an integration, go to **Email Security** > **Set up**.
5. Follow the instructions to [connect a domain](/cloudflare-one/email-security/setup/pre-delivery-deployment/mx-inline-deployment-setup/#connect-a-domain).

Expand Down Expand Up @@ -85,4 +85,4 @@ Then, follow the steps to [Set up MX/Inline](/cloudflare-one/email-security/setu
3. **Verify your domains**: It may take up to 24 hours for your domains to be verified. Select **Done**.
4. Once your domains have been verified, the dashboard will display a message like this: **You have verified domains ready to connect to Email Security**. This means that you can now set up Email Security via MX/Inline.
5. Select **Set up**, then select **MX/Inline**.
6. Follow the steps to [Initiate MX/Inline configuration](/cloudflare-one/email-security/setup/pre-delivery-deployment/mx-inline-deployment-setup/#initiate-mxinline-configuration).
6. Follow the steps to [initiate MX/Inline configuration](/cloudflare-one/email-security/setup/pre-delivery-deployment/mx-inline-deployment-setup/#initiate-mxinline-configuration).
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
title: Office 365 as MX Record
title: Microsoft 365 as MX Record
pcx_content_type: integration-guide
sidebar:
order: 3
Expand All @@ -9,7 +9,7 @@ import { Render, Markdown, GlossaryTooltip } from "~/components"

![A schematic showing where Email Security is in the life cycle of an email received](src/assets/email-security/Email_Security_O365_MXInline.png)

In this tutorial, you will learn how to configure Microsoft Office 365 with Email Security as its MX record.
In this tutorial, you will learn how to configure Microsoft 365 with Email Security as its MX record.

<Render file="email-security/deployment/mx-deployment-prereq"/>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,4 +9,4 @@ While there are multiple deployment methods, the easiest way to get started with

When you choose the [API deployment](/cloudflare-one/email-security/setup/post-delivery-deployment/api/), Email Security can both scan and take actions on emails after they have reached a user's inbox.

With a [Journaling setup](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/office365-journaling/) alone without API integration, Email Security can only scan emails after it has reached a user's inbox.
With a [Journaling setup](/cloudflare-one/email-security/setup/post-delivery-deployment/bcc-journaling/journaling-setup/m365-journaling/) alone without API integration, Email Security can only scan emails after it has reached a user's inbox.
Loading