Appendix A: Avanan Manual Integration with Office 365 Mail

Note:
  • Automatic mode for onboarding allows for better maintenance, management, and smoother user experience. Avanan recommends only using Manual mode as a last resort. Before using the Manual mode, contact Avanan Support to help resolve any issues raised with the Automatic mode for onboarding.

After you select to bind Avanan to your Office 365, the Office 365 Install Mode window opens.

Select one of these modes:

  • Automatic mode - Avanan automatically configures Office 365 emails to operate in Detect modes (Monitor only and Detect and Remediate) and/or Protect (Inline) mode. You only need to authorize the Avanan app during the wizard and all configuration changes are applied automatically.

  • Manual mode - You must manually perform the necessary configurations in the Office 365 Admin Exchange Center before you bind the application.

This topic explains the various settings that need to be configured for Manual mode in the Office 365 Exchange Admin Center.

We recommend that you review if any of these scenarios listed below apply to you:

  • You want to choose automatic mode but first want to learn the configuration changes that are automatically applied to Office 365.

  • You want to choose manual mode and need to know what the initial configuration should be.

Note:

Note - In this guide, {portal} refers to your portal name. The portal name can be found in the Office 365 Install window. For more information, see Portal Identifier of Avanan Tenant.

If you have any queries about how to apply these changes in the configuration, contact the Avanan Support for assistance.

Note:

Manual deployment does not support user blocking or provide visibility into the Microsoft Quarantine. For more information, see Unified Quarantine for Manual Mode On boarding with Office 365 Mail.

Manual Integration with Office 365 Mail - Required Permissions

As these configurations are not managed by Avanan, Manual mode require less permissions when compared with Automatic mode.

API Permissions - Display Name

Permissions required from Office 365 for manual integration

Functions performed by Avanan

Read all audit log data

AuditLog.Read.All

Used to detect anomalous user behavior and trigger workflows for compromised accounts.

Used to protect contacts and scope policies for users.

Read contacts in all mailboxes

Contacts.Read

Get orgContact OrgContact.Read.All Used to protect org Contacts and scope policies for users.

Read and write calendars in all mailboxes

Calendars.ReadWrite

Used to remove calendar invites added by malicious emails.

Read domains

Domain.Read.All

Collect protected domains to:

  • Secure domains.

  • Skip inspection and avoid returning emails from other domains to Microsoft.

  • Allow DMARC Management for these domains.

  • Automatically apply branding to the Security Awareness Training end user experience.

Read all groups

Group.Read.All

Used for mapping users to groups to properly assign policies to users.

Read all published labels and label policies for an organization

InformationProtectionPolicy.Read.All

Read Microsoft Sensitivity Labels to use them as part of the Check PointDLP policy.

Read and write mail in all mailboxes

Mail.ReadWrite

Used for these:

  • Enforcing Detect and Remediate policy rules, where emails are quarantined or modified post-delivery.

  • Allowing administrators to quarantine emails that are already in the users' mailboxes.

  • Allowing administrators to restore emails to users' mailboxes.

  • Baselining communication patterns as part of Learning Mode.

Read and write all user mailboxes settings

MailboxSettings.ReadWrite

Used for these:

  • Read mailbox rules to detect compromised accounts.

  • Add a mailbox rule as part of the Graymail workflow.

Read all hidden memberships

Member.Read.Hidden

Used to collect hidden group members to support policy assignment, policy enforcement, and user-based reporting.

Read all directory RBAC settings

RoleManagement.Read.Directory

Used to collect users and their roles to scope policies, enforce them, and generate user-specific reports.

Read all users' full profiles

User.Read.All

Used to collect all users for the purposes of protection and policy scoping.

Use Exchange Web services with full access to all mailboxes

full_access_as_app (Office 365 Exchange Online)

Required to allow the execution of other Microsoft Exchange APIs.

Read and write mail in all mailboxes

Mail.ReadWrite (Office 365 Exchange Online)

Used for these:

  • Enforcing Detect and Remediate policy rules, where emails are quarantined or modified post-delivery.

  • Allowing administrators to quarantine emails that are already in the users' mailboxes.

  • Allowing administrators to restore emails to users' mailboxes.

  • Baselining communication patterns as part of Learning Mode.

Read activity data for your organization

ActivityFeed.Read (Office 365 Management APIs)

Collecting user login events, Microsoft defender events and Active Directory hierarchy changes to detect compromised accounts and maintain an up-to-date user hierarchy.

Send mail as any user

Send mail as any user

Used to send notifications to end users in scenarios where Microsoft does not support other delivery methods.

Policy Modes

  • Monitor only - Monitors the emails and creates the relevant event.

  • Detect and Remediate - Creates an event, and also performs retroactive enforcement for Inbound emails already delivered to users.

  • Protect (Inline) - All emails are reviewed before delivery to the user.

Monitor only and Detect and Remediate have the same configuration and are sometimes referred to as Detect modes in this document.

Note:

Best Practice - We recommend that you start with the configuration for Detect modes and later change to Protect (Inline). If you are already in one of the Detect modes and want to start with Protect (Inline) mode, skip to Step 7 - Protect (Inline) Protection Mode Policy Configuration on Avanan.

Note:

For the system to work properly, you must follow the steps in the order they appear.