Jump to main content
Avanan
Administration Guide
Index
Avanan Administration Guide
Search
Important Information
Related Documents
Introduction to
Avanan
Getting Started
Accessing the
Avanan
Administrator Portal
Portal Identifier of
Avanan
Tenant
Licensing the
Avanan
Product
Managing
Avanan
Licenses
Limiting License Consumption and Security Inspection to a Specific Group
Manual Changes to License Assignment
Trial Period for
Avanan
in the
Check Point Portal
Managing Users, Roles, and their Permissions
Activating
SaaS
Applications
Minimum License Requirements to Activate
SaaS
Applications
Activating
Office 365
Mail
Office 365
Mail - Required Roles and Permissions
Automatic Mode Onboarding -
Microsoft 365
Footprint
Mail Flow Rules (Transport Rules)
Avanan
- Protect Outgoing Rule
Avanan
- Protect Internal Rule
Avanan
- Protect Rule
Avanan
- Whitelist Rule
Avanan
- Junk Filter Low Rule
Avanan
- Junk Filter Rule
Avanan
- Encryption
Connectors
Avanan
Inbound
Connector
Avanan
DLP
Inbound
Connector
Avanan
Internal Inbound
Connector
Avanan
Outbound
Connector
Avanan
DLP
Outbound
Connector
Avanan
Journaling Outbound
Connector
Connection Filters
Journal Rules
Groups
Distribution Lists
Spoofed Senders Allow List
Trusted ARC Sealers
Reported Phishing Emails
Delegated Token
PowerShell Scripts
Connecting Multiple Portals to the Same
Microsoft 365
Account
Connecting Multiple
Avanan
Tenants
Connecting Multiple Tenants to the same
Microsoft 365
Account -
Microsoft 365
Footprint
Deactivating
Office 365
Mail
Activating Microsoft Teams
Activating
Office 365
OneDrive
Activating
Office 365
SharePoint
Activating
Google Workspace
(Gmail and Google Drive)
Activating Gmail
Activating Google Drive
Google Workspace
Footprint
Super Admin
Changing the Google Application Role
Performing Actions on Behalf of Users
User Groups
Host
Inbound
Check Point Firewall
SMTP Relay Service
Content Compliance Rules
Google Drive Permissions Changes
Activating Slack
Onboarding Next Steps
Migrating from an
Avanan
Portal to a
Check Point Portal
Migration Steps
Accessing the
Check Point Portal
User Management and Access to the
Avanan
Portal
Configuring Security Engines
Anti-Phishing
(Smart-Phish)
Anti-Malware
(
Check Point
SandBlast
)
Data Loss Prevention
(SmartDLP)
DLP
Policies
DLP Categories
DLP
Data Types
Creating a Custom Regular Expression
DLP
Data Type
Validating Regular Expression
Dictionary
DLP
Data Types
Compound
DLP
Data Types
Creating a Custom Compound
DLP
Data Type
Edit, Clone, or Delete Custom
DLP
Data Types
Configuring Advanced
Data Type
Parameters
Configuring
DLP
Engine Settings
DLP
Exceptions
Forensics
Click-Time Protection
Configuring Click-Time Protection Engine
Rewritten
Avanan
URL
Click-Time Protection Against Malicious Files Behind Links
Click-Time Protection - End-User Experience
URL Reputation
Email Protection
Office 365
Mail
Office 365
Mail Security Settings
Configuration Templates for
Office 365
Mail
Protecting
Microsoft 365
Groups
Adding a New Domain to
Microsoft 365
Overriding Microsoft's False Positive Detections
Emails Falsely Quarantined by Microsoft
Emails Falsely Sent to Junk by Microsoft
Viewing
Office 365
Mail Security Events
Viewing Security Events for Microsoft Quarantined Emails
Visibility into Microsoft Defender Verdict and Enforcement
Google Gmail
Gmail Security Settings
Configuration Templates for Google Gmail
Viewing Gmail Security Events
Configuring Email Policy
Threat Detection Policy
Threat Detection Policy for Incoming Emails
Excluding Members of
Microsoft 365
Groups from a Prevent (Inline) Policy
Manually Controlling IP Exceptions in
Microsoft 365
Mail Flow Rules
Threat Detection Policy for Outgoing Emails
Supported Workflow Actions
Prerequisites to Avoid Failing SPF Checks
Threat Detection Policy for Internal Emails
Threat Detection Policy Workflows
Malware Protection
Phishing Protection
Customizing the Subject Prefix for Phishing Warning Emails
Configure the Subject Prefix
Password Protected Attachments Protection
Requesting Passwords from End Users - End-User Experience
Quarantine. User is alerted and allowed to restore the email workflow
Password Protected Attachments -
Administrator
Experience
Attachment Cleaning (
Threat Extraction
)
Configuring Attachment Cleaning (
Threat Extraction
) for
Office 365
Mail or Gmail
Attachment Cleaning (
Threat Extraction
) Clean Attachments and Workflows
Threat Extraction Exceptions
Attachment Cleaning (
Threat Extraction
) – File Types and Attachments
Viewing Emails with Cleaned Attachments
Sending the Unmodified Emails to End Users
Attachment Cleaning (
Threat Extraction
) - End-User Experience
Smart Banners for Non-Clean Emails
Spam Protection
Trusted Senders
Graymail Workflows
Quarantined Emails - End-User Experience
Data Loss Prevention
(
DLP
) Policy
Sync Times with Microsoft
Enhanced
DLP
Policy using Microsoft Purview Sensitivity Labels
Configure
DLP
Policy with File Type Criteria
Configuring Misdirected Email Prevention
Configuring the Maximum Alerts shown to the End Users
DLP Policy for Outgoing Emails
DLP
Subject Regular Expression (Regex)
Subject Regular Expressions Syntax
DLP
Workflows for Outgoing Emails
DLP
Alerts for Outgoing Emails
Prerequisites to Avoid Failing SPF Checks
Outgoing Email Protection -
Office 365
Footprint for
DLP
DLP
Policy Sensitivity Level
DLP
Policy for Incoming Emails
DLP
Workflows for Incoming Emails
DLP
Alerts for Incoming Emails
Encrypting Outgoing Emails
Microsoft Encryption for Outgoing Emails
Encrypting Outgoing Emails using
Avanan
Email Encryption
Click-Time Protection Policy
Notifications and Banners
Sending Email Notifications to End Users
Customizing the From address for Email Notifications
Warning Banners
Smart Banners
Notification and Banner Templates - Placeholders
Legacy Archiving
Email Archiving
Searching and Viewing Archived Emails
Litigation Holds
Importing Emails to Archive
Exporting Emails from Archive
Auditing
Support for S/MIME-Signed Emails
Messaging Apps Protection
Microsoft Teams
Microsoft Teams Security Settings
Configuring Malware Policy for Microsoft Teams
Configuring
DLP
Policy for Microsoft Teams
Secured Microsoft Teams Messages and Users
Viewing Microsoft Teams Security Events
Slack
Slack Security Settings
Configuring Malware Policy for Slack
Configuring
DLP
Policy for Slack
Viewing Slack Security Events
File Storage Protection
Office 365
OneDrive
Office 365
OneDrive Security Settings
Configuring Malware Policy for
Office 365
OneDrive
Configuring
DLP
Policy for
Office 365
OneDrive
Viewing
Office 365
OneDrive Security Events
Office 365
SharePoint
Office 365
SharePoint Security Settings
Configuring Malware Policy for
Office 365
SharePoint
Configuring
DLP
Policy for
Office 365
SharePoint
Viewing
Office 365
SharePoint Security Events
File Cleaning (
Threat Extraction
) for
Office 365
OneDrive and
Office 365
SharePoint
Configuring Microsoft Teams File Scanning for E1/E3 Tenants
Google Drive
Google Drive Security Settings
Configuring Malware Policy for Google Drive
Configuring
DLP
Policy for Google Drive
Viewing Google Drive Security Events
Action on Files Placed in Vault
Shared Files from Unprotected Drives
Compromised Account (Anomaly) Detection
Critical Anomalies
Suspected Anomalies
Configuring Anomaly Detection Workflows
Automatically Blocking All Outgoing Emails
Configuring Settings for Impossible Travel Anomaly
Creating Anomaly Exceptions
Partner Risk Assessment (Compromised Partners)
Cloud SMTP Relay
Access the
Domains
Section
Configure a
Domain
Configure DNS Records
Configure the Relay MX Record
Configure the SPF Record
Configure the DKIM Record
Re-checking DNS Records
Access the Relay Sources Section
Adding a New Relay Source
Activate Cloud Email Relay
Managing Domains and Relay Sources
Deliverability Reporting
Sender Domain Selection and DNS Requirements
SMTP Relay Email Retention
Managing Security Exceptions
Security Engine Exceptions
Anti-Phishing
Exceptions
Anti-Malware
Exceptions
DLP
Exceptions
Click-Time Protection Exceptions
URL Reputation Exceptions
Threat Extraction
Exceptions
Trusted Senders - End-User Allow-List
Global
IoC
Block List (IOC Management)
Managing Security Events
Dashboards, Reports and Charts
Overview Dashboard
Security Widgets
Security Events
Application Protection Health
Login Events Map
Avanan
Flow Charts
Analytics Dashboard
Customizing the Analytics dashboard using Infinity AI Copilot
Office 365 Email and Gmail Analytics
Office 365 OneDrive Analytics
Google Drive Analytics
Shadow IT Analytics
User Interaction
Dashboard
Security Checkup Report
Security Checkup Report Recipients
Generating a Security Checkup Report
Last 30 Days Security Checkup Report
Scheduling the Security Checkup Report
Configuring a Report Schedule
Default Weekly Report and Managing Report Schedule
Reviewing Security Events
Events
Attachment Preview
Reviewing Phishing Events
Reviewing Malware Events
Automatic Ingestion of End User Reports
Retention of Security Events
Searching for Emails
Mail Explorer
Acting on Filtered Results in Mail Explorer
Custom Queries
Creating and Saving a New Query
Filtering the Query Results
Updating the Query Details
Exporting a Query Results to your Email Address
Scheduling an Export of Query Results to your Email Address
Modifying the Query Columns
Performing Bulk Actions on Query Results
Quarantining a Query Results
Restoring a Query from Quarantine
Sending a Query Alerts and Reports to Users
Manually Sending Items to Quarantine
Remediating Compromised Accounts
Blocking a User Account
Resetting a User Account Password
Unblocking a Blocked User Account
Resetting Password and Unblocking a Blocked User Account
Monitoring and Auditing Actions on Users
System Settings
System Tasks
System Logs
Service Status
SIEM / SOAR Integration
Supported SIEM & SOAR Integrations
Configuring SIEM Integration from the
Check Point Portal
Extending Formats to Include Additional Information
Forwarding Logs in Syslog Format
Forwarding Audit Logs to SIEM
Supported Security Events and Field Mapping References for SIEM
Forwarding Events to
AWS
S3
Configuring
AWS
S3 to Receive
Avanan
Logs
Configuring
AWS
S3 to Send
Avanan
Logs to Splunk
Recommended Configuration for known SIEM Platforms
Configuring
Avanan
with Microsoft Sentinel
Step 1: Creating an Azure Resource Group
Step 2: Creating a Log Analytics Workspace
Step 3: Enabling Microsoft Sentinel
Step 4: Installing the
Avanan
Solution
Step 5: Retrieving the Data Collection Rule (DCR) Information
Step 6: Retrieving the Logs Ingestion Endpoint
Step 7: Retrieving the Microsoft Entra Tenant ID
Step 8: Creating a Microsoft Entra Application
Step 9: Granting Application Access to the DCR
Step 10: Configuring Microsoft Sentinel in
Avanan
Step 11: Verifying the Integration
Configuring Integration with Cortex XSOAR by Palo Alto Networks
CrowdStrike Integration
Step 1 - Create a CrowdStrike Data Connection
Step 2 - Configure CrowdStrike SIEM Integration
Managing Quarantine
Emails with Modified Attachments
End-User Daily Quarantine Report (Digest)
Enabling the End-User Quarantine Digest
Emails Included in the Quarantine Digest
Configuring Recipients for the End‐User Quarantine Digest
Configuring the Available End User Actions in the Daily Quarantine Digest
Scheduling and Coverage Timeframe for the Quarantine Digest
Allowing End Users to Manually Request a Quarantine Digest on Demand
Configuring a Custom Sender for the Quarantine Digest
Customizing the Text of the Quarantine Digest
Customizing Action Labels
End-User Portal (
Avanan
Portal)
Accessing the
Avanan
Portal
Enable or Disable an Authentication Method
Authorizing Login Access for the Organization
Accessing the
Avanan
Portal from Outlook
Required Permissions for Microsoft/Google Login Authorization
Limiting End User Portal Access to Specific Users or Groups
Including Blocklisted Emails in the End User Portal
Read and Unread Status of Emails in the End User Portal
Filtering Emails by their State
Acting on Emails
Managing Restore Requests
Quarantine Restore Requests
Requesting a Restore from Quarantine - End-User Experience
Restore Requests for Emails Sent to Groups - End-User Experience
Restoring Emails Without Administrator Approval - End-User Experience
Admin Quarantine Release Process
Cleaned Attachments Restore Requests
Restoring Quarantined Emails - End-User Experience
Notifying End Users about Rejected Quarantine Restore Requests
Restore Requests - Notifications and Approvers
Authentication for Email Notifications
Customization
Adding a Custom Logo
Adding a Branded Header and Footer to Admin Email Notifications
Customizing Time Zone for Email Notifications and Reports
Customizing End User Browser Pages Language
Customizing Retention Period of Emails
Auditing
SmartConfig Recommendations
Incident Response as a Service (IRaaS)
DMARC Management
DMARC
RUA Mailbox Hosted by
Avanan
Discovering Domains from RUA Reports
Virtual RUF Reports
Adding a New Domain
DMARC Widgets
Reviewing the DMARC Status of your Domains
Annotating / Tagging Domains and Sending Sources
Investigating Domains and Sending Sources
Viewing Specific RUA Reports
Improving your Domains' DMARC Enforcement
Monitoring SPF and DMARC Changes
Annotating / Commenting on SPF and DMARC Changes
SPF Management
Manually Adding New Source to SPF Records
Configuring and Defining the SPF Record
Managing Sending Sources
DKIM Management
Activating DKIM Management
Manually Adding New DKIM Selector to your Domain
Managing Selectors
Alerts and Reports
Adding a New Alert
Leaked Credentials
Resetting Passwords for a Compromised User Account
Blocking a Compromised User Account
Security Awareness Training
Creating Security Awareness Training Policy
Customizing Security Awareness Training Policy
Daily Sending Frequency
Customizing the Sender of Security Awareness Training Notifications
Custom Phishing Simulation Templates
Custom Phishing Simulation Templates – Placeholders
Importing Template Email Details from a Learning Management System (LMS)
Assigning Custom Phishing Simulation Templates to Users
Adding a Banner to Phishing Simulation Emails
Authorizing Training Module Access for the Organization
Security Awareness Training Email Headers
Branding the Security Awareness Training Web Page
Security Awareness Training Domains
Monitoring User Interactions with Phishing Simulations
Monitoring User Training Progress
Monitoring Phishing Simulations
Monitoring User Awareness Training Progress
Searching for Security Awareness Training Related Emails in Mail Explorer
Security Awareness Training - End User Experience
Supported Languages for Phishing Simulations and Training Modules
Phishing Simulation Email - End User Experience
Available Training Modules
User Management
Adding a New User
Updating User Information
Deleting a User
Configuration
SAML
SAML
Configuration for
Azure
SAML Configuration for Duo
SAML Configuration for Idaptive
SAML Configuration for JumpCloud
SAML
Configuration for
Okta
Multi-Factor Authentication
using Google Authenticator
Enforcing MFA for the User
Enabling MFA by a User
Logging in via Google Authenticator - End User Experience
Video Tutorials
How to Onboard Office 365 Mail with
Avanan
How to Onboard Microsoft Teams with
Avanan
How to Onboard Office 365 OneDrive with
Avanan
How to Onboard Office 365 SharePoint with
Avanan
How to Onboard Gmail with
Avanan
How to Onboard Google Drive with
Avanan
How to Contact
Check Point
Support and Incident Response Team from the
Avanan
Administrator Portal
Phishing Email End-User Experience with
Avanan
Password-Protected Attachments End-User Experience with
Avanan
Check Point
Email Encryption End-User (External Recipient) Experience with
Avanan
How to Enable Smart Banners to Emails with
Avanan
How to Configure Daily Quarantine Report (Digest) in
Avanan
and Allow End Users to Generate a Report on Demand
How to Configure Security Awareness Training Policy in
Avanan
How to Configure Outlook Add-In with
Avanan
User Interaction Administrator Experience with
Avanan
How to Request to Restore Quarantined Phishing Emails End User Experience with
Avanan
How to Respond to Misdirected Email Warnings in Outlook
How to Report a Phishing Email in Outlook
How to Access the
Avanan
Portal from Outlook
Smart Banners and Trusted Senders End-User Experience with
Avanan
Appendix
Appendix A:
Avanan
Manual Integration with
Office 365
Mail
Step 1 - Authorize the Manual Integration Application
Step 2 - On-boarding (Monitor only and Detect and Remediate)
Step 3 -
Avanan
Contact
Step 4 - Journal Rule
Step 5 - Connectors
Step 6 - Connection Filter (All Modes)
Step 7 - Protect (Inline) Protection Mode Policy Configuration on
Avanan
Step 8 - Connectors (Protect (Inline) Mode)
Step 9 - Transport Rules (Protect (Inline) Mode)
Avanan
- Protect External
Avanan
- Protect Internal
Avanan
- Protect
Avanan
- Allow-List
Avanan
- Junk Filter
Avanan
- Encryption
Transport Rules
Step 10 - Sending User Reported Phishing Emails to an Internal Mailbox
Reverting Manual Onboarding / Switching to Automatic Onboarding
Unified Quarantine for Manual Mode On boarding with
Office 365
Mail
Appendix B:
Avanan
Manual Integration with Google Gmail
Step 1: Add Groups
Step 2: Adding a Host
Step 3: Updating Inbound
Check Point Firewall
Step 4: Adding SMTP Relay Host
Step 5: Create a Compliance Rule
IP Addresses Supported by Region for Google Gmail
Appendix C: Manual Steps for Enabling Gmail Prevent (Inline)
DLP
Policy
Step 1: Adding a Host
Step 2: Updating Inbound
Check Point Firewall
Step 3: Adding SMTP Relay Host
Step 4: Add Groups
Step 5: Create a Compliance Rule
IP Addresses Supported by Region for Gmail Prevent (Inline) Policy
Appendix E:
DLP
Built-in
Data Types
and Categories
Appendix F: Supported Languages for
Anti-Phishing
Appendix G: Data Retention Policy
Appendix H: Activating
Office 365
Mail in Hybrid Environments
Appendix I: Permitted IP Addresses to access the
Avanan
Azure Application
Appendix J: Supported File Types for
DLP
Appendix K: Troubleshooting
Appendix L: Outlook Add-In
Configuring the Outlook Add-In
Generating the Add-In XML
Deploying the Outlook Add-In through
Microsoft 365
Admin Center
Outlook Add-In - Supported Outlook Types and Platform
Automatic Localization of the Outlook Add-In Experience
Appendix M: Configuring Postfix as an Internal SMTP Relay for Non‐TLS Senders to
Avanan
Cloud SMTP Relay
Postfix Configuration
Restart Postfix to Load the New Configuration
Example Postfix Configuration File
Testing and Debugging Postfix
11 September 2026
© 2024 - 2026 Check Point Software Technologies Ltd.