Reducing the Assigned Microsoft Application Role

Email Security uses the Privileged Authentication Administrator role to block accounts that are detected as compromised. This role allows Email Security to block every compromised account, even if it is a Global Administrator. For more information, see Remediating Compromised Accounts.

After successfully Activating Office 365 Mail, administrators can reduce the Privileged Authentication Administrator role to any of the roles described in this Microsoft article.

Once you do that, Email Security will only be able to block compromised accounts that the selected role can reset their password (see this Microsoft article).

Note:
  • When reducing the application role, make sure to apply the lesser role first (see this Microsoft article) and then remove the more privileged role (see this Microsoft article).

  • If you have connected Email Security to Office 365 Mail prior to December 09, 2024, your application might be assigned with the Global Administrator role. You can manually reduce this role to Exchange Administrator, Privileged Authentication Administrator or a lesser role.

Instructions to reduce the assigned Microsoft application roles:

  1. Add the new roles to the Check Point application.
  2. Wait 30 minutes to allow the new roles to populate properly.
  3. Remove the old roles from the Check Point application.

Microsoft 365 Mail - Approving User

As part of activating Office 365 Mail protection, you need a user with the Privileged Role Administrator role or higher to approve the required permissions for the application.