Skip to main content
My preferencesSign out
Proofpoint, Inc.

Configuring Office 365 Remote Journaling

Situation Office 365 provides a remote journaling functionality to send a copy of all mail sent or received by members of a defined security
group to a remote SMTP address. Proofpoint provides you with the SMTP address to use for this configuration.
Solution
  1. Setup on Proofpoint Essentials Archive
  2. Configuring an Outbound Connector on Office 365
  3. Configuring a Journal Rule on Office 365
  4. Confirm Data is being Archived successfully

 

Proofpoint Essentials Archive Configuration

  1. From the Proofpoint Essentials UI, click Archive. If Legacy Archive is enabled on the account, a prompt will display.
  2. Select Launch Email Archive
    archive_tab.JPG             
  3. Click the Cog icon and select Settings.                                                                                            connection_icon.JPG
  4. Click the plus sign to create a new connection.
  5. Provide an appropriate description for the connection and set the Connection Type to SMTP (Office 365).
  6. Enter the appropriate address in the Undeliverable Journal Address field. connection_details.png

Note: This must match the email address entered in Step 5 of the section Configuring a Journal Rule on Office 365. If these do not match, Remote Journaling will not function. This email address will not be Journaled and is only used for error reporting.

  1. Click Next.
  2. Note the SMTP Address provided as it required for the configuration on Office 365. This can be viewed again later by editing the connection. 
    smtp_address.JPG
  3. Click Done

Configuring an outbound connector on office 365

  1. Open the Office 365 Admin Center.
  2. Click the Admin Centers icon on the left-hand sidebar and choose Exchange.                                                                                 exchange_admin.JPG
  3. In the Exchange Dashboard, under the mail flow heading, click connectors.                                                               
  4. Click the sign to add a new connector.
  5. Select Office 365 for the From dropdown menu and Partner Organization for the To menu.
  6. Click Next.
  7. Enter a descriptive Name (and optionally, Description) for the connector.
  8. Tick the checkbox Turn it on to turn on the connector when it is saved. You can also edit the connector and check the box at any time.
  9. Click Next.
  10. Select Only when email messages are sent to these domains, then click + and enter the fully qualified domain name of the mail server: *.earchive.cloud  will work.
  11. Click OK to return to the connectors screen.
  12. Click Next.
  13. Select Use the MX record associated with the partner’s domain.
  14. Click Next.
  15. Leave the default settings for the How should Office 365 connect to your partner organization's email server? step and click Next

The next screen will ask that you confirm your settings. Review these settings, clicking back should you need to make any corrections. Otherwise, click Next

     confirm_settings.jpg

  1. In the Validate this Connector step, click and enter the following address: verification@us.earchive.cloud

Note: The above address must be used for the validation step, otherwise validation will fail.

  1. When prompted to validate the connection, click Validate and wait for the validation operation to finish.
  2. Click Save.                                                                                                                                                                                                                                                                                                             

Configuring a Journal Rule on Office 365

This step assumes you are enabling journaling for all users.

  1. From the Exchange Admin dashboard, click Journal Rules under Compliance Management.
  2. Right above the action icons, where it says Send undeliverable journal reports to:, click Select address, click Browse, and select an admin email account. This account will receive notification of non-deliverable journal reports. 

Note: This must match the address set in Step 5 of Proofpoint Essentials Archive Configuration above.

  1. Click the + sign to create a new Journal Rule. 
  2. In the Send journal reports to field, enter the SMTP address of the journaling mailbox (e.g. 5er123acd-5432-123aa0a1-d9348328b71@us.earchive.cloud)

This was provided in Step 7 of Proofpoint Essentials Archive Configuration

  1. Enter a descriptive Name for the rule (e.g. Journaling to Proofpoint Archive).
  2. From the If the message is sent to or received from... list, choose Apply to all messages.
  3. From the Journal the following messages... list, choose All messages.
  4. Click Save.
  5. When prompted to confirm that you want the rule to apply to all messages, click Yes.

Confirm Data is being archived successfully

To confirm that data is now being archived successfully please make sure to login and search the Archive with a user that has Discovery User access to all Mailboxes. 

Set Discovery User Access for User

  1. Login to the Proofpoint Essentials Admin Console as an Organization Admin.
  2. Click the Archive tab (click Launch Email Archive if Legacy is also configured).
  3. In the Archive UI, click on the Users icon.
  4. Search for the desired user and click on the Pencil Icon next to their address to edit their settings.
  5. Tick the Discovery User checkbox.
  6. Select the All Mailboxes radio button.
  7. Click Save.