Step 2 - Configure Microsoft 365 for Inbound and Outbound Mail
You can configure Microsoft 365 with Email Gateway Defense as your inbound and/or outbound mail gateway.
If you make changes to the settings, allow a few minutes for the changes to take effect.
Microsoft 365 IP addresses and user interfaces can change; refer to Microsoft documentation for configuration details.
You can specify Email Gateway Defense as an inbound mail gateway through which all incoming mail for your domain is filtered before reaching your Microsoft 365 account. Email Gateway Defense filters out spam and viruses, then passes the mail on to the Microsoft 365 mail servers.
You can also specify Email Gateway Defense as the outbound mail gateway through which all mail is sent from your domain via your Microsoft 365 account to the recipient. As the outbound gateway, Email Gateway Defense processes the mail by filtering out spam and viruses before final delivery. By configuring Microsoft 365, you instruct the Microsoft 365 mail servers to pass all outgoing mail from your domain to Email Gateway Defense (the gateway server).
Before you launch the wizard, verify you have the following:
Microsoft 365 admin credentials
Credentials to run a PowerShell script or terminal to manually execute PowerShell scripts
Note that you cannot reopen the wizard after you have completed the wizard. if you have started the wizard but did not complete it, log into Barracuda Cloud Control, select Email Gateway Defense on the left side. In the top banner, click Set Up Now to relaunch the wizard.
The setup wizard includes steps to identify your email server, add MX records, and remove MX records. Each of the domains where you want to filter email must be verified by Email Gateway Defense for proof of ownership; Email Gateway Defense does not process email for a domain until the verification process is complete.
Note that after verifying your domain, any mail sent to your domain from another Barracuda Email Gateway Defense customer will be processed normally by your Email Gateway Defense account and not delivered via MX records.
Log into Barracuda Cloud Control. If this is your first time launching the Email Gateway Defense setup wizard, you will be redirected to the Barracuda Trials Hub page. Click Open under Email Security.
Alternatively, if you have started the setup wizard but did not complete it, after logging into Barracuda Cloud Control, select Email Gateway Defense on the left side. In the top banner, click Set Up Now to launch the setup wizard.
The Email Gateway Defense wizard launches.
Click Next in the upper right corner to get started.
Click Connect to connect to Microsoft.
You will be prompted to log in with a global admin account to give permissions to the application to access your Microsoft data. Click Accept to authorize Barracuda Networks to access your details.
Once you are connected, Barracuda Networks will initiate a scan to identify any email threats. During this process, click Next in the upper right corner to continue.
Select the Region for your data center. Then click Next.
Confirm the domain you would like to protect. Then click Next.
Choose your deployment method.
Step 2. Deploy Partner Connector
The steps in this section enhance the security of the connection between Email Gateway Defense and Microsoft 365.
Create a Partner Connector
Creating a partner connector will allow you to use enhance filtering along with tenant access restrictions, ensuring a safe and secure environment.
Click the Add a connector button, and use the wizard to create a new connector.
For Connection from, select Partner organization. Then, click Next.
Enter a Name “Barracuda Inbound Connector” and (optional) Description to identify the connector. Then, click Next.
Select By verifying that the IP address of the sending server matches one of the following IP addresses, which belong to your partner organization.
Click the + to enter the correct IP range for your region. Then, click Next.
This is the region selected when setting up your Barracuda Networks instance. Refer to the Email Gateway Defense IP Ranges Used for Configuration for the IP ranges corresponding to your region.
For example, for the US region, enter 209.222.82.0/24.
Use the default settings for the Security restrictions: Reject email messages if they aren’t sent over TLS. Then, click Next.
Review your settings and then click Create connector.
Enable Enhanced Filtering for Connectors
To enable Enhanced Filtering for Connectors, use the following instructions:
Select Barracuda Inbound Connector, the partner connector you previously created.
Select Automatically detect and skip the last IP address and Apply to entire organization.
Click Save.
Review Microsoft Anti-Spam Settings
Enhanced Filtering for Connectors allows customers to continue to leverage anti-spam capabilities provided in Exchange Online. Review your Microsoft anti-spam policy to ensure it is configured to follow recommended best practices.
Log into the Microsoft Defender portal https://security.microsoft.com/.
On the left, navigate to Email & collaboration > Policies & rules.
Select Threat policies > Anti-spam.
Select Anti-spam inbound policy (Default).
Scroll down and click Edit actions.
Review your settings and click Save.
Contact Us
Barracuda Campus
Barracuda Support