Configure Journaling - Microsoft O365

Configure Journaling - Microsoft O365

1.0 Introduction

This KB Article provides instructions of how to set up journaling to the IoT Secure Cloud Archiving Service from Microsoft 365.

2.0 Setup Journaling

2.1 Add a Remote Domain and Connector

  1. Log into Microsoft 365 Exchange admin center.
  2. Navigate to mail flow > remote domains.
  3. Select Add a remote domain.
  4. Complete the following: 
    1. NameIoT Secure Archiving
    2. Remote domain:  archive.iotsecure.io

  5. Click Next.
  6. Define the following settings:
    1. In the Out of Office automatic reply types section, click None
    2. In the Automatic replies section, select Allow automatic forwarding and uncheck Allow automatic replies. Click Next.
      bcasReplyTypes.png
  7. In the Message reporting section,  uncheck Allow delivery reports and Allow non-delivery reports. Click Next.
    bcasMessageReport.png
  8. In the Use rich-text format section, select Never. Click Next.

    bcasTextSet.png

  9. Review your settings, and then click Save
  10. Navigate to Mail flow > Connectors.
  11. Click Add a connector.
  12. Define the following settings:
    1. In the Connection from section, select Office 365.
    2. In the Connection to section, select Partner organization. Click Next.
      BCASNewConnector.png
  13. Enter a Name for the connector. Click Next.

  14. Define the following settings:
    1. Select Only when email messages are sent to these domains.
    2. Type archive.iotsecure.io and then, click the blue +. Click Next.

  15. Select Use the MX record associated with the partner's domain. Click Next.
    bcasRouting.png
  16. Select Always use Transport Layer Security (TLS) to secure the connection (recommended) > Any digital certificate, including self-signed certificates. Click Next.
    bcasSecurity.png

  17. Get your unique Journalg Address from IoT Secure.
  18. In Microsoft 365, paste this email address into the provided field in the Verification page. Click the blue +, and then click Validate. The connector validation process starts.

    Note that the validation might fail. If the validation fails, click Next. You will see a yellow banner to confirm that you want to continue without successful validation. Click Yes.

  19. Click Next. Review your settings and click Create Connector.

The connector is created.


2.2 Create a Non-Delivery Report Recipient

Before creating journal rules, specify a journal recipient for non-delivery reports (NDRs) to reduce the risk of losing journal reports:

ndr_warning.png

To create an NDR recipient:

  1. Log into the Microsoft Purview compliance portal, navigate to Solutions > Data lifecycle management > Exchange (legacy).
  2. Click the Settings icon.
  3. In Send undeliverable journal reports to, enter the email address of a valid user account. Note that the mailbox must be a mail user, mail contact, or external user, not an Exchange Online Mailbox.

  4. Click Save.


2.3 Configure Microsoft 365 to Send Journal Mail

  1. Log into the Microsoft Purview compliance portal, navigate to Solutions > Data lifecycle management > Exchange (legacy) > Journal rules, and then select + New rule.
  2. On the Define journal rule settings page, provide a name for the journal rule and then configure the following options:
    1. Send journal reports to – Enter the journaling address from IoT Secure.  This is called the journaling mailbox.

    2. Journal rule name: IoT Secure Archiving Service

    3. Journal messages sent or received from – Select Apply to all Messages.

    4. Type of message to journal – Select All Messages.

  3. Select Next, review the settings, and then click Submit to create the journal rule.