The steps outlined below detail how to grant Cloud Email and Collaboration
Protection access to Exchange Online (Inline Mode) with an Authorized Account from
Dashboard for Inline Protection over both inbound and
outbound messages.
Before the access grant, verify related security configuration in Microsoft to ensure
that Inline Protection for Exchange Online works properly for your organization and
emails get delivered as expected. For details, see Verifying related security settings in Microsoft.
NoteIf you have already granted access to Exchange Online (Inline Mode) for inbound
protection with a service account, upgrade the service account to have Inline
Protection in the outbound direction as well:
Go to
, locate your Exchange Online (Inline Mode) service account, click
Upgrade for Outbound Protection, and follow the
onscreen instructions to complete the procedure. |
Procedure
- Go to .
- Click Grant Access in the Action
column for Exchange Online (Inline Mode).The Grant Access to Exchange Online (Inline Mode) screen appears.
- Select the policy to enable automatically when the access grant is complete.
- Grant Cloud Email and Collaboration
Protection the permission to configure the
Exchange mail flow.
- Click Grant Permission.
- On the Microsoft logon screen that appears, specify your Microsoft 365 Global Administrator credentials and click Sign in.
- On the Exchange Online authorization screen that appears, click
Accept to grant Cloud Email and Collaboration
Protection the permission.During this process, Cloud Email and Collaboration Protection creates the Trend Micro Cloud App Security app on Exchange Online.
- Assign the Microsoft Entra ID roles to the Trend Micro Cloud App
Security app created in Microsoft Entra ID.
- Go back to the Cloud Email and Collaboration Protection management console and copy the app ID shown in Step 2.
- Log on to the Microsoft Entra ID portal as an Exchange Online administrator.
- In the left-side area, click Microsoft Entra ID, and select Roles and administrators under Manage.
- In the list on the Roles and administrators screen, click Exchange administrator.
- On the Exchange administrator | Assignments screen, click +Add assignments.
- Assign the Exchange administrator role to the Trend Micro
Cloud App Security app.
-
If you have not enabled Privileged Identity Management:
-
In the search box on the Add assignments screen, paste the app ID copied earlier and press Enter.
-
Locate and select the app Trend Micro Cloud App Security, and then click Add.The app appears on the Exchange administrator | Assignments screen.
-
-
If you have enabled Privileged Identity Management:
-
On the Add assignments screen, click No member selected.
-
On the Select a member screen, paste the app ID copied earlier, and press Enter.
-
Locate and select the app Trend Micro Cloud App Security, and then click Select.
-
On the Setting tab, retain the default settings, provide a justification for assigning the role under Enter justification, and click Assign.The app appears on the Active assignments tab of the Exchange administrator | Assignments screen.
-
-
- Grant Cloud Email and Collaboration
Protection the permission to sync user and
domain data from Microsoft Entra ID and access all mailboxes.
- Go back to the Cloud Email and Collaboration Protection management console and click Click here after Step 3.
- On the Microsoft logon screen that appears, specify your Microsoft 365 Global Administrator credentials and click Sign in.
- On the Exchange Online authorization screen that appears, click Accept to grant Cloud Email and Collaboration Protection the permission to sync user and domain data from Microsoft Entra ID.
- Wait until the process is completed.If the message "Successfully created a service account and synced data." appears on the screen, the access grant is successful.
- To allow Cloud Email and Collaboration Protection to enhance protection for your Exchange Online service based on user behavior, click Grant Permission in the banner on the Dashboard screen, and follow the instructions to grant Cloud Email and Collaboration Protection the permission to read activity data for your organization.