Provisioning an Exchange Online (Inline Mode) Authorized Account

Important:

This is a "Pre-release" feature and is not considered an official release. Please review the Pre-release Disclaimer before using the feature.

The steps outlined below detail how to provision an Exchange Online (Inline Mode) Authorized Account for inbound protection of Exchange Online in inline mode from Dashboard.

  1. Log on to the Cloud App Security management console.
  2. Hover over Exchange Online (Inline Mode) and click Provision.
    Note:

    You can also go to Administration > Global Settings > Inline Protection Settings for Exchange Online and click the Inbound Protection tab to perform the provisioning.

    The Provision Service Account for Exchange Online (Inline Mode) screen appears.

  3. Grant Cloud App Security the permission to configure the Exchange mail flow.
    1. Click Click here at the end of Step 1.
    2. On the Microsoft logon screen that appears, specify your Office 365 Global Administrator credentials and click Sign in.
    3. On the Exchange Online authorization screen that appears, click Accept to grant Cloud App Security the permission.

      During this process, Cloud App Security creates the Trend Micro Cloud App Security app on Exchange Online.

  4. Assign the Exchange administrator role to the application created in Azure AD.
    1. Go back to the Cloud App Security management console and copy the App Id in step 2.
    2. Log on to the Azure Active Directory portal as an Exchange Online administrator.
    3. In the left-side area, click Azure Active Directory, and select Roles and administrators under Manage.
    4. In the list on the Roles and administrators screen, click Exchange administrator.
    5. On the Exchange administrator screen that appears, click +Add assignments.

      The Add assignments screen appears.

    6. In the search box, paste the App Id copied in step 4.a above and press Enter.
    7. Locate and select the app Trend Micro Cloud App Security, and then click Add.
  5. Grant Cloud App Security the permission to sync user and domain data from Azure AD.
    1. Go back to the Cloud App Security management console and click Click here after step 3.
    2. On the Microsoft logon screen that appears, specify your Office 365 Global Administrator credentials and click Sign in.
    3. On the Exchange Online authorization screen that appears, click Accept to grant Cloud App Security the permission to sync user and domain data from Azure AD.
  6. Return to the Cloud App Security management console and click Verify and Submit under step 4.
  7. Wait until the process is completed.
  8. Hover over the ring icon in the upper-right corner of the management console.

    If the message "Exchange Online protected in inline mode." appears on the Notifications screen, the provisioning is successful.

    The provisioning automatically creates the following transport rules, connectors, and Microsoft 365 group on Exchange Online to implement mail flow, For details, see Connectors, Transport Rules, and Group for Inbound Protection.