Skip to content

Configure M365 journaling automatically

This feature might not be available for all customers yet.

Sophos can automatically configure journaling for Microsoft 365, so you don't need to manually create journal rules or configure NDR mailbox settings in Microsoft Purview.

Note

Automatic configuration applies only to Microsoft 365. If you select Google as your journal source, you must configure journaling manually. See Configure Google journaling manually.

Before you start

Make sure you have the following requirements:

  • A Microsoft 365 Global Administrator account.

    If you aren't a Global Administrator, your account must have permission to grant admin consent for applications and create Exchange Online journal rules.

  • A supported Microsoft 365 Exchange Online plan.

    Supported plans are Business Basic, Business Standard, Business Premium, E1, E3, and E5.

    Note

    Exchange Online Kiosk plans don't support journal rules. If your domain uses this plan, automatic configuration fails. Upgrade your plan.

  • A domain added to Sophos EMS with Microsoft 365 selected as the journal source.

    For information on adding a domain, see Add a domain.

Configure journaling

Automatic configuration verifies domain ownership through Microsoft 365 authentication, then configures the required journal rule and non-delivery report (NDR) mailbox setting on your behalf.

Note

If journal rules are already configured for a domain, adding subsequent domains from the same Microsoft 365 tenant will leverage the existing journaling configuration.

To configure journaling, do as follows:

  1. In the domain dialog, click Setup M365 Journal.

    A confirmation dialog explains that you'll be redirected to Microsoft 365 to verify domain ownership, and that Sophos needs permission to do the following actions:

    • Create an application in Microsoft 365.
    • Create journal rules in Microsoft 365.
  2. Click Proceed.

  3. Sign in to Microsoft 365 using an account that has the required permissions, and grant the requested permissions.

    Sophos uses these permissions to verify domain ownership and configure the required Microsoft 365 journaling settings on your behalf.

Automatic configuration can take a few minutes to complete. You can keep the progress dialog open or close it and return to the domains page later to check the status.

Automatic configuration does the following actions in Microsoft 365:

  • Creates the Sophos Email Monitoring application if it doesn't already exist for your Microsoft 365 tenant.
  • Creates a journal rule in Microsoft 365 that sends a copy of your inbound and outbound email to Sophos EMS for scanning.
  • Sets the non-delivery report (NDR) mailbox for the journal rule, but only if one isn't already configured. Sophos never overwrites an existing NDR mailbox setting.

Next steps

After journaling is configured successfully, you can do one of the following actions:

  • Click Review Policies to configure monitoring policies for the domain.
  • Click Run a Quick Test to send a test email and confirm that journaling is working.

Troubleshooting

If automatic configuration fails and you see an error message, Microsoft 365 might be blocking Sophos from creating the application credentials it needs. This can happen if an Application Management Policy restricts credential types.

Ask your Microsoft 365 administrator to review any Conditional Access and Application Management Policies that might block credential creation for new applications.

If domain ownership verification fails, make sure you signed in to Microsoft 365 using an account that has the required permissions. Also make sure the domain is associated with your Microsoft 365 tenant.

Delete a domain

When you delete a domain that was configured automatically, Sophos removes the link between the journal rules and the deleted domain. If the deleted domain is the last domain for the Microsoft 365 tenant, Sophos removes the journal rules and the Microsoft 365 application it created.

Microsoft 365 doesn't allow Sophos to reset the Journal NDR fallback mailbox. If you need to change the NDR mailbox address, you must do so manually in Microsoft Purview.

For steps, see Delete a domain.