Skip to main content

EncryptTitan V2

Configuring M365 for EncryptTitan

To use EncryptTitan email encryption services with M365, you must configure M365 to send outbound email through the EncryptTitan encryption gateway. Once configured, EncryptTitan will inspect each message to determine whether to encrypt the message based on your organizational encryption triggers.

Each of the main steps to configure EncryptTitan for M365 are listed below, followed by more specific substeps.

  1. Add an EncryptTitan Connector.

    1. Log in to Microsoft Online, and enter your administrator email address and password.

      Note

      If you are not an administrator, you will be redirected to the user hub. Contact your O365 Administrator if you need administrator access.

    2. Select Sign in.

    3. In the left area of the O365 console, select Admin to go to the O365 Admin Center.

    4. Select Exchange > Mail Flow > Connectors.

      ET-Configure-O365_7.jpg
    5. In the Connectors section, select the + sign to add a new connector. The Mail Flow Scenario dialog box opens.

    6. In Connection From, select Office 365 and in Connection to, select Partner organization. Select Next.

      ET-Configure-O365_8.jpg
    7. In the Name field, enter a descriptive name for the outbound connector; for example, EncryptTitan.

    8. In the Description field, enter additional information about the outbound connector. To enable the connector immediately upon completion, select Turn it on. Select Next.

    9. In the Use of Connector dialog box, select the option Only when I have a transport rule set up that redirects messages to this connector. Select Next.

      ET-Configure-O365_9.jpg
    10. On the Route email messages page, select Route email through these smart hosts.

      ET-Configure-O365_10.jpg
    11. Go to your EncryptTitan admin portal to get your SmartHost:

      1. Select Configurations > Domain Setup and select the checkbox for your domain.

      2. Select Outbound servers.

      3. In the pop-up window, select Microsoft 365 from the dropdown menu and take note of the Smart Host where O365 will deliver emails (securemail.encrypttitan.io).

        ET-New-Outbound-Servers.jpg
      4. Enter your Smart Host in the text field and click the + sign to add the Smart Host.

      5. Select Next.

    12. Ensure that Always use Transport Layer Security (TLS) and Issued by a trusted certificate authority (CA) are selected. Select Next.

      ET-Configure-O365_11.jpg
    13. Verify the connector by entering a test email address. This can be any email outside the domain you are setting up. Select the + sign, and then select Validate.

      ET-Configure-O365_12.jpg
    14. The validation step will attempt a connection from Office 365 to the EncryptTitan Gateway and email the designated email address. Both validation results should be successful.  Select Next.

    15. Select Create connector.

  2. Add an EncryptTitan Token Header.

    1. Go to Mail Flow and select Rules.

    2. Select the plus + sign beside Add a rule, and select Create a new rule from the dropdown menu.

      ET-Configure-O365_13.jpg
    3. Enter a name for the rule you are creating, and from the Apply this rule if dropdown menu, select Apply to all messages.

      ET-Configure-O365_14.jpg
    4. From the Do the following dropdown menu, select Modify the message properties and in the dropdown menu beside it, select set a message header.

      ET-Configure-O365_15.jpg
    5. Select the Enter text... link beside message header, and enter X-ETVALTOK. Select Save.

      ET-Configure-O365_16.jpg
    6. Select the Enter text... link beside value, and retrieve the value for your account in the EncryptTitan portal. Go to Configurations > Domain setup and select the domain you are setting up. Select Outbound servers and in the window that appears, copy the custom x-header value by clicking the copy ET-Copy-Icon.jpg icon. Paste this value, which is typically 20 characters, into the message header text field and select Save.

      ET-Configure-O365_17.jpg
    7. Select Next.  If Next is greyed out, review your selections rule conditions to ensure they are correct.

    8. Under Rule mode, leave the default Enforce selected. Other available options would typically be left unchanged from the default settings.

    9. Select Next to review the rule.  Then select Finish > Done.

  3. Add EncryptTitan Keyword Trigger.

    1. Go to Mail Flow and select Rules.

    2. Select the plus + sign beside Add a rule and select Create a new rule from the dropdown menu. Enter a name for the rule.

      ET-Configure-O365_1.jpg
    3. Select The subject or body and then select subject includes any of these words. Enter the keywords that you configured in the EncryptTitan Access Management Portal (https://access.encrypttitan.io) and select Save.

      ET-Configure-O365_2.jpg

      Note

      Note: keywords are case-insensitive.

    4. Add another action by pressing the + sign in the rule you just created.  This will create a new And conditional dropdown selection.

    5. In the newly created dropdown menu, select The recipient. Next, select is external/internal, then Outside the organization and Save.

      ET-Configure-O365_3.jpg
    6. Go to the Do the following section, and from the Do the following dropdown menu, select Redirect the message to and then select the following connector. This is the connector you set up in Step 1.

      ET-Configure-O365_4.jpg
    7. Select the Select one link and choose the connector that you just created for EncryptTitan. Select Save.

    8. Select Next.  If Next is greyed out, review your selections rule conditions to ensure they are correct.

    9. Under Rule mode, leave the default Enforce selected.

    10. Select the Stop processing more rules checkbox. Other available options are typically left unchanged from the default settings.

      ET-Configure-O365_5.jpg
    11. Select Next to review the rule.  When you're finished, select Finish > Done.

      Note

      Note that mail rules are disabled when created.

    12. Click on each new EncryptTitan rule that you created and select enabled or disabled rule to enable the rule.

      ET-Configure-O365_6.jpg

      Note

      The token header rule you created in Step 2 should be a higher priority than the keyword rule. Ensure that the token header rule has a higher priority in your list of rules.

You have now completed the configuration for the EncryptTitan service for the O365 platform. Note that changes normally take effect within five minutes.