Configuring Remote Journaling via Microsoft 365
Microsoft 365 provides a remote journaling functionality to send a copy of all mail sent or received by members of a defined security group to a remote SMTP address. Spambrella provides you with the SMTP address to use for this configuration.
Solution
- Setup on Email Archive Service
- Configuring an Outbound Connector on Microsoft 365
- Configuring a Journal Rule on Microsoft 365
- Confirm Data is being Archived successfully
Archive Configuration
- From the Admin User Interface, click Archive.
- Select Archive.
- Expand Data Management and then Connections.

- Click Add Connection to create a new connection.
![]()
- Provide an appropriate description for the connection and set the Connection Type to SMTP (Microsoft 365).

- Enter the appropriate email address in the ‘Undeliverable Journal Address’ field. This has to be a valid email address that exists on your account and in Microsoft 365.
- Note: This email address will be used in a later stage of configuring a Journal Rule on Microsoft 365. If these do not match, Remote Journaling will not function. This email address will not be journaled and is only used for error reporting.
- Click Next.
- Note the SMTP Address provided, as it is required for the Microsoft 365 configuration. This can be viewed again later by editing the connection.

- Click Done
Configuring an outbound connector on Microsoft 365
- Open the Microsoft 365 Admin Center.
- Click the Admin Centers icon on the left-hand sidebar and choose Exchange.

- In the Exchange Dashboard, under the mail flow heading, click connectors.

- Click the + sign to add a new connector.
- Select Microsoft 365 for the From dropdown menu and Partner Organization for the To menu.
- Click Next.
- Enter a descriptive Name (and optionally, Description) for the connector.
- Tick the checkbox Turn it on to turn on the connector when it is saved. You can also edit the connector and check the box at any time.
- Click Next.
- Select Only when email messages are sent to these domains, then click + and enter the fully qualified domain name of the mail server: *.earchive.cloud will work.
- Click OK to return to the connectors screen.
- Click Next.
- Select Use the MX record associated with the partner’s domain.
- Click Next.
Leave the default settings for the How should Microsoft 365 connect to your partner organization’s email server? step and click Next.
The next screen will ask that you confirm your settings. Review these settings, clicking back should you need to make any corrections. Otherwise, click Next.

In the Validate this Connector step, click + and enter the following address: verification@us.earchive.cloud
Note: The above address should be used. However, this will often fail verification, but has no impact on the success of the connector going forward if this step fails. You can continue with the setup and testing.
When prompted to validate the connection, click Validate and wait for the validation operation to finish.
Click Save.
Configuring a Journal Rule on Microsoft 365
This step assumes you are enabling journaling for all users.
- From the Admin Centers (now called Microsoft Purview) dashboard, click Compliance. Then go to the Data Lifecycle Management dropdown and select Exchange (Legacy).
Note: This must match the address set in Step 5 of Proofpoint Essentials Archive Configuration above.
- In the Journal Rules tab, Click the + sign to create a new Journal Rule.
- In the Send journal reports to field, enter the SMTP address of the journaling mailbox (e.g. 5er123acd-5432-123aa0a1-d9348328b71@us.earchive.cloud)
This was provided in Step 7 of Archive Configuration.
- Enter a descriptive Name for the rule (e.g. Journaling to Archive).
- From the Journal messages sent or received from, choose Everyone.
- From the Type of message to journal, choose All messages.
- Click Save.
- When prompted to confirm that you want the rule to apply to all messages, click Yes.

- Go to Settings on the left hand menu, Select Data Lifecycle Management, select Exchange (legacy) review your Undeliverable reports where it says ‘ADD or Replace’, make sure the same address is entered in Archive Configuration step Six. This account will receive notification of non-deliverable journal reports.

Confirm Data is being archived successfully
To confirm that data is now being archived successfully, please make sure to log in and search the Archive with a user that has Discovery User access to all Mailboxes.
Set Discovery User Access for User
- Log in to the Spambrella/Proofpoint Admin Console as an Organization Admin.
- Click the Archive tab.
- In the Archive UI, click on the Users icon.
- Search for the desired user and click on the Action > manage permissions

Further resources:
