Curtis Parker | December 2010 | Microsoft Corporation
FOPE and Office 365 Scenarios − FOPE Connectors Overview Q/A 2 |
Connection Analysis (IP-based edge blocks) Reputation Analysis Edge Protect businesses from receiving –borne viruses and other malicious code with scan engines and heuristic detection Anti-Virus Anti-spam filter can detect all types of spam before they reach the corporate network Anti-Spam Policy rules to regulate flow for compliance Policy Core Product Capabilities
Every Exchange Online (BPOS)/Office 365 customer is a FOPE customer!!! Office 365 Protect on-premises servers Standalone Protect on-premises Exchange servers and integrates FPE/FOPE policies (On-prem/Cloud Policies) Hybrid Protection Live EDU (Next CY) Others Implementation Scenarios
Connectors Overview - Inbound and Outbound Connector routing options
Building blocks to give granular control over all stages of mail flow: Enhanced Secure Messaging B2B Secure Channel Forced Inbound TLS Enhanced Outbound TLS Clear separation of Edge Rules vs. Content based policy Enable Hybrid deployments on-premises and hosted mailbox co-exists on-premises compliance solution continued to serve hosted mailbox
FOPE Connector is solution to enable complex mail flow paths and provide granular control over every stage of mail flow − Inbound Connector: For mail coming in to the customer − Outbound Connector: For mail sent by customer
Inbound Connector − Inbound Connectors are created to control coming into customer domains Outbound Connector − Outbound connectors are created to control mail flow for e- mail sent from customer domains Source IP
Fully hosted Shared address space with hosted and on-premises (Virtual Domains)Shared address space with on-premises address rewriteRegulated partner with forced TLSOutbound Smart HostInbound safe listing
Fully Hosted − Contoso Ltd is all in to the cloud. They elect to host all of their mailboxes in the cloud and retire their on premise mail servers entirely. − Bill is a salesman at Contoso. 13
Exchange online sends to FOPE FOPE filters as outbound FOPE delivers to internet FOPE Contoso signed up for EXO EXO has provisioned tenant in FOPE Mail sent to FOPE FOPE filters inbound mail FOPE delivers to EXO mailbox Value Proposition All Office 365 Mailboxes Inbound mailflow protected Outbound mailflow protected INTERNET EXCHANGE ONLINE Inbound From: To: Inbound From: To: Outbound From: To: Outbound From: To:
Exchange online delivers directly to user mailbox Value Proposition Same mail protection for all mail outside the organization FPE virus scan for intra-org mail INTERNET EXCHANGE ONLINE Intra Org From: To: Intra Org From: To: FOPE Inter Org From: To: Inter Org From: To: Exchange online sends to FOPE which filters as outbound Sends via MX back to FOPE then filters as inbound and delivers.
Fully hostedShared address space with hosted and on-premises (Virtual Domains)Shared address space with on-premises address rewriteRegulated partner with forced TLSOutbound Smart HostInbound safe listing
FOPE on-premises INTERNET EXCHANGE ONLINE MX points to FOPE for initial filtering Cloud mail is re-directed (virtual domains) Routed to on-premises Delivered to Exchange Online cloud Value proposition Gradual migration to the cloud Maintain control over mailflow Leverage existing investment Inbound From: To: Inbound From: To:
FOPE on-premises INTERNET EXCHANGE ONLINE Outbound From: To: Outbound From: To: Value Proposition Outbound mail protected Company maintains control Hosted mailbox and on- premises send mail outbound Filtered by FOPE Delivered to Internet
FOPE on-premises INTERNET EXCHANGE ONLINE MX points to on premise for initial filtering. Custom filtering, archival etc. done on-site. Cloud mail is re-directed (address rewrite) Filtered by FOPE Delivered to Exchange Online cloud. Value proposition Gradual migration to the cloud Maintain control over mailflow Leverage existing investment Inbound From: To: Inbound From: To:
FOPE on-premises INTERNET EXCHANGE ONLINE Hosted mailbox sends mail outbound Filtered by FOPE Delivered to on-premises Custom processing on- premises Delivery by on-premises Value Proposition Outbound mail protected Company maintains control Outbound From: To: Outbound From: To:
On-premises mailbox sends mail outbound. Custom processing on-premises Delivery to FOPE (address rewrite) Filtered skipped Delivery to EXO by FOPE Value Proposition Secure and seamless cloud and on- premises intra-org mailflow FOPE on-premises INTERNET EXCHANGE ONLINE Intra Org From: To: Intra Org From: To:
Business Regulated Partner − Now, Contoso has decided to have Woodgrove Bank handling some B2B financial requirements. − Woodgrove Bank mandates that all business partners communicate over TLS with Woodgrove Bank and sign using a third party verified certificate. − Contoso wants to ensure they are compliant with Woodgrove Bank standards.
Business Regulated Partner Business/Regulated Partner − Secure and trusted channel communication with partners Value proposition Easily configure routing to ensure that the communication channel is secured for all mail EXCHANGE ONLINE On-Premises CROSS PREMISE FOPE
Outbound mail Filtered by FOPE Delivery to Smarthost for custom mail process or delivery Value Proposition Outbound mail protected Customer maintains control FOPE on-premises INTERNET Inter Org From: To: Inter Org From: To:
Inbound mail Filtered by FOPE Spam filtering skipped for trusted domains Value Proposition Bypass Spam filtering Customer maintains control FOPE on-premises INTERNET Inbound Safelisting From: To: Inbound Safelisting From: To: EXCHANGE ONLINE
© 2010 Microsoft Corporation.