Where it runs
Hosted by xorlab, or on your own virtual infrastructure. Same detection either way.
What the integration involves
Three steps. Inline or monitoring is the one decision that shapes the rest.
What changes in your environment
Connectors and mail flow rules. No MX change, nothing installed, no mailbox moved.
What you maintain afterward
Upgrades, certificates, backups and monitoring, split by SaaS and on-premises.
Where it runs
Two deployment options, with the same detection either way.- xorlab SaaS — hosted and operated by xorlab. There is nothing to provision, and the platform itself is kept up to date for you.
- On-premises — you run the xorlab Control Center (XCC) and one or more xorlab MTAs on your own virtual infrastructure, so processing and storage stay with you. Install and configure the VMs first, following the VM Setup Guide; the Sizing Guide says what to provision and the Network Guide says which connections to open. Only start the integration once the VMs are running.
What the integration involves
Three steps, in this order.
Inline or monitoring is the decision that shapes the rest. In monitoring mode xorlab receives a copy of every email and drops it after the analysis, so your mail flow is untouched and nothing can be blocked. In inline mode email passes through xorlab and is forwarded on, which is what active protection requires. You can go inline in Toothless Mode first, where every email is still delivered and you review what would have been quarantined. See Switch Between Inline and Monitoring Mode.
Most admin changes are made in the Expert Editor, the configuration editor built into XCC. It is worth getting familiar with it early.
What changes in your environment
The integration is made of settings in your own admin portal:- Microsoft 365 — two connectors with TLS enforced, two mail flow rules, and one enterprise application in Entra ID. Microsoft Graph permissions, a reporting mailbox and moving the Microsoft quarantine into xorlab are separate, optional steps.
- On-premises — the scope of your receive connector and a send connector on Exchange, or BCC rules for monitoring mode; firewall rules for SMTP between your mail servers and the xorlab MTAs; and your own mail servers registered inside xorlab as trusted infrastructure, which is a setting in xorlab rather than in your environment (Add Your Trusted Infrastructure).
Undoing it is the same size as doing it. Disabling the two mail flow rules puts email back on its previous path within minutes, with no DNS change and no cutover window.
Review What Changes in Your Environment
The full table for each path: which setting goes where, whether it is mandatory, what your users notice, and how to roll it back.
What your users notice
- In monitoring mode, nothing at all. No email is modified, delayed or blocked.
- In inline mode, with the delivered defaults, email with a malicious verdict is quarantined instead of delivered, and some verdicts are delivered with a subject prefix such as
[SPAM]. Both are adjustable in Review Default Actions. - Only if you enable them, users get the Self-Service Quarantine and the notifications that go with it, or Contextual Banners inside the message body. Both are off until you turn them on.
What you maintain afterward
How much of the platform you operate depends on where it runs. The security configuration — guarded domains, detection tuning, lists, users and roles — stays with you in both cases.
Releases are rolled out to SaaS customers first and monitored before they are announced for on-premises upgrades, so an on-premises upgrade is applied to a release that has already been running elsewhere.
Where to start
Integration Overview
The complete integration in three steps, with the Microsoft 365 and on-premises paths side by side.
Review What Changes in Your Environment
The questions your mail, network and security teams ask before the project starts, answered per path.
Evaluate xorlab
How a trial runs on live traffic without blocking anything, and how long each phase takes.
What xorlab Connects To
Whether the rest of your stack is covered: SIEM, SOAR, identity, Microsoft Graph, threat intelligence.