Skip to main content
M365 sends a copy of every incoming and outgoing email to xorlab.
Prerequisites
  • Using BCC monitoring sends an additional copy of each email to xorlab, which can lead to hitting the external recipients rate limit (tenant ERRL) of Microsoft Exchange.
  • You can monitor how close you are to the limit under: Reports → Mail flow → Outbound external recipients

Choose how to configure it

Both paths create the same connector and the same two mail flow rules. Pick one.

Quick integration with PowerShell

Run one script that asks for your values. Mail flow rules need to be activated manually.

Manual integration in the Exchange Admin Center

The same configuration manually in the web interface. Use it if you prefer to see each setting before you apply it.

Quick integration with PowerShell

One script creates the connector and both mail flow rules. It asks for your values, shows a summary and changes nothing until you confirm. You need the Exchange Administrator role and the ExchangeOnlineManagement module. Run it either in a PowerShell window on your own machine or in the Azure Cloud Shell.
Run these once, in a PowerShell window on your own machine. Everything installs for your user account only, so you do not need local administrator rights:
  1. Download the script with the command on Script Downloads, which requires you to log in. Run that command in your PowerShell window, then come back here and start the script. If you are not signed in to Exchange Online yet, a sign-in window opens first:
    If the connector or one of the rules already exists in your tenant, the script stops without changing anything.
  2. Answer the prompts:
  3. Check the summary and confirm with y. The script then:
    • creates the Microsoft365Toxorlab connector
    • validates it with a test email to the monitoring address and summarizes the result
    • creates the IncomingBCCxorlab and OutgoingBCCxorlab mail flow rules, disabled
    In the validation summary, both the connectivity check and the test email should succeed. If one fails, the script continues anyway; validate the connector again later in the Exchange Admin Center. It shows as not validated there until you do, because Validate-OutboundConnector does not record its result on the connector.
  4. Enable both rules:
    From then on, M365 sends a copy of every incoming and outgoing email to xorlab. It can take several minutes until the rules are active.
To remove the connector and mail flow rules again, run ./xorlabExoSetup.ps1 -Mode Monitoring -Remove.

Test with one mailbox first

With the test scope, each rule gets one extra condition on top of its organization-wide ones: IncomingBCCxorlab matches only email to the test mailbox, and OutgoingBCCxorlab only email from it. No copies are sent for any other email. When you are done testing, remove that condition and the same rules apply to the whole organization. Either delete it in the Exchange Admin Center under Mail flow → Rules — The recipient → is this person on the incoming rule, The sender → is this person on the outgoing one — or run:

Manual integration in the Exchange Admin Center

Create mail flow rule

  1. Go to Exchange Admin Center → Mail flow → Rules and create a new rule: Creating a new rule
  2. Configure the rule like this:
    • Name: IncomingBCCxorlab
    • Apply this rule if → The sender → is external/internal → Outside the organization
    • Click the plus icon (+) to add another condition
    • And → The recipient → is external/internal → Inside the organization
    • Do the following → Add Recipients → to the Bcc box → enter monitor@mx.xyz.activeguard.cloud, where xyz is your customer ID
    • Click the plus icon (+) to add another action
    • And → Modify the message properties → set a message header → set x-xor-tenant-token to your header value
    Rule settings for incoming emails
  3. Click through Next → Finish and leave all settings at their defaults.
  4. Repeat steps #2-3 to add another rule but this time set:
    • Name: OutgoingBCCxorlab
    • The sender → Inside the organization
    • The recipient → Outside the organization
    Rule settings for outgoing emails
  5. Enable both rules in the Rules page.
Now, a copy of every incoming and outgoing email will be sent to xorlab.

Create a connector

In addition to the mail flow rule above, we need to create a connector to make sure the emails are sent directly to xorlab.
We recommend to always create a connector to ensure proper email delivery. However, you can omit the connector if the following two conditions are met:
  • You do not have any other connectors that might interfere with the BCC emails sent to xorlab.
  • You do not have a hybrid MS setup with an on-prem-only email delivery (Centralized Mail Transport).
  1. Go to Exchange Admin Center → Connectors → add a connector: Add a connector
  2. Connection from → Office 365, and Connection to → Your organization’s email server: New connector from O365
  3. Set the name to Microsoft365Toxorlab and enable Retain internal Exchange email headers: Connector name from M365
  4. Choose the third option and enter mx.xyz.activeguard.cloud, where xyz is your customer ID. Click the plus (+) icon: Use of connector
  5. Add a new smart host with the value mx.xyz.activeguard.cloud, where xyz is your customer ID: Routing
  6. Activate Always use Transport Layer Security… and select Issued by a trusted certificate authority (CA): Security restrictions Security restrictions
  7. Enter a company mailbox where a validation email should be sent to: Validation email
    Unsuccessful validationThe connector validation might fail at this point. If this happens, save the connector without validation, and then validate the connector again.
  8. Review the connector and click Create when it’s OK.

Optional: Include internal emails

Per default, xorlab only processes incoming and outgoing emails. However, if you want to include also internal emails, do the following:
  • Remove one of the two mail flow rules from above
  • Rename the existing one to BCCxorlab
  • Change Apply this rule if to Apply to all messages and remove the And condition
Configuring the monitor rule Now, a copy of every email will be sent to xorlab.

Next steps

Optionally continue with: Once the integration is complete, continue with What to Configure Next.