This article applies to:
- MailMarshal Cloud (M365 Integrated Mode)
Question:
- What Connectors and Rules are automatically created in the M365 environment by MailMarshal Cloud Integrated Mode provisioning?
- What filtering settings are automatically created in Microsoft Defender by MailMarshal Cloud Integrated Mode provisioning?
Information:
MailMarshal Cloud creates configuration in M36 Mail Flow and in Microsoft Defender threat policies.
For the service to work correctly, all items must be present and enabled.
Mail Flow:
The following items are created in M365 Mail Flow. The items are created below any existing items.
When created, both connectors are enabled and both rules are disabled. Messages will not be passed to MailMarshal Cloud.
Connectors
- From: Your organization's Mail Server
- To Office 365
- How to identify email sent from your email server:
- Subject name on the certificate matches *.[region].mailmarshal.cloud
- Where [region] is the regional instance configured for the customer and is one of the following: (au eu us)
- From: Office 365
- To: Partner organization
- Use only when I have a transport rule set up that redirects messages to this connector
- Route email messages through these smart hosts:
- Set the value for the regional instance configured for the customer:
- AU: m365integrated-array-1.au.mailmarshal.cloud
- EU: m365integrated-array-1.eu.mailmarshal.cloud
- US: m365integrated-array-1.us.mailmarshal.cloud
- Set the value for the regional instance configured for the customer:
- Security restrictions:
- Always use TLS
- Server certificate issued by a trusted CA and the subject name is: *.[region].mailmarshal.cloud
- Where [region] is the regional instance configured for the customer and is one of the following: (au eu us)
Rules
- Apply this rule if the 'X-MMCloud-ID' message header includes (GUID value)
- The value in the header is unique for each customer. If you have deleted this rule, contact LevelBlue for assistance.
- Remove the header 'X-MMCloud-ID'
- Apply to all messages
- Route the message using the following connector: 'To MailMarshal Cloud Integrated'
Filtering Settings:
The following items are created in Microsoft Defender Email & Collaboration settings.
If required items appear to be missing, contact support for advice.
Trusted ARC sealers
In the Defender portal, review the setting in Email & collaboration > Policies & rules > Threat policies > Email Authentication Settings in the Rules section > ARC
- The list should include an entry for dkim.mailmarshal.cloud
Enhanced filtering for connectors
In the Defender portal, review the setting in Email & collaboration > Policies & rules > Threat policies > Rules section > Enhanced filtering.
- For the connector "From MailMarshalCloud Integrated", a list of IP addresses should be configured. This is a list of sources that will be trusted. The list depends on the regional instance. If you have any questions, contact support to verify the entries.
- Note that some IPv6 addresses are expected to be included. IPv6 addresses cannot be configured in these lists using the portal.
MailMarshal Cloud KB article Q21244
Last Modified: March 18, 2026