Skip to main content

LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

LevelBlue + SentinelOne: Global Partnership to Deliver AI-Powered Managed Security Operations and Incident Response. Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
PGA of America Partnership
Secure What's Next
LevelBlue Security Operations Platforms
Security Colony
Partners
SentinelOne
Advancing integrated, intelligence‑driven security operations
Microsoft
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Partner Portal
 

This article applies to:

  • MailMarshal Cloud (M365 Integrated Mode)

Question:

  • What Connectors and Rules are automatically created in the M365 environment by MailMarshal Cloud Integrated Mode provisioning?
  • What filtering settings are automatically created in Microsoft Defender by MailMarshal Cloud Integrated Mode provisioning?

Information:

MailMarshal Cloud creates configuration in M36 Mail Flow and in Microsoft Defender threat policies.

For the service to work correctly, all items must be present and enabled.

Mail Flow:

The following items are created in M365 Mail Flow. The items are created below any existing items.

When created, both connectors are enabled and both rules are disabled. Messages will not be passed to MailMarshal Cloud.

Connectors

From MailMarshal Cloud Integrated
This connector instructs Exchange to accept all messages from the MailMarshal Cloud instance.
  • From: Your organization's Mail Server
  • To Office 365
  • How to identify email sent from your email server:
    • Subject name on the certificate matches *.[region].mailmarshal.cloud
      • Where [region] is the regional instance configured for the customer and is one of the following: (au eu us)
To MailMarshal Cloud Integrated
This connector allows messages to be routed to the MailMarshal Cloud instance by the Transport Rule.
  • From: Office 365
  • To: Partner organization
  • Use only when I have a transport rule set up that redirects messages to this connector
  • Route email messages through these smart hosts:
    • Set the value for the regional instance configured for the customer:
      • AU: m365integrated-array-1.au.mailmarshal.cloud
      • EU: m365integrated-array-1.eu.mailmarshal.cloud
      • US: m365integrated-array-1.us.mailmarshal.cloud
  • Security restrictions:
    • Always use TLS
    • Server certificate issued by a trusted CA and the subject name is: *.[region].mailmarshal.cloud
      • Where [region] is the regional instance configured for the customer and is one of the following: (au eu us)

Rules

MailMarshal Cloud Integrated Loop Check
This rule helps to prevent re-delivery of incorrectly routed messages.
  • Apply this rule if the  'X-MMCloud-ID'  message header includes  (GUID value)
    • The value in the header is unique for each customer. If you have deleted this rule, contact LevelBlue for assistance.
  • Remove the header 'X-MMCloud-ID' 
MailMarshal Cloud Integrated Redirect
This rule routes messages to MailMarshal Cloud for scanning.
  • Apply to all messages
  • Route the message using the following connector: 'To MailMarshal Cloud Integrated' 

Filtering Settings:

The following items are created in Microsoft Defender Email & Collaboration settings. 

If required items appear to be missing, contact support for advice.

Trusted ARC sealers

In the Defender portal, review the setting in Email & collaboration > Policies & rules > Threat policies > Email Authentication Settings in the Rules section > ARC

  • The list should include an entry for dkim.mailmarshal.cloud

Enhanced filtering for connectors

In the Defender portal, review the setting in Email & collaboration > Policies & rules > Threat policies > Rules section > Enhanced filtering.

  • For the connector "From MailMarshalCloud Integrated", a list of IP addresses should be configured. This is a list of sources that will be trusted. The list depends on the regional instance. If you have any questions, contact support to verify the entries.
  • Note that some IPv6 addresses are expected to be included. IPv6 addresses cannot be configured in these lists using the portal.


MailMarshal Cloud KB article Q21244

Last Modified: March 18, 2026

 Turn On Turn Off Highlight