Microsoft Exchange Online integration

  • Release version: Xanadu
  • Updated August 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Microsoft Exchange Online integration

    The Microsoft Exchange Online integration connects the ServiceNow AI Platform® Security Incident Response (SIR) product with Microsoft Exchange Online, part of Microsoft Office 365. This integration enables Security Operations Center (SOC) analysts to search corporate email environments for phishing threats and remediate them by deleting suspicious emails directly from Exchange Online. Analysts can initiate searches based on email subject lines, sender, and recipient addresses, and optionally configure approval processes to control email deletion. The integration supports incorporating email search and deletion into broader phishing response workflows, helping identify and mitigate phishing campaigns by locating related emails and potential victims.

    Show full answer Show less

    Key Features

    • Customizable search criteria based on sender, recipient, and subject within Security Incident Response.
    • Email notifications to analysts upon completion of large or lengthy searches, including the number of matched messages.
    • Status indicators showing if recipients have read or deleted suspicious emails.
    • Optional approval workflows to ensure emails are not deleted without proper authorization.
    • Audit trails logged in security incident work notes documenting delete requests and counts.
    • Security tags that track the initiation and completion status of search and delete workflows for quick identification.

    Supported Environments and Prerequisites

    The integration supports Microsoft Exchange Online services (Exchange 2016 version) within Microsoft Office 365 but does not support hosted Exchange environments. To implement, the com.snc.sidep plugin must be installed first, followed by required Security Operations applications in the correct order to ensure smooth installation. Additionally, a Microsoft Azure account connected to your Exchange Online tenant is necessary for email access.

    Implementation Steps

    • Install the Microsoft Exchange Online application from the ServiceNow Store.
    • Configure the application to connect with your ServiceNow AI Platform instance, activating search and delete workflows.
    • As an analyst with the snsi.analyst role, define email search criteria on security incident records and submit requests to find suspicious emails.
    • Optionally request approval for deleting identified suspicious emails to enforce organizational controls.
    • Microsoft Exchange administrators can recover deleted emails if needed during incident remediation.
    • Customize security tags in your instance to visually track the status of email search and deletion activities.

    Benefits for ServiceNow Customers

    This integration empowers SOC analysts to efficiently investigate and remediate phishing threats within corporate email environments, improving incident response times and reducing risk exposure. The optional approval and audit features enhance governance and compliance by controlling and documenting email deletions. Integration with existing ServiceNow Security Incident Response workflows simplifies managing phishing campaigns and protecting users from malicious emails.

    For the Microsoft Exchange Online integration application by ServiceNow, the ServiceNow AI Platform® Security Incident Response (SIR) product is integrated with the Microsoft Exchange Online service, one of the cloud-based services in the Microsoft Office 365 suite of products. Your Security Operation Center (SOC) analyst can search your corporate email environment for security-related threats and remove and remediate phishing emails with email search and delete capabilities.

    Overview of Microsoft Exchange Online integration

    As the security incident analyst, you execute the integration from the security analyst interface, and the workflow returns email message details that match search criteria. Email searches are based on criteria that include subject lines as well as sender and recipient email addresses. After the email search is complete, you can delete suspicious emails from the Microsoft Exchange Online service, and, an optional approval process can be configured to request approval prior to deleting emails.

    This email search and delete integration can be used with a broader phishing response incident workflow or runbook. After a corporate user or employee receives a suspicious email and reports it to the company's phishing response team or inbox, the reported email is forwarded to the ServiceNow AI Platform and categorized as a security incident. After you have verified that an email is a phishing attack, as the analyst responsible for investigating phishing incidents, you can initiate an email search to determine if other corporate users have received this phishing email. The search allows you to locate related emails from the same phishing campaign and identify other potential victims who may have received the email, read it, and also potentially clicked a malicious URL or opened an attachment.

    Key features

    The integration includes the following key features:

    • Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
    • For large and lengthy email searches, the security incident analyst is notified via email when the search has successfully completed, along with the number of matched messages.
    • Status for individual messages informs you if recipients have read or deleted suspicious emails.
    • If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
    • A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents.
    • If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents.

    Supported Microsoft Exchange Online versions

    This integration supports Microsoft Exchange Online services, which are part of the Microsoft Office 365 suite. The integration does not support hosted Microsoft Exchange environments. Microsoft runs Microsoft Exchange Online services on the Exchange 2016 version.

    Prerequisites

    The com.snc.si_dep plugin is required for any ServiceNow AI Platform version. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before installing and activating the other Security Operations applications.

    The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed below to ensure a smooth installation:
    1. Security Integration Framework
    2. Security Support Common
    3. Security Support Orchestration
    4. Security Incident Response