This may take up to 24 hours to fully propogate the Microsoft environment, please plan accordingly. 


The following steps begin with logging into https://admin.exchange.microsoft.com with credentials authorized to make enterprise-wide email configuration changes.


  • DKIM / DMARC Validation



Create Basic Connector


In the Exchange admin center (https://admin.exchange.microsoft.com/#/connectors), navigate to Mail Flow -> Connectors, and click on “Add a connector”



Configured your connector as a “Partner Organization”:


Name the connector “PhishProtection Inbound”, and optionally add notes:



When prompted, enter ALL of the IPs from ( https://support.duocircle.com/support/solutions/articles/5000524218-ip-addresses-for-firewalls)






Accept the remaining defaults to complete adding the connector:



Upgrade to Enhanced Connector


Once the connector is saved, visit https://security.microsoft.com/skiplisting, to upgrade the connector to an Enhanced Connector. 


Click on the connector, and under “IP addresses to skip”, enter all of the IPs found at https://support.duocircle.com/support/solutions/articles/5000524218-ip-addresses-for-firewalls


Notes






More information about connectors


https://www.undocumented-features.com/2019/08/13/exchange-online-protection-eop-best-practices-and-recommendations/#Enhanced_IP_Filtering_for_Connectors


https://docs.microsoft.com/en-us/Exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/enhanced-filtering-for-connectors


https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/manage-mail-flow-using-third-party-cloud