Home

Can ATP re-write URLs in a hybrid scenario?

%3CLINGO-SUB%20id%3D%22lingo-sub-47062%22%20slang%3D%22en-US%22%3ECan%20ATP%20re-write%20URLs%20in%20a%20hybrid%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-47062%22%20slang%3D%22en-US%22%3E%3CP%3EWhere%20a%20customer%20has%20an%20Exchange%20Online%20hybrid%20scenario%20and%20MX%20records%20are%20still%20pointed%20on-premises%2C%20can%20ATP%20still%20re-write%20the%20links%20inside%20emails%20to%20make%20them%20%22Safe%20links%22%3F%3C%2FP%3E%3CP%3EThe%20%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fmt789012(v%3Dexchg.150).aspx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EFAQ%20on%20TechNet%3C%2FA%3E%20isn't%20100%25%20clear%20on%20this%20as%20it%20indicates%20that%20the%20rewrite%20is%20done%20at%20the%20EOP%20end%20which%20makes%20sense%2C%20but%20how%20can%20it%20be%20done%20when%20they%20email%20isn't%20going%20via%20EOP%3F%3C%2FP%3E%3CP%3EIt%20does%20also%20say%20in%20that%20FAQ%3A%20%22Safe%20attachments%20scans%20incoming%20mail%20from%20outside%20the%20organization%20for%20all%20customers%2C%20as%20well%20as%20internal%20emails%20between%20employees%20for%20hosted%20mailbox%20customers.%20Safe%20links%20is%20only%20applied%20for%20inbound%20traffic%20from%20external%20senders%20to%20internal%20recipients.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20I'm%20just%20wanting%20to%20confirm%20if%20yes%20-%20all%20emails%20with%20URLs%20are%20scanned%20even%20if%20they%20are%20from%20the%20on-prem%20hybrid%20server%20to%20Online%2C%20or%20not.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-47062%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Server%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-60971%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20ATP%20re-write%20URLs%20in%20a%20hybrid%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-60971%22%20slang%3D%22en-US%22%3EYes%20-%20it%20works%20(for%20us).%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-47236%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20ATP%20re-write%20URLs%20in%20a%20hybrid%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-47236%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Adam%20and%20Loryan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20a%20good%20question%2C%20if%20someone%20or%20Microsoft%20can%20send%20a%20link%20that%20we%20could%20test%20and%20for%20example%20to%20show%20to%20the%20client%20when%20implementing%20it%20will%20be%20a%20must.%20I%20think%26nbsp%3Bit%20will%20be%20a%20good%20way%20to%20acomplish%20the%20test%20phase%20of%20a%20implementation%20on%20this%20kind%20of%20feature.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-47214%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20ATP%20re-write%20URLs%20in%20a%20hybrid%20scenario%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-47214%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20a%20very%20interesting%20question!%3CBR%20%2F%3E%3CBR%20%2F%3EI%20have%20spent%20a%20bit%20trying%20to%20replicate%20this%20and%20see%20what%20I%20could%20find%2C%20as%20I%20could%20not%20anwser%20this%20off%20the%20top%20of%20my%20head.%20I%20do%20allot%20of%20hybrid%20deployments%20with%20my%20clients%2C%20so%20know%20how%20this%20works%20with%20most%20filtering%2C%20I%20have%20just%20never%20specificly%20testing%20the%20malicious%20link%20aspect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20short%2C%20you%20are%20in%20scenario%203%20here%20-%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fe1da5f2f-c732-4010-85c9-878b2cef3fb3(v%3Dexchg.150)%23scenario3%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftechnet.microsoft.com%2Fen-us%2Flibrary%2Fe1da5f2f-c732-4010-85c9-878b2cef3fb3(v%3Dexchg.150)%23scenario3%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20would%20have%20a%20connector%20in%20place%2C%20and%20that%20connector%20would%20enable%20mail%20flow.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EUnfortunately%20I%20did%20not%20find%20anything%20conclusive%20on%20the%20ATP%20side%20of%20the%20house.%20I%20do%20know%20from%20testing%20and%20documentation%20that%20even%20with%20a%20connector%2C%20EOP%20will%20still%20do%20such%20tasks%20as%20malware%2Fspam%20filtering%2C%20as%20well%20as%20more%20advanced%20compliance%20asks.%20Ultimately%20from%20my%20understanding%20the%20connector%20just%20shields%20you%20from%20blacklisting%2C%20but%20the%20filtering%20still%20happens.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSPAN%3EThis%20connector%20enables%20Office%20365%20to%20scan%20your%20email%20for%20spam%20and%20malware%2C%20and%20to%20enforce%20compliance%20requirements%20such%20as%20running%20data%20loss%20prevention%20policies.%20When%20your%20email%20server%20sends%20all%20email%20messages%20directly%20to%20Office%20365%2C%20your%20own%20IP%20addresses%20are%20shielded%20from%20being%20added%20to%20a%20spam%20block%20list.%20To%20complete%20the%20scenario%2C%20you%20might%20need%20to%20configure%20your%20email%20server%20to%20send%20messages%20to%20Office%20365.%22%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3EWith%20that%20said%2C%20logically%20I%20would%20say%20yes%2C%20ATP%20should%20still%20work.%20But%20this%20is%20just%20my%20extrapalation%20from%20my%20own%20testing%20and%20previous%20experience.%20I%20do%20not%20have%20a%20malicious%20link%20to%20test%20with%20%26gt%3B%26lt%3B%3CBR%20%2F%3E%3CBR%20%2F%3ESorry%20this%20was%20not%20conclusive%2C%20but%20hopefully%20this%20mesh's%20with%20your%20own%20thoughts%20on%20the%20matter%20and%20gives%20you%20a%20bit%20more%20confidence.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Adam%3C%2FP%3E%3C%2FLINGO-BODY%3E
Loryan Strant
MVP

Where a customer has an Exchange Online hybrid scenario and MX records are still pointed on-premises, can ATP still re-write the links inside emails to make them "Safe links"?

The FAQ on TechNet isn't 100% clear on this as it indicates that the rewrite is done at the EOP end which makes sense, but how can it be done when they email isn't going via EOP?

It does also say in that FAQ: "Safe attachments scans incoming mail from outside the organization for all customers, as well as internal emails between employees for hosted mailbox customers. Safe links is only applied for inbound traffic from external senders to internal recipients."

 

So I'm just wanting to confirm if yes - all emails with URLs are scanned even if they are from the on-prem hybrid server to Online, or not.

 

Thanks

3 Replies

This is a very interesting question!

I have spent a bit trying to replicate this and see what I could find, as I could not anwser this off the top of my head. I do allot of hybrid deployments with my clients, so know how this works with most filtering, I have just never specificly testing the malicious link aspect.

 

In short, you are in scenario 3 here - https://technet.microsoft.com/en-us/library/e1da5f2f-c732-4010-85c9-878b2cef3fb3(v=exchg.150)#scenar...

 

You would have a connector in place, and that connector would enable mail flow. 

Unfortunately I did not find anything conclusive on the ATP side of the house. I do know from testing and documentation that even with a connector, EOP will still do such tasks as malware/spam filtering, as well as more advanced compliance asks. Ultimately from my understanding the connector just shields you from blacklisting, but the filtering still happens.

 

"This connector enables Office 365 to scan your email for spam and malware, and to enforce compliance requirements such as running data loss prevention policies. When your email server sends all email messages directly to Office 365, your own IP addresses are shielded from being added to a spam block list. To complete the scenario, you might need to configure your email server to send messages to Office 365."

With that said, logically I would say yes, ATP should still work. But this is just my extrapalation from my own testing and previous experience. I do not have a malicious link to test with ><

Sorry this was not conclusive, but hopefully this mesh's with your own thoughts on the matter and gives you a bit more confidence.

 

-Adam

Hi Adam and Loryan,

 

This is a good question, if someone or Microsoft can send a link that we could test and for example to show to the client when implementing it will be a must. I think it will be a good way to acomplish the test phase of a implementation on this kind of feature.

 

Yes - it works (for us).