Create Rules
Last updated
Was this helpful?
Last updated
Was this helpful?
The Email flow rule enables Nightfall to route your emails back to Exchange Online once scanned.
Additionally, you can also create a rule for quarantining suspicious emails. This rule is optional and is required only if you wish to quarantine emails.
On the Exchange Admin Center page, Expand Mail flow and select Rules.
Click Add a Rule and select Create a new Rule.
Enter a name for the rule in the Name field.
In the Apply this rule if field, select The sender.
Select Is External/Internal.
Select Inside the Organization in the select sender location field.
Click Save.
Select Redirect the message to in the Do the following field.
Select the Following connector option and select the connector created in the OutBound Connector section.
Click Save.
Click + to add an additional condition to the rule.
Select Modify the message properties in the And field.
Select Set a message Header.
Click the first Enter text button.
Enter x-nightfall-id and click Save.
Click the second Enter text button.
Enter the UUID of your Nightfall tenant and click Save. You can view the UUID of your Nightfall tenant by navigating to the Settings section from the Nightfall app.
Select The message headers… in the Except if field.
Select includes any of these words.
Click Enter text.
Type x-nightfall-scanned and click Save.
Click Enter words.
Type True, and click Add. Select the True check box.
Click Save.
Click Next.
Ensure that the Rule mode is set to Enforce and the Severity is set to High.
Click Next.
Click Finish.
You must create this rule only if you wish to implement the quarantine action while creating policies.
Click Add a Rule and select Create a new Rule.
Enter a name for the rule in the Name field.
In the Apply this rule if field, select The message headers...
Select includes any of these words.
Type X-NIGHTFALL-QUARANTINE and click Save.
Click Enter words.
Type True, and click Add. Select the True check box.
Click Save.
Select Redirect the message to in the Do the following field.
Select the hosted quarantine option.
Click Next.
Ensure that the Rule mode is set to Enforce and the Severity is set to High.
Click Next.
Click Finish.