Microsoft Exchange Online integration
Summarize
Summary of Microsoft Exchange Online integration
The Microsoft Exchange Online integration within the ServiceNow AI Platform® Security Incident Response (SIR) product enables Security Operation Center (SOC) analysts to search corporate email environments for security threats and remediate phishing emails by leveraging email search and delete capabilities. Analysts execute email searches based on criteria such as subject lines, sender, and recipient addresses directly from the security analyst interface. After locating suspicious emails, analysts can delete them, with an optional approval process configurable to control deletions. This integration is designed to support phishing response workflows by identifying and mitigating phishing campaigns across the organization.
Show less
Key features
- Configurable search criteria using sender, recipient, and subject fields within Security Incident Response to identify phishing threats.
- Email search notifications sent to analysts for large or lengthy searches, including the number of matched messages.
- Status tracking for emails indicating if recipients have read or deleted suspicious messages.
- Optional approval workflows to ensure emails are not deleted without proper authorization.
- Comprehensive audit trails recorded in incident work notes documenting deletion requests and counts.
- Security tags configurable to mark initiation and completion of email search and delete workflows for quick identification.
Supported environments
The integration supports Microsoft Exchange Online services as part of Microsoft Office 365, specifically Exchange 2016 versions. Hosted Microsoft Exchange environments are not supported.
Prerequisites and setup
- Installation and activation of the com.snc.sidep plugin and essential Security Operations applications (Security Integration Framework, Security Support Common, Security Support Orchestration, and Security Incident Response) in a specified order are required.
- A Microsoft Azure account must be set up to enable access to the Microsoft Exchange Online tenant for retrieving email message details.
- The Microsoft Exchange Online application must be installed from the ServiceNow Store and configured to connect with your ServiceNow AI Platform instance, activating search and delete workflows.
Operational workflow
- Security analysts with the snsi.analyst role define and submit email search criteria based on incident details.
- Upon successful search completion, analysts can request deletion of suspicious emails directly from Microsoft Exchange Online.
- If enabled, deletion requests undergo an approval process involving designated approval group members to add control over email removals.
- Microsoft Exchange administrators may recover deleted emails if incident remediation requires restoration.
- Security tags within ServiceNow can be customized to visually track the status and results of search and delete actions.
For the Microsoft Exchange Online integration application by ServiceNow, the ServiceNow AI Platform® Security Incident Response (SIR) product is integrated with the Microsoft Exchange Online service, one of the cloud-based services in the Microsoft Office 365 suite of products. Your Security Operation Center (SOC) analyst can search your corporate email environment for security-related threats and remove and remediate phishing emails with email search and delete capabilities.
Overview of Microsoft Exchange Online integration
As the security incident analyst, you execute the integration from the security analyst interface, and the workflow returns email message details that match search criteria. Email searches are based on criteria that include subject lines as well as sender and recipient email addresses. After the email search is complete, you can delete suspicious emails from the Microsoft Exchange Online service, and, an optional approval process can be configured to request approval prior to deleting emails.
This email search and delete integration can be used with a broader phishing response incident workflow or runbook. After a corporate user or employee receives a suspicious email and reports it to the company's phishing response team or inbox, the reported email is forwarded to the ServiceNow AI Platform and categorized as a security incident. After you have verified that an email is a phishing attack, as the analyst responsible for investigating phishing incidents, you can initiate an email search to determine if other corporate users have received this phishing email. The search allows you to locate related emails from the same phishing campaign and identify other potential victims who may have received the email, read it, and also potentially clicked a malicious URL or opened an attachment.
Key features
The integration includes the following key features:
- Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
- For large and lengthy email searches, the security incident analyst is notified via email when the search has successfully completed, along with the number of matched messages.
- Status for individual messages informs you if recipients have read or deleted suspicious emails.
- If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
- A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents.
- If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents.
Supported Microsoft Exchange Online versions
This integration supports Microsoft Exchange Online services, which are part of the Microsoft Office 365 suite. The integration does not support hosted Microsoft Exchange environments. Microsoft runs Microsoft Exchange Online services on the Exchange 2016 version.
Prerequisites
The com.snc.si_dep plugin is required for any ServiceNow AI Platform version. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before installing and activating the other Security Operations applications.
- Security Integration Framework
- Security Support Common
- Security Support Orchestration
- Security Incident Response