Changes to audit unauthorized use of allow-relay in ProofPoint

Please see the following scheduled Information Technology Services (ITS) maintenance:

Date: Thursday October 5th                        

Start Time: 8:00pm
End Time: 10:00pm

The following work is being completed: Three rules that are already in place will be enabled, one on Exchange Online that adds a security GUID to the headers of emails sent directly from 365 to ProofPoint, and two in ProofPoint one that removes this header for known authorized senders, and a second that creates an audit log entry for unknown senders. The unknown senders, if any, will be reviewed and additional legitimate senders added as needed. On a future date the allowed relay senders will be locked down so that unknown senders (potentially through abuse of other 365 tenants) will not be allowed to use the relay.

All affected groups: Any account that is sending directly to ProofPoint, this is currently devices and SMTP traffic.

All processes affected: All emails sent from 365 directly will have a new header added with a unique GUID to identify that the email came from WSU’s instance and not from another 365 customer.

Duration of impact: About two hours.

Follow up steps customers need to take: None

Questions? Please contact mark.bradt@wsu.edu with any questions regarding this scheduled outage.