Skip to content
Avanet

Set up Sophos Email Mailflow for Microsoft 365

Sophos Mailflow integrates Sophos Email through Microsoft 365 applications, Exchange Online connectors, and mail flow rules. It doesn’t require an MX change: Microsoft 365 sends matching messages to Sophos for scanning and receives them back. Because setup grants organization-wide consent and makes automated Exchange Online changes, perform it in an approved change window.

Quick path: record prerequisites and rollback, synchronize the directory, optionally create a Microsoft 365 group for a subset, add the domain under Global Settings > Products and Services > Email > M365 Mailflow Domains, consciously review and grant Microsoft consent, run Connect, resolve conflicts before activation, and run Run a Quick Test. Then verify inbound and outbound traffic in Sophos Message History and Microsoft Message Trace.

Record prerequisites and the starting state

Use a Microsoft 365 subscription that supports inbound connectors; Microsoft developer tenants aren’t supported. The sign-in account needs the Microsoft 365 administrator role required for domain confirmation and consent. Sophos specifies a Global admin for the Microsoft-domain sign-in and a Super Admin of the corresponding domain to set up a connection. Assign owners for Microsoft 365, Sophos Fusion (formerly Sophos Central), and DNS, and approve a recovery path first.

Record the tenant, domains, mailbox or group scope, current rule and connector names and priorities, any Gateway deployment, test senders and recipients, and stop criteria. Allow Microsoft pop-ups and ensure the browser is signed in to the intended tenant; use a private window if it has credentials for another tenant. Mailflow checks only domains added and verified in Sophos Fusion and included in the Microsoft connectors. Deliberately assess any used onmicrosoft.com or other sender domain too.

Consent applies to the organization, not just the person approving the prompt. Before selecting Accept, compare the tenant, publisher, application name, and requested permissions with the approved change. Sophos documents three application roles:

  • Sophos Email reads domains, directory data, and user profiles, and can read and write mail in all mailboxes.
  • Sophos can manage applications that it creates or owns and read the signed-in user’s profile.
  • Sophos Email Mail flow manages Exchange as an application, reads organization activity data, reads and writes domains and directory RBAC settings, and reads directory data.

These permissions let Sophos create the applications, accepted domain, connectors, and transport rules through Microsoft APIs and PowerShell. They are not a reason to run unverified scripts with broader privileges. Consent doesn’t expire automatically; revoking it stops Mailflow. Enabling post-delivery protection creates a second application with separate Graph permissions. Stop if the tenant, publisher, names, or permissions are unexpected.

Protect all mailboxes or a selected subset

For all mailboxes, preferably synchronize users, mailboxes, and groups through Active Directory or Microsoft Entra ID; manual and CSV entry are also supported. Compare the imported inventory with the intended scope before changing routing.

For a subset, create a group of type Microsoft 365 in the correct domain in the Microsoft 365 admin center before connecting Mailflow, then add the selected mailboxes. Directory synchronization makes the group name available as a suggestion; without synchronization, enter it exactly. A domain can contain up to 10,000 mailboxes while the group selects only those requiring protection. Microsoft 365 expands a distribution list into per-recipient messages before sending them to Sophos, so align policies with that behavior.

Create the domain, rules, and connectors

  1. Open Global Settings > Products and Services > Email > M365 Mailflow Domains and select Setup Domains and Policies for M365 Mailflow. For a Gateway migration, select Copy Existing M365 Domains instead.
  2. Synchronize the directory if needed. Choose the domain details and optional prepared Microsoft 365 group, then start Setup M365 Mailflow.
  3. In Microsoft’s redirect, sign in to the correct tenant, review each consent prompt, and grant only the approved permissions.
  4. In the domain list, select Connect and complete the guided application, connector, and rule creation. Creation can take up to ten minutes, and Microsoft may finish resources in the background afterward.
  5. In Exchange Admin Center, inspect Mail flow > Rules and Mail flow > Connectors and compare each new object’s status and priority with the change record. Sophos also adds an accepted subdomain ending in xgeconnector.com for certificate-based Exchange communication. Don’t delete it; doing so can break mail flow.

Sophos rules take priority over existing rules so threat scanning runs first; existing rules retain their relative order afterward. Microsoft can still filter high-confidence phishing or malware before Sophos receives it. Treat that as an architecture boundary, not a reason to disable Microsoft protection broadly.

Resolve rule conflicts before activation

When Pre-existing Mailflow Rules Found appears, don’t activate blindly. Complete setup with immediate activation only when the existing rules and connectors are understood and don’t affect the Sophos path. Otherwise choose Complete Sophos mailflow configuration but keep it turned off. Sophos creates the objects but leaves the connection off.

In Exchange Admin Center, compare conditions, exceptions, target connectors, and priorities between existing and Sophos rules. There must be one coherent outbound-and-return path. After documenting conflict resolution, activate the domain with Connect in M365 Mailflow Domains and retest. Renaming, disabling, deleting, or reprioritizing Sophos objects directly without assessment can interrupt protection.

Migrate from Gateway without duplicate scanning

Mailflow and Gateway aren’t a permanent dual architecture for one domain. Copy detected Microsoft 365 domains, create Mailflow disabled, inspect the new objects, then activate only for a short monitored test. First record the Gateway domain, MX values, and all original Microsoft 365 changes.

Once both Mailflow directions are proven, delete the old Gateway connection under Products and Services > Email > Gateway Domains, undo the Microsoft 365 settings previously made for Gateway, and restore unneeded MX changes according to the approved plan. Keep overlap as short as possible. Duplicate Message History entries, smart banners, or quarantine entries indicate double processing; Sophos can’t reliably prevent it with group-based protection. Trigger the approved rollback or cleanly disconnect the old Gateway path immediately.

Validate setup and delivery

The domain must show a green check mark. Send Run a Quick Test to a controlled address. If it fails immediately, wait at least 15 minutes and try once more because Microsoft may still be creating resources. Don’t reconnect repeatedly without first diagnosing the state.

For each domain, send one inbound message from an external account and one outbound message. Match sender, recipient, time, and Message-ID in Sophos Message History and Microsoft Message Trace. Also test one protected group mailbox and one mailbox outside the group. Check Microsoft quarantine if inbound mail never reaches Sophos. The change passes only when domain state, both directions, intended scope, and exactly one Sophos scan are confirmed.

For failed tests, changed rules or connectors, and other operational faults, follow the systematic Sophos Email Mailflow troubleshooting guide for Microsoft 365.

Roll back and remove everything cleanly

During an incident, first disable or disconnect Mailflow in a controlled way and restore the documented working route. Confirm delivery with test messages before deleting more objects. Disconnecting the domain in Sophos Fusion normally removes its related rules and connectors automatically, but verify the actual Microsoft 365 state.

If remnants remain or Mailflow is being retired, work one domain at a time. In Microsoft Entra admin center under App registrations, delete that domain’s Sophos Email Mail flow application and, if used, the post-delivery application. In Exchange Admin Center, delete that domain’s inbound and outbound Sophos redirect rules under Mail flow > Rules, then its inbound and outbound connectors under Mail flow > Connectors. Remove only objects unambiguously associated with the domain. Finally verify domain status, accepted-domain remnants, two-way delivery, Message Trace, and the absence of Sophos routes, then revoke organization-wide consent according to the approved offboarding record.