Connect Sophos Email Monitoring System to Microsoft 365
Sophos Email Monitoring System (EMS) can set up journaling for Microsoft 365 automatically. In the EMS domain, select Microsoft 365 as the journal source, start Setup M365 Journal, and grant the requested consent in Microsoft 365. Sophos then verifies domain ownership, creates the required application and journal rule, and configures the NDR mailbox setting if none exists yet.
Through the journal rule, EMS receives copies of inbound and outbound emails for analysis. Normal mail flow remains in Microsoft 365; this process does not turn EMS into an upstream mail gateway. Automatic configuration applies only to Microsoft 365, not Google Workspace.
Prerequisites, license, and roles
Before starting, make sure that:
- The domain already exists in Sophos EMS and Microsoft 365 is selected as the journal source.
- The tenant uses a supported Exchange Online plan: Business Basic, Business Standard, Business Premium, E1, E3, or E5.
- A Microsoft 365 Global Administrator is available to sign in. Alternatively, the account used must be able both to grant Admin Consent for applications and to create Exchange Online journal rules.
- The administrator performing the setup can open the EMS domain dialog.
Exchange Online Kiosk does not support journal rules. Automatic configuration fails with this plan; switch to a supported plan before trying again.
Microsoft 365 permissions and Sophos Fusion roles are separate areas of responsibility. Assign Sophos Fusion administration roles correctly explains the general Sophos role boundaries. The Microsoft role requirement does not imply a specific minimum Sophos role. If Setup M365 Journal is missing, first clarify EMS access and licensing with the responsible Sophos administrator or partner instead of broadening roles on suspicion.
Record the initial state
Before selecting Proceed, record at least the domain, Microsoft 365 tenant, and administrator account used. In Microsoft Purview, also record the existing journal rules and the current Journal NDR fallback mailbox. If the Sophos Email Monitoring application already exists in the tenant, include that in the baseline as well.
This inventory is important for later acceptance and removal: Sophos does not overwrite an existing NDR mailbox setting and cannot reset it during offboarding.
Set up Microsoft 365 journaling automatically
- Open the EMS domain for which Microsoft 365 is selected as the journal source.
- In the domain dialog, select Setup M365 Journal.
- In the confirmation dialog, verify that it announces a redirect to Microsoft 365 and permissions to create an application and journal rules.
- Select Proceed.
- Sign in with the designated Microsoft 365 account.
- Review the requested permissions and grant Application Consent.
- Return to EMS and monitor the progress. Configuration can take several minutes. You can leave the dialog open or close it; check the status again later on the Domains page.
After successful configuration, expect the following state:
- The Sophos Email Monitoring application is created if it does not already exist in this Microsoft 365 tenant.
- A journal rule sends copies of inbound and outbound emails to Sophos EMS for analysis.
- The NDR mailbox for the journal rule is configured only if none exists. An existing value is not overwritten.
If journaling is already configured for one EMS domain, Sophos reuses that EMS configuration when additional domains from the same Microsoft 365 tenant are added. Do not infer from this that arbitrary manually created or unrelated journal rules are adopted. Therefore, do not manually create additional applications or rules for the same EMS workflow.
Validation and expected result
After the success message, select Run a Quick Test. Sophos sends a test email; the expected result is confirmation that journaling works. Connect additional domains from the same tenant only after this test succeeds.
Also verify the automatically expected resources against the baseline:
- The Sophos Email Monitoring application exists in the tenant.
- The journal rule created by Sophos exists under Microsoft Purview > Journal rules.
- The Journal NDR fallback mailbox either matches the previously recorded value or the value set when the initial setting was empty.
After successful setup, you can select Review Policies to configure monitoring policies. These policies are not part of the Microsoft 365 journaling configuration. Setup is complete when EMS reports that automatic configuration succeeded and Run a Quick Test confirms journaling.
Troubleshooting by symptom
Automatic setup fails with Exchange Online Kiosk
Kiosk plans do not support journal rules. Repeating the attempt unchanged cannot succeed. First switch to Business Basic, Business Standard, Business Premium, E1, E3, or E5, then start setup again.
Sophos cannot create the required application credentials
An Application Management Policy can restrict credentials allowed for new applications. Conditional Access can also block setup. The Microsoft 365 administrator checks both policy types for rules that prevent creation of the required credentials. Run Setup M365 Journal again only after correcting the specific block found.
Domain ownership verification fails
Verify that the signed-in account can grant Admin Consent and create Exchange Online journal rules. The domain must also belong to the Microsoft 365 tenant being used. Then sign in again with the correct tenant and an account with sufficient permissions.
The status remains in progress or cleanup continues
Setup and cleanup can take several minutes. You can close the progress dialog and check the status later on the Domains page. While the operation is running, do not manually create or delete parallel applications or journal rules for the same workflow. If the status does not change, provide the recorded baseline and visible error message to Sophos Support instead of changing resources on suspicion.
Run a Quick Test does not confirm journaling
First check the domain status in EMS. Then compare the application, journal rule, and NDR value with the recorded baseline. If an expected resource is missing, do not adjust monitoring policies yet. Evaluate the displayed error, check for blocks caused by Conditional Access or an Application Management Policy, and repeat the Quick Test only after correcting the issue.
Safe rollback or offboarding
Before deleting an automatically configured domain, determine whether other EMS domains in this tenant use the same journaling configuration. This is essential because Sophos cleans up differently:
- If at least one other EMS domain in this tenant remains, Sophos removes the association between the journal rules and the deleted domain. The shared journaling configuration remains for the other domains.
- For the last EMS domain in this tenant, Sophos removes the journal rules and Microsoft 365 application it created.
Use this controlled rollback:
- Inventory all EMS domains in the Microsoft 365 tenant and determine whether the domain to be deleted is the last one.
- Record the journal rules, application, and Journal NDR fallback mailbox again.
- Delete the domain in EMS and allow cleanup to finish.
- If domains remain, use Run a Quick Test there to confirm that the shared journaling configuration still works.
- If the last domain was deleted, verify that the journal rules and application created by Sophos were removed.
- Compare the NDR fallback address separately with the approved target value.
Microsoft 365 does not allow Sophos to reset the Journal NDR fallback mailbox. If the address must change after offboarding, change it manually in Microsoft Purview. The correct target depends on your Exchange Online environment and must not be replaced with a generic value.
Operations, review, and lifecycle
Run Run a Quick Test again after changes to Microsoft 365 plans, domains, Conditional Access, or Application Management Policies. Do the same after adding another domain in the same tenant, even if Sophos reuses the existing configuration.
For ongoing operations, document the responsible Microsoft 365 and EMS owners, the account or role authorized to grant consent, affected domains, and current NDR value. Review this record again before removing the last domain. This keeps it clear which resources Sophos created and which NDR setting already existed.
Related existing guides
- Assign Sophos Fusion administration roles correctly explains Sophos-side roles and the least-privilege principle. Microsoft 365 roles and Admin Consent remain separate.