Set up and verify Sophos Email Post-Delivery Protection
Post-Delivery Protection (PDP) removes messages that have already reached user mailboxes. It does this by connecting a protected Microsoft 365 or Google Workspace domain to Sophos Fusion (formerly Sophos Central). The features are initially off and should be enabled deliberately only after the connection succeeds.
Operational boundary: This workflow covers setup and operation in Sophos Fusion. API-based clawback and API access to post-delivery quarantine are a separate automation workflow. Post delivery summary reporting is also not the configuration source.
Check prerequisites and record the starting state
Before the change, verify and record:
- a Sophos Fusion account with Super Admin rights for the domain connection;
- a valid Sophos Email license;
- an already added and connected protected domain: Microsoft 365 Gateway or Mailflow, or Google Workspace Gateway;
- an administrator account in the correct Microsoft 365 or Google Workspace tenant that can grant the requested permissions;
- the current Post-Delivery connection status and state of every PDP switch;
- up to five mailboxes that must remain excluded for a documented reason;
- the provider connection, checked at domain level with Test connection where the provider workflow offers it;
- one controlled test mailbox reserved for delivery and manual clawback validation.
The browser must allow the Microsoft or Google pop-ups during setup. Stored credentials for another tenant are a common cause of failure. Use a private window in that case and check the displayed domain before granting consent.
For new Google Workspace accounts, Google Cloud enables a policy that prevents service-account key creation by default. Disable it before connecting PDP or the connection fails. Coordinate this change with the Google Cloud owner and record it in the change.
Separate automatic and manual remediation
The two features have different triggers:
- Auto search and remediate searches user mailboxes for delivered messages that are subsequently found to be malicious. Remove emails containing malicious URLs responds to URLs later identified as malicious; Remove emails containing malware responds to malware found after delivery. Matches move from the mailbox to post-delivery quarantine.
- On demand clawback is initiated by an administrator for a previously delivered message considered unsuitable for one or more recipients. It isn’t an automatic malware verdict. Selected messages are retracted into post-delivery quarantine.
Include internally forwarded emails extends both operations to internally forwarded or replied-to copies. For manual clawback this includes inboxes and sent items. This option is supported only for Microsoft 365 mailboxes. When it is off, remediation affects only the originally delivered message.
Exclude mailboxes can exempt at most five mailboxes from PDP. Neither automatic nor manual clawback removes messages from them. An exclusion is therefore a deliberate protection gap and needs an owner, reason, and review date.
Connect Microsoft 365
- In Sophos Fusion, open Global Settings.
- Go to Products and Services > Email > Gateway Domains, or M365 Mailflow Domains for Mailflow.
- Under Post-Delivery, hover over the required domain status and select Connect.
- If Sophos can’t detect the service, choose Microsoft M365. Read and accept the terms of use.
- Review the Microsoft permission windows and grant consent using an administrator in the correct tenant. Two requests normally appear—one for the Sophos master application and another for API access—but a previous consent can reduce this to one.
- Select Continue, allow the setup several minutes, and select Close only when it completes.
- Check the domain status. Then open Configure Post Delivery, enable the approved features, and select Save.
A consent window not appearing again doesn’t by itself indicate a fault: Sophos Fusion can reuse an existing Microsoft 365 authorization for additional domains in the same tenant. The correct tenant and resulting connection status are what matter.
Connect and authorize Google Workspace
- In Sophos Fusion, open Global Settings > Products and Services > Email > Gateway Domains.
- Under Post-Delivery, hover over the required domain status and select Connect.
- If prompted for the service, choose Google Workspace and accept the terms of use.
- Select the Google Workspace administrator account for the correct domain, verify the account, and grant all requested access. PDP doesn’t work without these permissions.
- Select Continue, wait for setup to finish, and select Close.
- In the expanded domain row, use the Copy buttons for Google OAuth Client ID and the list of OAuth scopes.
- Open the supplied Google Workspace Admin console link, select Add new, paste the client ID and comma-delimited scopes, and select Authorize. Select Overwrite existing client ID only when that client ID already exists and is intentionally being replaced.
- Return to Sophos Fusion and run Test connection. Authorization can take several minutes; a successful test confirms full authorization.
- Open Configure Post Delivery, enable the approved features, and select Save.
Sophos Fusion can reuse an existing Google Workspace authorization for multiple domains in the same tenant. Still verify the domain, account, and status separately for each domain.
Distinguish Google permissions from Phish Threat
The Google consent dialog can show https://www.googleapis.com/auth/cloud-platform to create, read, update, or validate required Google Cloud resources during setup and https://www.googleapis.com/auth/userinfo.email to identify the consenting administrator account. These permissions are used by Google Directory, Google Post-Delivery Protection, and Google Direct Delivery. Their presence does not mean that all three features are configured: Sophos uses them only for the feature being configured.
Of these three features, this workflow covers only Google Post-Delivery Protection. Google Direct Delivery delivers Phish Threat simulations and is configured separately in Set up and verify Sophos Phish Threat Direct Delivery; PDP exclusions such as Exclude mailboxes are not a substitute for its delivery configuration.
After consent, Test connection and the controlled, harmless clawback in “Validate safely” confirm the PDP connection. If a required permission is revoked in Google Workspace, the associated Sophos feature stops working until it is reconnected in Sophos Fusion. Repeat both checks after reconnecting; third-party permissions can also be reviewed or removed in the Google Admin console.
Configure the protection scope
Use a staged rollout:
- Enable and save On demand clawback for the connected domain first.
- Perform a controlled, harmless clawback and inspect the result.
- Enable Auto search and remediate, then explicitly select the required sub-options for malicious URLs and malware.
- For Microsoft 365, enable Include internally forwarded emails only after reviewing its wider reach.
- Add any necessary Exclude mailboxes entries and document the five-mailbox limit and resulting protection gap.
The sub-options matter: enabling Auto search and remediate alone doesn’t state whether later URL detections, malware detections, or both are to be removed.
Validate safely
Never send live malware or unknown samples. First run Test connection for the domain where the provider workflow offers it. Then deliver a harmless, uniquely identifiable inbound message to an isolated test mailbox in that connected domain and use this GUI workflow:
- Record its time, sender, recipient, subject, and Message-ID.
- Go to Reports > Email Security Logs > Message History. Filter for inbound messages with Delivery Successful, and use Advanced Search and the recorded identifiers to locate the eligible message. Only successfully delivered messages in mailboxes belonging to a domain connected for PDP can be clawed back.
- Select the message subject to open Message Details, then select only the recipient row for the controlled test mailbox and select Initiate clawback. In the dialog, select a reason and, where offered, whether to report the message to SophosLabs; select Clawback to start the action.
- In Message Details, check Additional details. The expected progression is Clawback Initiated and then Clawback Successful; provider processing can take up to 10 minutes. A distribution-list recipient can remain at Clawback Initiated even after a successful attempt.
- If the state becomes Clawback Failed, inspect Additional details and recheck successful delivery, the selected recipient, and that recipient’s mailbox domain connection. Correct that specific cause before making one new attempt.
- Confirm that the message is no longer in the selected mailbox and appears under My Products > Email Security > Quarantined Messages > Post delivery quarantine. In some views the path begins at Email Security Dashboard. Match the recipient and message there. The follow-up actions are Release and Delete; perform either only after content review and the organization’s release or deletion process.
- Cross-check the event under Reports > Post delivery summary, without treating the report as configuration.
Don’t validate automatic remediation by mailing malicious content. Inspect an existing legitimate detection or wait for a genuine reclassification within the pilot scope, then compare the mailbox, post-delivery quarantine, and summary.
For Google Workspace, internally routed messages with multiple recipients can show recipient failures in the summary even though a message has already been clawed back. Google processes recipients separately. Check the actual mailbox outcome before repeating the clawback.
Diagnose status and failures
The connection doesn’t complete
Let the displayed message determine the next step:
- Failed to establish session: session has timed out: retry in a new private window and permit pop-ups.
- Consent for API access wasn’t granted or consent for data access wasn’t granted: reconnect with the correct provider administrator and approve all requested access.
- Domains … don’t match: compare the Sophos Email domain with the signed-in Microsoft 365 or Google Workspace tenant; don’t bypass this by consenting in the wrong tenant.
- Google requires the Google APIs Terms of Service or Google Apps Admin APIs Terms of Service: accept the displayed terms as an administrator, then reconnect.
- Google reports denied Cloud data access, Access was denied, or an application error: check for a canceled consent screen, selected access, and the correct account.
- A Google test still fails: compare the client ID and comma-delimited scopes in the Admin console with the values in the domain row, allow time for authorization, and retest. Also check whether the service-account-key creation policy is blocking setup.
Rapidly reconnecting multiple times doesn’t repair missing consent or a domain mismatch. Correct the specific cause, then make one new attempt.
The connection exists but no message is removed
Check in this order:
- Does the affected domain show as connected?
- Was Auto search and remediate or On demand clawback actually saved, with the relevant URL or malware sub-option enabled?
- Is the recipient mailbox listed under Exclude mailboxes?
- Are internally forwarded copies expected in Google Workspace or with the Microsoft option off? That scope isn’t available in those cases.
- Was the message already delivered, was the right recipient selected, and is there a result in post-delivery quarantine or the summary?
- For multiple Google recipients, is the reported failure only the documented internal-processing effect even though the mailbox has already been remediated?
A message that was never reclassified as malicious isn’t a negative test of Auto search and remediate. That test requires a valid post-delivery detection.
Roll back without uncontrolled release
Before setup, record the connection status, switches, sub-options, internal-forwarding option, and excluded mailboxes. If the pilot fails, first restore those switches to their documented starting state and save. Don’t bulk-release or delete quarantined messages; assess each one.
To remove the provider link completely, use Disconnect under Post-Delivery for the domain. This stops scanning delivered messages and further post-delivery actions for that domain. For Google Workspace, confirm an administrator account, accept the displayed terms and permission windows, allow the several-minute process to finish, and then check the domain status.
After rollback, use a harmless message to confirm that normal delivery still works and verify that no new PDP operation is expected or triggered. For escalation, collect the domain, provider, connection status, UTC time, administrator tenant, exact error, enabled PDP options, recipient, Message-ID, and the outcomes in post-delivery quarantine and the summary. Never put passwords, tokens, or other credentials in a ticket.