Incydr email data connection overview

Overview

As part of your insider risk detection strategy, allowing Incydr to access your email services enables you to capture information about the attachments that your users email to other recipients.

See the articles listed below to learn how to authorize Incydr to start capturing metadata from your email service.

Considerations

  • Your product plan must include at least one email service. If your license expires, the email connection is deauthorized within 24 hours. If you need assistance with licensing, contact your Customer Success Manager (CSM). If you do not know your CSM, please contact our Technical Support Engineers.
  • To connect to the email service, you must have the appropriate permissions in the email service as well as in Incydr.

    • Gmail: You must be a Google Workspace administrator with a Super Admin role to authorize the connection to Incydr
    • Microsoft Office 365: You must be a global administrator in Office 365 to authorize the connection to Incydr
  • Incydr only monitors email attachments. Email message content is not accessed, monitored, or changed.

  • To use this functionality, Incydr users must be assigned specific roles. For more information, see Permissions for Incydr

Monitoring and alerting tools may report download activity
When ongoing file activity is detected, Incydr temporarily streams files from your cloud storage or email service to the Incydr cloud to calculate the file hash. (Incydr does not calculate hash value during the initial inventory process.) 

This appears in your vendor logs as users downloading files. The requesting service's IP address may point to Microsoft Azure hosts. Consider adding these IP addresses to your allowlist to reduce false alerts in your vendor logs, keeping in mind that these addresses can change. 

Incydr never stores file contents or writes them to disk during this process.

Supported email service vendor plans and licenses

Incydr can only connect to your cloud storage environment when supported by that vendor's plan or license.

Gmail Microsoft Office 365

Requires one of these Google plans:

  • Business Starter
  • Business Standard
  • Business Plus
  • Enterprise Standard
  • Enterprise Plus

Requires a Microsoft license or subscription that includes Exchange Online.

Follow the instructions in the articles linked below to connect your email environment to Incydr.

Once authorized, Incydr captures file and message information about all attachments that are emailed through your organization's environment from that point forward. Incydr can monitor all user email accounts, only specific user email accounts, or only the user email accounts that are in specific groups.

When new users are added to your organization's environment, information about the attachments they email also becomes available in Forensic Search automatically.

Related topics

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.