Hybrid model (where some exchange mailboxes are hosted in Microsoft 365) (using DNAT) Palo Alto inspect the traffic be regarded secure enough?
cancel
Showing results for 
Search instead for 
Did you mean: 

Hybrid model (where some exchange mailboxes are hosted in Microsoft 365) (using DNAT) Palo Alto inspect the traffic be regarded secure enough?

L2 Linker

We have clients who want a Hybrid model (where some exchange mailboxes are hosted in Microsoft 365) rather than full blown integration.

 

Would the proposed solution (using DNAT) with the sources constrained to the Microsoft approved IP/URL list and having the Palo Alto inspect the traffic be regarded secure enough?

2 REPLIES 2

L4 Transporter

Follow this:

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POJACA4

 

 

 

If you are planning to do SSL decryption you may see some issues like for sharepoint so be prepared

 

 

https://live.paloaltonetworks.com/t5/general-topics/how-to-exclude-office-365-from-ssl-decryption/m-...

 

 

 

For the best security for Cloud Apps CASB (Cloud Access Security Broker) is needed if you are in a health or bank company, so maybe also see Prisma SaaS or other CASB provider.

 

 

https://www.paloaltonetworks.com/prisma/saas

Hello,

Could you expand on the statement "secure enough"? 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!