Docs / Obsidian Suite / Connect your mail
Exchange Server
How to put Obsidian Suite in front of an on-premises Exchange Server, and how to connect it through Exchange Web Services and LDAP. Your domain page in the portal (Manage > Organizations > your organization > the domain) shows the same steps, filled in with your domain and Obsidian Suite's addresses.
Before you start
- Your organization's Platform is Exchange Server (organization page, Settings).
- Note the Obsidian Suite IP addresses listed on the domain page. Obsidian Suite connects to your Exchange server from those addresses.
Mail flow
- Delivery target. On the domain page, set Deliver clean mail to to the public name or address of your Exchange server, Port 25, and save. Use Test delivery host to check that Obsidian Suite can reach it and that it offers STARTTLS.
- Receive connector. Make sure the Exchange receive connector accepts anonymous mail from the Obsidian Suite addresses. Once the MX points at Obsidian Suite, restrict it to those addresses, so nobody can bypass the filtering by connecting to Exchange directly.
- Junk rule. Transport rule: if the header
X-Obsidian-SpamincludesYes, set the spam confidence level (SCL) to 6. Tagged mail then goes to Junk Email. - MX record. Change your domain's MX to
10 mx1.obsidiansuite.net. See Getting started. - Outbound (optional). See Sending outbound mail.
API connector
The connector adds user sync, sign-in with Windows passwords and clawback of delivered threats, plus API-mode scanning if you want it. On your organization page choose API connectors > Add connector > Exchange Server. Exchange Web Services and a domain controller must be reachable from Obsidian Suite for it to work; allow only the Obsidian Suite addresses.
Prepare Exchange
- Create a service account, for example
svc-obsidian. - In the Exchange Management Shell, give it the ApplicationImpersonation role:
New-ManagementRoleAssignment -Name ObsidianImpersonation -Role ApplicationImpersonation -User svc-obsidian - The EWS URL is normally
https://mail.<your-domain>/EWS/Exchange.asmx. Keep NTLM authentication: it is what Exchange expects. - For LDAP, use LDAPS (port 636) to a domain controller. The same account can bind for directory reads.
Connector fields
| Field | What to enter |
|---|---|
| EWS URL | The Exchange Web Services endpoint, normally https://mail.<your-domain>/EWS/Exchange.asmx. |
| EWS service account | The service account with the ApplicationImpersonation role (DOMAIN\user or user@domain). |
| Ews password | That account's password. Stored encrypted. |
| EWS auth type | NTLM (the default, what Exchange expects) or basic. |
| Verify EWS TLS certificate | yes or no. Choose no only when Exchange uses a certificate from an internal certificate authority. |
| LDAP URL | The domain controller for directory sync and user sign-in, for example ldaps://dc1.contoso.local:636. |
| LDAP bind user | The account used to read users (can be the same service account). |
| Ldap password | Its password. Stored encrypted. |
| LDAP search base | For example DC=contoso,DC=local. |
| Mailboxes to scan (API mode) | Comma separated. Empty means every active synced user. |
Secret fields show stored once a value is saved. Leave them blank to keep the stored value.
Then choose the capabilities, described in API connectors, and use Test connection.
Users of an Exchange organization sign in to the user portal with their normal Windows password, checked against the domain controller. No password is stored in Obsidian Suite.
Troubleshooting
- ErrorImpersonateUserDenied: the service account lacks the ApplicationImpersonation role.
- Mail shows as delivered in Message trace but never arrives: run Test delivery host on the domain page, and check that the receive connector accepts the Obsidian Suite addresses.