OneDrive integration

This page includes:

Note: Before implementing this channel integration, contact your Customer Success Manager for FortiMail Workspace Security to make sure that this functionality is included in your current FortiMail Workspace Security license.

About the OneDrive integration

FortiMail Workspace Security can be integrated with various products. This page explains what configurations are required to integrate FortiMail Workspace Security with OneDrive. For general information about integrating FortiMail Workspace Security with other products, see Bundles and Channels.

When the FortiMail Workspace Security-OneDrive integration is fully configured, FortiMail Workspace Security will scan all the organization folders, both shared and private, each time a file is uploaded or modified. Scan details are included in the Scans page in FortiMail Workspace Security. Remember to click the OneDrive filter icon [] to show only OneDrive scans.

This page describes what must be performed by FortiMail Workspace Security Support and what must be performed by you, the customer admin - to perform the integration.

Note: By default, files up to 100 MB are scanned - larger files are not scanned. Contact FortiMail Workspace Security Support [support@perception-point.io] if you want to change this limitation.

About quarantining files in OneDrive

By default, each new FortiMail Workspace Security-OneDrive integration is configured to quarantine files. Files will be quarantined when a scan assigns a malicious verdict to a file, or when someone changes the verdict of a scan to malicious. When a file is quarantined:

  • The quarantined file is moved to the quarantine folder.

  • The quarantined file it is not accessible to the owner of the file.

  • FortiMail Workspace Security may be configured to send an email alert to the owner of the file to inform the owner that the file has been quarantined. For details, see Alerts.

  • FortiMail Workspace Security may be configured to send an alert to administrators to inform them about the quarantined file. For details, see Alerts.

  • The quarantined file is replaced by a text file in its original location. The replacement "placeholder" text file has the same name as the quarantined file, but has an additional .txt extension. For example, the placeholder file for Document-123.docx would have the name Document-123.docx.txt

    The content of the placeholder text file is similar to:

    Document-123.docx was blocked by FortiMail Workspace Security. Contact your system administrator in order to access this file.
    • You can customize the text that appears in quarantine placeholder files. You can also add links. If necessary, contact FortiMail Workspace Security Support [support@perception-point.io] to specify the customized text and the links that will appear in the placeholder files.

When an administrator releases a quarantined file [by changing its verdict to clean]:

  • An email is sent to the owner of the file to inform the owner that the file has been released from quarantine.

  • The released file will be accessible to the owner, in the original location of the file.

  • The placeholder text file is deleted.

    For details about releasing a file from quarantine, see Changing Verdicts.

Note: To disable quarantine, contact FortiMail Workspace Security Support [support@perception-point.io].

Prerequisites

In order to perform the required integration with FortiMail Workspace Security, make sure that you have the following prerequisites:

  • Microsoft 365 Business Basic

  • Administrator rights in Microsoft 365

  • Admin role in Perception Point X‑Ray

The OneDrive integration procedure

Perform the procedure below to integrate FortiMail Workspace Security with OneDrive.

Activating OneDrive

Activating OneDrive

This step activates the FortiMail Workspace Security-OneDrive integration.

To activate the OneDrive integration:

  1. In FortiMail Workspace Security, in the left navigation menu, select Settings > Bundles and Channels.

  2. Under Assigned Bundles, make sure that at least one bundle is assigned that includes the OneDrive channel.

    For example, the "Advanced Cloud Storage Security for MS Package" bundle includes OneDrive.

    Note:

    • If a bundle that includes the OneDrive channel is assigned, then OneDrive will appear in the list of channels under Enabled Channels.

    • You can click Bundles Settings, that is located on the right of each Assigned Bundle, to see which channels are included in a bundle.

  3. Under Enabled Channels, locate "OneDrive" and then click "Activate".

  4. You'll be redirected to sign-in to your Microsoft account.

  5. Sign-in to your Microsoft account as an admin. You'll see a list of the permissions that are required.

  6. Click Accept.

    Make sure that OneDrive now appears as "Active" under Settings > Bundles and Channels > Enabled Channels.

    Your FortiMail Workspace Security-OneDrive integration should now be functional.

  7. Make sure that OneDrive now appears as "Active" under Settings > Bundles and Channels > Enabled Channels.

What gets scanned

IMPORTANT: The FortiMail Workspace Security-OneDrive integration protects only the Documents folder, all sub-folders inside the Documents folder, and all files inside these folders.

FortiMail Workspace Security scans the following files in OneDrive:

  • Every file that is added by a user to the user's own drive.

  • Every file that an administrator uploads.

  • Every file that is changed by a user in the user's own drive.
    [Only the first time it is changed in a 24-hour period.]

  • Every file that is changed by an administrator.
    [Only the first time it is changed in a 24-hour period.]

Note:

  • By default, files up to 100 MB are scanned - larger files are not scanned. Contact FortiMail Workspace Security Support [support@perception-point.io] if you want to change this limitation.

  • FortiMail Workspace Security scans files that are uploaded by internal [protected] users - files that are uploaded by external [guest] users are not scanned.

  • FortiMail Workspace Security scans files that are uploaded after the integration is configured. Files that were uploaded before the integration was configured are not scanned [unless they are modified].

Flow chart diagram

Hover your cursor over the graphic below to enlarge it