Exchange Server (Graph)
Use the Exchange Server (Graph) source configuration screen to crawl and classify multiple Exchange mailboxes in the same tenant. The Graph source type connects only to Exchange Online. To crawl mailboxes on an on-premises Exchange server, use Exchange Server (EWS).
You can use Match Rules to include or exclude specific mailboxes.
To configure an Exchange Server (Graph) source, follow these steps.
Step 1 – In Netwrix Data Classification management console, open the Sources view and click Add.
Step 2 – Select Exchange Server (Graph) source type and in the properties window specify the necessary settings.
Step 3 – To display all settings, click the "wrench" icon next to Settings in the bottom-left corner.
Authentication
You must specify the following:
| Option | Description |
|---|---|
| Admin Username | Specify the administrative account for the required Exchange Online organization. The user must have a mailbox connected to it to crawl Exchange. |
| Tenant ID | Enter the Tenant ID you obtained at Step 5: Obtain Tenant ID. |
| Certificate thumbprint | Enter the certificate thumbprint you prepared at Step 4: Configure Certificates & secrets. |
| Application ID | Enter the app ID you got at application registration at Step 2: Create and Register a new app in Azure AD (you can find it in the Azure AD app properties >Overview). See Configure Microsoft Exchange for Crawling and Classification for details of the permissions to grant to the application. |
Other configuration settings
Specify the following settings:
| Option | Description |
|---|---|
| Cloud Environment | Select the Azure environment that hosts your Exchange Online tenant. |
| Crawl Range | Define which portions of data to retrieve from Exchange Online:
|
| Match Rules | Define rules with regular expressions to limit which mailboxes the product crawls. You must define at least one match rule. Examples: 1. .*@netwrix.com— enter the wildcard (.*) and the domain (here netwrix.com) to restrict crawling to a set of domain mailboxes 2. .*—enter to crawl all mailboxes. |
| Detection Period | Specify how often to check the source for changes. Default period is 1 day. |
After specifying all the necessary settings, click Save.