Enterprise Vault™ Setting up Exchange Server and Office 365 for SMTP Archiving
- Configuring Exchange Server for an Enterprise Vault SMTP Archiving solution- About using Enterprise Vault SMTP Archiving for Exchange Server journaling
- Summary of steps
- Creating a remote domain using the Exchange Management shell
- Creating a recipient mail contact in the remote domain
- Creating a Send Connector for the remote domain
- Setting up Exchange Server journaling
- Points to note when setting up Enterprise Vault SMTP Archiving servers
 
- Configuring Office 365 for Enterprise Vault SMTP Archiving
- Configuring the Azure RMS Decryption feature for Office 365 email encryption support- About configuring the Azure RMS Decryption feature for Office 365 email encryption support
- Summary of steps
- Configuring IRM settings for journal report decryption in your organization
- Getting the Rights Management configuration details of your Azure tenant
- Creating a new service principal that represents your tenant to external applications
- Adding the service principal to the list of superusers for your organization
- Installing Microsoft Right Management Services Client 2.1
- Configuring the decryption of RMS-protected messages in Enterprise Vault
 
- Configuring decryption of MPIP-protected Office 365 emails archived in Enterprise Vault- About configuring the MPIP decryption feature in Enterprise Vault
- Summary of steps
- Disable decryption of journal report in your organization
- Register an application with the Azure Active Directory
- Assign the required permissions to an application
- Upload certificates
- Configure decryption of MPIP-protected emails in Enterprise Vault
 
Register an application with the Azure Active Directory
To enable Enterprise Vault to decrypt Microsoft Purview Information Protection (MPIP) protected emails, you must first register it with the Azure Active Directory. Registering the application establishes the trust relationship between the Enterprise Vault and the Microsoft identity platform.
Perform the following steps to register the application:
Note:
Ensure that you have an Azure Account with an active subscription.
- Open the Azure Portal (https://portal.azure.com/) by entering the credentials which have access to register application. - Depending on the configuration of your tenant, you may also need to be a member of the "Global Administrator" directory role to register the application. 
- Select from the Azure services. 
- On the left navigation pane, select . 
- Click . 
- Enter the user-facing display name for the application and click . - Note: - Ensure that all the other values on the is the same as displayed in the above image. 
- Navigate to the section and find your and . - Note: - Make a note of the and , which are required for enabling decryption of the MPIP-protected emails in Enterprise Vault.