- play_arrow Overview
- play_arrow Juniper Advanced Threat Prevention Cloud Overview
- play_arrow Juniper Advanced Threat Cloud Prevention Setup
-
- play_arrow Juniper ATP Cloud Web Portal
- play_arrow Juniper ATP Cloud Web Portal Overview
-
- play_arrow Enroll SRX Series Firewalls in Juniper ATP Cloud Web Portal
- play_arrow Enroll and Manage SRX Series Firewalls
-
- play_arrow Monitor Juniper ATP Cloud Features
- play_arrow Reports
- play_arrow Hosts
- play_arrow Identify Infected Hosts
- play_arrow Threat Sources
- play_arrow Identify Hosts Communicating with Command and Control Servers
- play_arrow IoT Device Discovery and Classification
- play_arrow Reverse Shell
- play_arrow Files
- play_arrow E-mails
- play_arrow Statistics
- play_arrow DNS
- play_arrow Encrypted Traffic Insights
-
- play_arrow Administration
- play_arrow Juniper ATP Cloud Administration
- Modify My Profile
- Create and Edit User Profiles
- Set Password
- Application Tokens Overview
- Create Application Tokens
- Multi-Factor Authentication Overview
- Configure Multi-Factor Authentication for Administrators
- Set Up Single Sign-on with SAML 2.0 Identity Provider
- Configure SSO Settings
- View Audit Logs
-
- play_arrow More Documentation
- play_arrow ATP Cloud Tech Library Page Links
-
Emails: Configure IMAP
To access this page, navigate to Configure > Emails > IMAP.
Read the Emails Overview topic.
Decide how malicious emails are handled. For IMAP, the available options are to block or permit email. Unlike SMTP, there is no quarantine option for IMAP and no method for previewing a blocked email.
- Select Configure > Emails > IMAP.
- Based on your selections, configuration options will vary. See the tables below.
Setting | Guideline |
---|---|
Action to take |
When you select to block email attachments, in place of the original email, intended recipients receive a custom email you configure with information on the block action. Both the original email and the attachment are stored in the cloud in an encrypted format. |
IMAP Server |
When you add IMAP servers to the list, it is sent to the SRX Series Firewall to filter emails sent to Juniper ATP Cloud for scanning. For emails that are sent for scanning, if the returned score is above the set policy threshold on the SRX, then the email is blocked. |
IMAP Servers | Select the Specific IMAP Server option above and click the + sign to add IMAP server hostnames to the list. Note: You must use the IMAP server hostname and not the IP address. |
Email Notifications for End Users | |
URL to learn more about Policy | If you have a corporate web site with further information for users, enter that URL here. If you leave this field blank, this option will not appear to the end user. |
Subject | When an email is blocked, the recipient receives a custom message informing them of their blocked email. For this custom message, enter a subject indicating a suspicious email sent to them has been blocked, such as "Malware Detected." |
Custom Message | Enter information to help email recipients understand what they should do next. |
Custom Link Text | Enter custom text for the Juniper ATP Cloud quarantine portal link where recipients can preview blocked emails and take action on them. |
Buttons |
|
Administrators Who Receive Notifications
To send notifications to administrators when emails are blocked or released from quarantine:
Click the + sign to add an administrator.
Enter the administrator's email address and click OK.
Once the administrator is created, you can uncheck or check which notification types the administrator will receive.
Block Notifications—When this check box is selected, a notification is sent when an email is blocked.
Unblock Notifications—When this check box is selected, a notification is sent when a user releases a blocked email.