Securing the Microsoft 365 Application Endpoint Host
This section provides instructions on how to improve the security of the Microsoft 365 Application Endpoint Host.
- Log on to the Microsoft 365 Application Endpoint Host as an administrator.
- Make sure the IP and Domain Restrictions role service is installed for the Web Server (IIS) role. See the http://www.iis.net/ConfigReference/system.webServer/security/ipSecurity article for details.
- Open Internet Information Services (IIS) Manager.
-
For each Microsoft 365 gateway application, perform the following actions:
- In the navigation tree, select the Microsoft 365 gateway application.
- Double-click the IP Address and Domain Restrictions icon.
- Click the Edit Feature Settings link.
- Select Deny in the Access for unspecified clients field.
- Click OK.
- Click the Add Allow Entry link.
- Select the Specific IP address option.
- In the field, specify the BackNet IP address of the Operations Management Node that corresponds to the Microsoft 365 gateway application.
- Click OK.
- Validate that the
https://<Microsoft_365_Gateway_Site>/<Microsoft_365_Gateway_Application>/aps/
URL is accessible only from the Operations Management Node.
Important: If you have additional management nodes on your installation, add the respective allow item for each of them by using the instructions above.