Microsoft 365 Exchange Online traffic inspection from Outlook clients
Hello!
We have a Fortigate 60F running latest mature (7.2.8) FortiOS. We would like to inspect (as much as possible) email traffic, ie around 10 users accessing Exchange Online via latest Outlook clients on Windows and using default protocols (MAPI over HTTPS?). We are clear on how to inspect IMAP/POP3/SMTP traffic, but not sure how to handle Exchange Online default protocol. Fortigate docs mention RPC over HTTP (should be deprecated for Exchange) as well as MAPI. Is MAPI the way to go. If so, how should we configure policies, profiles etc. to separate from the rest of HTTP/Microsoft traffic and make sure email and antivirus detections/profiles are applied.
Also, while 7.2.8 still makes it possible to enable proxy-based policies and profiles (MAPI inspection not supported in flow-based), what is the way forward for M365 Excange Online inspection on < 2GB RAM devices for smaller networks?
Any advice is welcome. Thanks!
