Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents

Summary

The INKY auto-onboarding was designed and created with MSPs in mind to provide an easy way to deploy INKY to the MSP’s customers. You will find this to be an easy 3 stage process for your convenience. Starting with License Registration followed by License Redemption and lastly then Tenant Installation. You should be able to complete start to finish within 30 15 minutes!

Info

Note: This deployment is for O365 customers only!

...

  • The MSP team needs to be elevated to a PARTNER ACCOUNT.

  • The admin performing the deployment must have INKY SUPER ADMIN access for the MSP – ALL TEAMS account

  • The admin performing the deployment must have Global Admin rights in O365

  • The new account can only be setup on the INKY US grid at this time.

STAGE 1: License Registration

Step 1: Open a browser and go tohttps://licensing.inkyphishfence.com/generate INKY Partner Center

Step 2: Log in using your INKY Admin single-sign-on authentication

...

Step 3: License Registration

...

...

is done by clicking Generate License

...

  • Pick the products that you are installing in addition to INKY Phish Fence

  • Domain: (required) Please choose what partner this license should be associated with.

  • Parent Team: (optional) Select a related partner team to become the direct parent of the team created with this license. If none is selected, the parent will default to the issuing partner.

 

Step 4: Select product features that your client should be licensed for

...

Step 5:

  • Provide the number of mailboxes to be protected by Inky

Info

INKY licenses are required for each individual user with a o365 licensed mailbox that will be passing email through the INKY platform. You do not need an INKY license for shared mailboxes / distribution groups / alias email addresses. Please contact your INKY account rep for further assistance/clarification.

  • Provide a name for your customer (Team Name)

...

Step 6: Generate License Key

...

  • Enter the primary domain of the M365 tenant as domain.com

    • All subdomains, secondary domains, and m365 domains will be populated in INKY during the installation

  • Team Label: (required) Enter the Team Label that you would like to see as a child team

Step 4: Generate License Key

...

You will then be provided with a License Key and URL

...

STAGE 2: License Redemption

Step 1: Copy Take the Redemption Link copied link provided and paste into a new private/incognito browser

...

Click Continue

Step 2: You will now log into the CUSTOMER’S O365 tenant with your Global Admin account

...

Click Sign in

Step 3: Accept the O365 prompt for Admin consent for INKY to configure read access for Directory Sync in the customer’s O365 tenant

...

Step 4: Authorize the installation of INKY into the customer’s O365 tenant

...

Click ‘copy to clipboard and then click the blue button to ‘open device log in page’.

 

Step 5: You will now paste the code that was copied and click next

...

You will then again be prompted to authenticate with your Global Admin Account for the Customer’s O365 tenantConsent to Remediation API Access via the Graph API:

...

Step 5: Consent to Exchange PowerShell Permissions:

...

STAGE 3: Tenant Installation

Step 1: Click the ‘start’ button to begin the install

...

Step 2: Review results of INKY install

...

  • Be sure to review the details. Confirm your MX record data as you may have outdated lower priority routes still listed.

  • Review your transport rules to ensure there are no rules that will conflict with INKY rules. Especially rules that have the option to ‘stop processing more rules’ option enabled.  – Please reach out to your account team if you need any assistance reviewing this.

...

Once ready, click ‘CONTINUE’

 

Step theContinue

 Step 3: User Notification is always key to avoid deployment confusion when end users see changes in their day-to-day operations. This next screen provides you with options to download documentation to help you make the announcement to your organization of the changes to come once you begin to add more members to the IPW Group in O365.

...

The ‘start processing messages in x minutes’ can be is set to 0. With recent INKY developments, we have increased our backend propagation for faster deployment. Please note that O365 will still have its own propagation to complete and may delay the initial changes to your mail flow30 minutes by default. This will provide ample time to set the tenant into silent mode after installation. Instructions are below for post-installation tasks.

You can now click ‘continue’ to proceed.

 

Step  Step 4: For the next few moments you will view the Installation Progress Bar

...

INKY will give a line-by-line progress of the installation in this window:

...

Congratulations, Installation is now completed successfully!

...

Step 5: When you are ready you can now add users to your IPW-Group or IPW-Group-Silent group as needed. You will also need to configure your customer settings in the INKY team admin portal.

During the install process a Dynamic Distribution Group is created named “IPW-Dynamic-All” add that dynamic group to your IPW-Group to ensure all current and future accounts are automatically added to INKY.

Optional: Grant Remediation access which allows actions via the dashboard, such as removing dangerous or unwanted messages from user mailboxes.Post-installation you will want to place the tenant into Silent Mode. You will do that by clicking Visit Dashboard at the end of the installation.

In the Dashboard go to Admin Center → Markup and opt the tenant into Silent Mode:

...

Optional (recommended): Add the INKY macro-SPF record to the clients' DNS:

exists:%{i}._spf.inkyphishfence.com

This record will authenticate all INKY transactions between M365 and the INKY Security Cloud

Info

Again, for any assistance please reach out to your account team or open a support ticket by sending an email to Support@Inky.com.

...