Proofpoint Essentials
Import your Proofpoint Essentials organization's domains, mail servers, website, and active users into Guard.
The Proofpoint Essentials integration imports your email security footprint from Proofpoint Essentials into the Praetorian Guard Platform (PGP). Guard reads your organization, its domains, and its mail servers through the Proofpoint Essentials API and adds them as assets, along with your active users. This guide walks you through connecting Proofpoint Essentials to Guard.
What the integration does
Each time the integration runs, Guard signs in to Proofpoint Essentials, confirms it is reading the organization you configured, and imports:
- Domains: your organization's primary domain and every other domain registered to it.
- Mail servers: each domain's delivery destination and failover servers, linked to that domain, and your organization's outgoing mail servers. Proofpoint Essentials service hosts, such as
us1.proofpointessentials.com, are skipped. - Website: your organization's website, as recorded in Proofpoint Essentials, as a web application. Guard imports it only when it is an
http://orhttps://address. - Users: the email address and name of each active user. Silent users and functional accounts are skipped.
Guard also drops domains and mail servers it should not scan:
- Loopback, link-local, multicast, and unspecified addresses.
- IP addresses in public cloud provider ranges, and domains that resolve to a public cloud provider, such as a cloud-hosted mail server.
- Private IP addresses, such as
10.0.0.0/8or192.168.0.0/16, and domains that do not resolve in public DNS. - Any IP address, public or private, that does not answer a single ping within half a second.
This filter does not apply to the website. To import private and non-responding assets, contact Praetorian support.
The integration only reads from Proofpoint Essentials. It does not change users, domains, or filtering settings.
Prerequisites
- A Proofpoint Essentials organization and its primary domain, for example
example.com. - The username and password of a Proofpoint Essentials administrator account that can use the API for that organization.
- Permission to add integrations in Guard.
Connect Proofpoint Essentials in Guard
- In Guard, go to Integrations and open Managed Detection and Response → Proofpoint Essentials.
- Enter:
- Customer / Tenant Domain: your organization's primary domain in Proofpoint Essentials, for example
example.com. - API Username: the administrator's username, for example
api-user@example.com. - API Password: the administrator's password.
- Customer / Tenant Domain: your organization's primary domain in Proofpoint Essentials, for example
- Click Connect.
Before saving, Guard looks up the Proofpoint Essentials stack that serves your domain, signs in with the username and password, and checks that the organization Proofpoint returns has the primary domain you entered. If any check fails, Guard shows the error and does not save the integration. Guard repeats these checks at the start of every run.
Verify the integration
After the first run, go to Assets and search for your primary domain. It should appear as an asset, along with the mail servers it delivers to.
Troubleshooting
If you need help with this integration, contact support@praetorian.com.