Proofpoint Essentials

Import your Proofpoint Essentials organization's domains, mail servers, website, and active users into Guard.

The Proofpoint Essentials integration imports your email security footprint from Proofpoint Essentials into the Praetorian Guard Platform (PGP). Guard reads your organization, its domains, and its mail servers through the Proofpoint Essentials API and adds them as assets, along with your active users. This guide walks you through connecting Proofpoint Essentials to Guard.

What the integration does

Each time the integration runs, Guard signs in to Proofpoint Essentials, confirms it is reading the organization you configured, and imports:

  1. Domains: your organization's primary domain and every other domain registered to it.
  2. Mail servers: each domain's delivery destination and failover servers, linked to that domain, and your organization's outgoing mail servers. Proofpoint Essentials service hosts, such as us1.proofpointessentials.com, are skipped.
  3. Website: your organization's website, as recorded in Proofpoint Essentials, as a web application. Guard imports it only when it is an http:// or https:// address.
  4. Users: the email address and name of each active user. Silent users and functional accounts are skipped.

Guard also drops domains and mail servers it should not scan:

  • Loopback, link-local, multicast, and unspecified addresses.
  • IP addresses in public cloud provider ranges, and domains that resolve to a public cloud provider, such as a cloud-hosted mail server.
  • Private IP addresses, such as 10.0.0.0/8 or 192.168.0.0/16, and domains that do not resolve in public DNS.
  • Any IP address, public or private, that does not answer a single ping within half a second.

This filter does not apply to the website. To import private and non-responding assets, contact Praetorian support.

The integration only reads from Proofpoint Essentials. It does not change users, domains, or filtering settings.

Prerequisites

  • A Proofpoint Essentials organization and its primary domain, for example example.com.
  • The username and password of a Proofpoint Essentials administrator account that can use the API for that organization.
  • Permission to add integrations in Guard.

Connect Proofpoint Essentials in Guard

  1. In Guard, go to Integrations and open Managed Detection and Response → Proofpoint Essentials.
  2. Enter:
    • Customer / Tenant Domain: your organization's primary domain in Proofpoint Essentials, for example example.com.
    • API Username: the administrator's username, for example api-user@example.com.
    • API Password: the administrator's password.
  3. Click Connect.

Before saving, Guard looks up the Proofpoint Essentials stack that serves your domain, signs in with the username and password, and checks that the organization Proofpoint returns has the primary domain you entered. If any check fails, Guard shows the error and does not save the integration. Guard repeats these checks at the start of every run.

Verify the integration

After the first run, go to Assets and search for your primary domain. It should appear as an asset, along with the mail servers it delivers to.

Troubleshooting

Message

What to do

Missing Required Field

Enter the tenant domain, API username, and API password.

Invalid Format: Proofpoint primary domain must be a valid DNS domain

Enter only the domain, such as example.com, with no https://, path, or email address.

Invalid Format: Proofpoint endpoint discovery returned no endpoints

Check that the domain is your organization's primary domain in Proofpoint Essentials.

Invalid Format: endpoint discovery returned too many endpoints, or an untrusted endpoint

Guard found no single trusted Proofpoint Essentials stack for the domain. Contact Praetorian support.

Authentication Failed

Check the username and password, and that the account can use the Proofpoint Essentials API.

Insufficient Permissions: the credentials authenticated successfully but cannot read the configured organization

Use an administrator account that manages this organization.

Invalid Format: Proofpoint did not return the configured Proofpoint organization

The domain you entered is not the organization's primary domain, or the account does not manage it. Enter the primary domain of the organization the account manages.

Invalid Format: Proofpoint returned an invalid configured organization

Proofpoint returned the organization without a name or a valid primary domain. Check the organization's details in Proofpoint Essentials.

Validation Failed: Proofpoint Essentials returned HTTP 400 or 404 during validation

Check the domain, username, and password.

Connection Failed: Could not reach the Proofpoint Essentials API

Guard could not connect to Proofpoint. Try again later.

Mail servers are missing from Assets

They may be hosted by a cloud provider, not resolve in public DNS, be private, or not answer ping.

The website is missing

It is not recorded in Proofpoint Essentials, is not an http:// or https:// address, or is a Proofpoint Essentials host.

If you need help with this integration, contact support@praetorian.com.