SaaS Applications - Onboarding Next Steps

Learning Mode

After activating Office 365 Mail or Gmail, Avanan performs several calibration processes for the Anti-Phishing engine.

The processes include:

  • Scanning 13 months of email metadata (sender, recipient, subject, time) in users’ mailboxes to determine the communication patterns.
  • Automatic identification of MTAs placed before Microsoft or Google. It could affect SPF checks and other aspects of detection.

While these processes are running, Avanan Portal will be in Learning Mode. You can see a banner at the top of the dashboard. Also, you can see the progress of the Learning Mode in the Dashboard tab.

Note – To complete these processes, it takes a couple of minutes to 24 hours, depending on the number of protected mailboxes and the volume of their emails.

In Learning Mode, no email will be flagged as phishing or spam. All Anti-Phishing scans return Phishing Status as Clean and the Detection Reason as Learning Mode.

All other security engines work as usual in the Learning Mode and flags the malware, DLP, Shadow IT, and anomalies. Avanan automatically exits Learning Mode after the calibration processes are complete.

Note - If a Prevent (Inline) policy rule is added, Learning Mode automatically stops.

Backward Scanning

After activating the SaaS application, Avanan performs backward scanning of its content in parallel to live  scanning.

The backward scanning period for SaaS applications is as follows:

SaaS Application Scanning Period
Office 365 Email
  • For accounts up to 500 users: 14 days
  • For accounts with more than 500 users: No backward scanning
Note - Backward scanning starts only after Learning Mode is completed.
Gmail
Office 365 OneDrive 14 days *
Google Drive 30 days
Slack No backward scanning
Microsoft Teams No backward scanning
Office 365 SharePoint 14 days *
Citrix ShareFile 14 days
Dropbox 14 days
Box 14 days
* For Office 365 OneDrive and Office 365 SharePoint, Avanan finds the file that was last updated and takes its date as a reference. Then, it inspects all the files that were updated in the 14 days leading to that reference date.

Note - If you need backward scanning for your accounts or to extend the backward scanning period, contact Avanan Support.

Live Scanning

After activating the SaaS application, Avanan starts scanning all the files and emails for any threats in real-time.

The Dashboard (Security Overview) page shows the security events found if any. At the bottom of the overview screen, you can see the status of active scans of your SaaS applications. Depending on the amount of data, this stage may take time.

Note - The number of active users may exceed the number of licensed users in the SaaS and does not necessarily reflect the number of Avanan licenses required.

Click Active users to review the list of users. This opens a query in the Custom Queries under Analytics & Reports tab.

For example, in Office 365, Shared Mailboxes do not require a separate license in Avanan but are counted as active users.

Note - By default, after activating a SaaS application, policies get created for threats (phishing and malware).
For DLP, there is no default policy.