Jump to:navigation, search
Wiki





























{{var | neu--Azure | Authentifizierung mit OAuth 2 | [[#Create e-mail domains | Authentication with OAuth 2 }}

De.png
En.png
Fr.png






Last adaption: 01.2023
New:
  • Hinweis, zum Import von E-Mails
notempty
This article refers to a Resellerpreview

3.1.4

Access: UMA-IP:Port or UMA-URL:POrt
z.B.: https://uma.ttt-point.de:11115
Default: https://192.168.175.254:11115
System Settings



Reasons for using UMA as a Service

Managed services in IT security is much more than just offering technical solutions. Managed service means being able to offer a defined service for small environments both cost-effectively and with high availability at no cost for your own infrastructure.

UMA as a Service offers these advantages to your customers:

  • Legal advantages:
    • Signing of emails and documents with qualified time stamps
      (manipulation-free and court-proof archiving.)
    • Audit-proof email archiving to the highest standards
    • Compliance with legal requirements,
      • GoBD (Grund­sät­ze zur ord­nungs­mä­ßi­gen Füh­rung und Auf­be­wah­rung von Bü­chern, Auf­zeich­nun­gen und Un­ter­la­gen in elek­tro­ni­scher Form so­wie zum Da­ten­zu­griff / Principles for the orderly keeping and retention of books, records and records in electronic form and for data access)
      • German Commercial Code (HGB)
      • German Tax Code (AO, Abgabenordnung)
      • Basel II
      • BSI TR 03125 (Technische Richtlinie des Bundesamt für Sicherheit in der Informationstechnik / Technical guideline of the Federal Office for Information Security, national cyber security authority in Germany)
    • Rule-based storage
    • Automatic storage based on legal archiving periods
  • Operational advantages:
    • Increases the performance of an existing mail server and releases storage capacity by outsourcing historical emails.
    • Powerful search engine for emails and documents
    • Sorting, categorization and indexing of emails and documents
    • Permanently reduces email storage costs by rule-based deletion of unneeded emails.
    • Data backups are significantly simplified with UMA


In addition, UMA as a Service offers the following advantages for resellers:

  • It is multi-client capable for up to 50 customers.
  • Provision of up to 500 mailboxes
  • Optimization for Office 365
  • No change to the customer's infrastructure is necessary


Securepoint supports you with these services:

  • Complete provision
  • Journal email mailboxes
  • backup
  • monitoring
  • Updates and Support

Organizational requirements

UMA v3.1 Dashboard UMAaaS-en.png
For the use of a UMAaaS environment, forwarding of all incoming and outgoing e-mails is necessary! Note the point "Kann das UMA auch ohne Mailserver verwendet werden?"

The Managed Service "UMA as a Service" can be ordered either via the TERRA CLOUD Center or via the api Cloud.

  • For an order in the TERRA CLOUD Center, the account there must be linked to a corresponding Securepoint Reseller Account. This is configured in the settings (gearwheel at the bottom left) under "My additional services" → "Securepoint".

    After successful linking you will find our products under: "TERRA CLOUD" -> "Security as a Service". If you have any further questions regarding the ordering process, please contact the WORTMANN AG Security Team (e-mail: security@wortmann.de). Please use only the URL www.terracloud.de for orders.

  • For an order via api Cloud the account there must be linked with a corresponding Securepoint Reseller-Account. This can be configured in the settings (gearwheel at the bottom left) under "My additional services" > "Securepoint".

    If you have further questions about the order process, please contact the api Security Team (e-mail: security@vad4u.de).

The service is provided by the company Wortmann AG and hosted on their servers in Germany and configured and maintained by Securepoint.
If the service is provided, a mail with the required credentials will be sent.
The password for administrator access is communicated by telephone and must not be changed! We need the credentials for the maintenance of the Managed Service (updates, monitoring etc.) !

  • Der Import von E-Mails in das UMAaaS ist ein kostenpflichtiger Service.
    Dieser kann über die Terra Cloud, die api Cloud oder direkt über Securepoint gebucht werden.


  • Configuration

    Create e-mail domains

    System Settings Tab Mailserver

    By default, email addresses are provided for receiving mails for archiving under the domain archiv.securepoint.cloud. This access is already preconfigured.
    Additional domains can be added whose access must be configured in the Remote email accounts section.

    Remote Mailserver settings UMAv3.3 System-Einstellungen E-Mail-Server Remote-E-Mail-Server-Einstellungen-en.png
    Email domains: ttt-point.onmicrosoft.com
    Example for Office 365 domain
    Submit email domain with add See also the wiki article on Office 365 accounts.
    In order to archive an email for an account, the complete email domain must be stored here.



    The administration center allows further settings, which should however not be changed in any case without consulting our support.
    Remote email accounts
    Changes only after consultation with our support!
    Remote Smarthost Settings
    Not configured
    Remote email accounts UMAv3.3 System-Einstellungen E-Mail-Server Remote-E-Mail-Konten-en.png
    At this point, the central mailbox is configured where all emails to be archived arrive.
    The assignment to individual users with their mail addresses is done in the Accounts tab or UMA NG v3 (New or Upgrade from June 15, 2020): on the Mail Accounts . With Add account additional mailboxes can be configured.
    Name: Xnnnnn Name of the connection to the server Assigned by Securepoint
    Protocol: Auto The protocol used (POP3 or IMAP) with which the UMA collects the emails from the mail server. With the AUTO option, the UMA automatically searches for the protocol used on the mailserver.
    OAuth 2 (IMAP) An existing OAuth 2 connection is required to use the OAuth 2 protocol. Further information in the Wiki article Azure Apps with OAuth for the UMA.
    Exclusively possible for individual users
    Servername: imap.archiv.securepoint.cloud Address of the server on which the mails to be archived arrive. Wird von Securepoint vergeben
    Username: Xnnnnn
    Password: •••••• Password for logging on to the server on which the mails to be archived arrive.
    Fetch Mails Every: 1 Minute (Default) Frequency with which the mails are collected
    Keep Mails: Usually, e-mails are deleted after they have been collected. Activating Keep Mails prevents this deletion.
  • When activated, external mailboxes can fill up!
    Keep Mails should only be used temporarily for test purposes, or if it is otherwise ensured that the external mailbox does not reach its capacity limit.
  • SSL: Required
    Max. E-Mail Size: Disabled Can be set between disabled and 1- 100MB.
    email Header Evaluation: Enable MS Journal-Envelope autodetection
    default
    The recognition of the header entries "MS journal envelope" enables the UMA BCC recipient to recognize in the Exchange-own header and assign it to a user account.
    BCC recipients are not in the original mail header
      
    Disable MS Journal-Envelope autodetection Uses the original header of the email to assign it to a user account
    X-Envelope-To Uses only the X-Envelope-To entry from the original header of the email to assign it to a user account
    X-Original-To Uses only the X-Original-To entry from the original header of the email to assign it to a user account
    Delivered-To Uses only the Delivered-To entry from the original header of the email to assign it to a user account
    Custom Recipient Header A custom defined header part to be evaluated.
    Example: envelope-from


    Configuring User Accounts

    System Settings Tab Mail Accounts

    User Repository
    User repository UMAv3.3 System-Einstellungen E-Mail-Konten Benutzer-Repository-en.png
    Local users
    Local users
    Only local user lists can be used.
    To be able to use AD or LDAP directory services an UMA as Hardware or VM is necessary.

    Local users
    Add user
    Add user
    Add user
    User-ID: Username for access to the UMA email archive. ( user-definable)
    The username cannot be changed later anymore.
    We recommend absolutely to provide the username with a customer-specific prefix. This ensures an overview when displaying the accounts and avoids problems with identical names!
    UMAv3.3 System-Einstellungen E-Mail-Konten Lokale-Benutzer-hinzufügen-en.png
    Password: Password, for access to the UMA e-mail archive
    First Name: First name of the user
    Last Name: User's last name
    Email: Mail address to which the user has access, e.g.: user@ttt-point.onmicrosoft.com . Here several addresses can be defined with hinzufügen.
    In order for the emails to be archived, the corresponding mail domain (here: ttt-point.onmicrosoft.com) must be entered under / Remote Email Server Settings.
    Save Completion of the process
    CSV Import
    CSV Import
    A .csv file with the following format can be imported: User ID, password, first name, last name, email, further email
    Any number of email addresses can be specified.
    The content of the .csv file must be UTF-8 encoded and without header line.
    Browse Selecting an Import File
    Import Completion of the process
    CSV Export
    CSV Export
    Download The user list can be exported with the following information:
    User ID, password, first name, last name, e-mail, other e-mail addresses
    The content of the .csv file is UTF-8 encoded and without headers.

    Archived user accounts

    Archived user accounts
    Enable manual select UMAv3.3 System-Einstellungen E-Mail-Konten Lokale-Benutzer-en.png
    Choosing this option allows you to restrict archiving to individual accounts.
    When removing mail accounts from archiving, it must be noted whether legal regulations on storage are affected!
    On When activated, the selected user account is archived. This can be done either for specific accounts or for all accounts.
    The user accounts to be archived are listed in Archived User Accounts.
    User Search     Immediately filters the displayed accounts for contained characters.