> Source: [sk103721](https://support.checkpoint.com/results/sk/sk103721)

# sk103721 - Configuring an Office 365 Capsule Workspace Account

| Property | Value |
|----------|-------|
| Solution ID | sk103721 |
| Date Created | 2014-12-14 |
| Last Modified | 2023-02-08 |
| Technical Level | General |
| OS | Android, iOS |

## Solution

The following instructions allow Check Point Capsule Workspace mobile app to connect to an Office 365 account's Web services via a Mobile Access gateway.

### Requirements

* Either a local Microsoft Active Directory server or an Azure-based directory service.  

  **Important:** OAuth 2.0 SSO to an Azure-based directory requires an R81.20 or later Mobile Access gateway. Relevant configuration instructions appear in the [R81.20 Mobile Access Administration Guide](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/Exchange-Mail-Applications-for-Smartphones-and-Tablets.htm?Highlight=OAuth%202.0). Older gateway versions support only 'basic' SSO to the cloud service.

* If the customer is NOT using a Microsoft Active Directory, the feature works with internal users as well.

* A Management Server R77.30, or R80.10 and above.

* A Mobile Access gateway R77.30, R80.10 and above with access to the AD server and the Internet.

* A mobile device with Capsule Workspace app installed.

* Access to SmartDashboard R77.30, SmartConsole R80.10 and above and GuiDBedit Tool.

### Instructions

1. Unless you already have a valid Office 365 account: On the Web, configure an Office 365 [Business Premium Trial](http://www.microsoft.com/office365) account.

2. On the AD server, configure a user with the same settings as the ones used for the Office 365 account:

   1. The username and password must be identical.

   2. The account's 'E-mail' field must be in the form of:

      *username@myofficeaccount.onmicrosoft.com*
      (According to the username and domain name specified in the Office 365 account)

   Alternatively, configure an internal user whose username is in the form of:
   *username@myofficeaccount.onmicrosoft.com*
3. If an AD server is used, then:

   * Management Server R77.30 requires the [R77.30 Management Add-on](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105412) to be installed and enabled
   * For Management Server R80.x, no plugins needed.
4. In SmartDashboard / SmartConsole, configure a Capsule Workspace Mail application (in in SmartDashboard R77.20, it is called "Secure Container Mail"):

   1. In the 'General' -\> 'Exchange' Server field, type:  
      *outlook.office365.com*   
      and leave the default port (443) as is.  

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/4-A1902200531.JPG)

   2. On the 'Exchange Access' tab, make sure the box 'Use encryption' is checked.  

      ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/4-B C1902200532.JPG)

   3. Check the 'Use specific domain' setting, and configure the domain specified in the Office 365 account.

      Example:  
      *myofficeaccount.onmicrosoft.com*
      **Note:** the dialog part of the SSO settings remains as default.
5. If a local AD is used for authentication, then create an LDAP Account Unit and configure the AD server as the Account Unit's LDAP Server.  

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/5 A1902200534.JPG)

   Proceed to create an LDAP user group for the newly-created LDAP Account Unit.  
   If a local user is used, then create a local user group instead.  

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/5 B1902200538.JPG)
6. On the Mobile Access '`Policy`' page, allow the user group created above access to the newly-configured Secure Container Mail application.  

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/61902200542.JPG)

7. Save your settings and close SmartDashboard / SmartConsole.

8. Connect with [GuiDBedit Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk13009) to Security Management Server / Domain Management Server.

9. Locate the Secure Container Mail application object.

10. It its settings, change the '`authentication_method`' to `Basic`.  

    ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/101902200545.JPG)

11. If an AD server is used, then modify the SSO format of the same object to '`email`' syntax (`$$user@$$domain`) according to the instructions in the Mobile Access Administration Guide ([R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24851), [R80.10](http://downloads.checkpoint.com/dc/download.htm?ID=53103), [R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_MobileAccess_AdminGuide/html_frameset.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_MobileAccess_AdminGuide/html_frameset.htm)).  
    Note: If the attributes mentioned in the instructions are missing, then something went wrong in Step (3).  

    ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk103721/111902200546.JPG)

12. Save your settings, and close the GuiDBedit Tool.

13. Reconnect with SmartDashboard / SmartConsole, and install the policy.

14. Configure the Mobile Access gateway as a "Site" in the Capsule Workspace app, and authenticate as the Office 365 user.  
    The Office 365's mail content appears under the '`Inbox`' icon.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
