Barracuda, Microsoft 365, and Azure AD
Impersonation Protection monitors licensed Microsoft 365 mailboxes.
Note that in hybrid email deployments, Impersonation Protection only monitors Microsoft 365 mailboxes; Impersonation Protection does not monitor mailboxes that are part of on-premises solutions.
For Account Takeover suspicious sign-in data, Barracuda Networks requires full Azure AD (Active Directory) tenants. It does not always receive sign-in data from hybrid environments that include both on-premise active directory and Azure AD.
Logging in for the First Time and Connecting Your Microsoft 365 Account
Complete the following steps to enable Impersonation Protection to protect your Microsoft 365 account:
Navigate to https://sentinel.barracudanetworks.com.
If you do not already have a Barracuda account – Enter your email, create a password, and click Get Started. Provide information for your account and click Get Started.
If you have a Barracuda account – Enter your email and password and click Sign In.
Note that for your first login, Barracuda Networks requires a linking code, but does not require a serial number.
Click Connect to Microsoft 365. Optionally read about the permissions needed.
When Microsoft 365 opens, log in as a global tenant administrator.
Review the permissions required by Barracuda and click Accept.
After you sign up, Barracuda will take anywhere from several hours to several days (depending on the size of your account) to fully learn your environment. After the initial learning phase is completed, you will receive an email notifying you that Impersonation Protection is now available.
Managing Users
Manage users who have administrative access to your Barracuda account within Barracuda Cloud Control.
To add or remove users:
Go to http://login.barracudanetworks.com and sign in.
Navigate to Home > Admin > Users.
Perform the desired action:
To add a user, click Add Users.
Specify the information for the user, following the instructions in How to Add Users and Configure Product Entitlements and Permissions. Be sure to specify entitlements for Impersonation Protection for all users that need access to Impersonation Protection.To remove a user, select an existing user and click Remove User.
Seamless Connection to Automatic Remediation and Incident Response
You can access your licensed or trial version of Automatic Remediation (and Incident Response, if purchased) directly from here. Click the menu button in the top left corner of the page and select Automatic Remediation or Incident Response.
If you already have a licensed or trial version of Automatic Remediation (and optionally Incident Response), it will open in a new browser tab.
If you do not yet have a license or trial for Automatic Remediation (and optionally Incident Response), a sign-up page displays. You can sign up for a license or free trial on that page.
If you purchased Incident Response: When viewing the details of an attack, you can click Search for Similar Messages to open Incident Response to locate incidents similar to the one you are currently viewing.