Disabling Forefront Online Protection for Exchange

 

Applies to: Forefront Protection for Exchange

Important

This article is intended for Forefront Online Protection for Exchange (FOPE) administrators and requires a cancellation order in addition to updating specific DNS and firewall settings.

In order to disable Forefront Online Protection for Exchange (FOPE), you need to revert the configuration changes you made when provisioning FOPE in your environment.

To disable Forefront Online Protection for Exchange

  1. Start a cancellation order by contacting the appropriate FOPE representative. If you purchased through a Service Provider Licensing Agreement (SPLA) or Telco partner, contact that partner to start the cancellation process.  If you purchased through Volume Licensing (VL), contact FOPE support to deprovision your account (e-mail: support@messaging.microsoft.com or Web: https://go.microsoft.com/fwlink/?LinkID=149248or phone: 866.291.7726). 

  2. Before your cancellation order is processed, do the following to ensure that no mail is lost:

    1. Update the Mail Exchange (MX) record on your external DNS server so that it no longer points to the FOPE datacenter: mail.messaging.microsoft.com

    2. Update the Sender Policy Framework (SPF) record so that it is no longer defined as: v=spf1 include: spf.messaging.microsoft.com –all

    3. Update your firewall rules and Exchange Edge Receive Connectors to remove the allow rules for the FOPE IPs that you created when enabling FOPE filtering for your environment. This change will allow mail from IP addresses other than the FOPE datacenter IPs. Also ensure that any restrictions enforced on other IPs are appropriately updated to ensure that incoming mails can be accepted.

  3. In the Forefront Protection 2010 for Exchange Server Administrator Console  Policy Management tree view, expand Online Protection, and then click Configure.

  4. In the Online Protection - Configure pane, in the Forefront Online Protection for Exchange Gateway Management area, deselect the Enable Forefront Online Protection for Exchange Gateway checkbox.

  5. Click Save at the top of the pane.

Once you have cancelled your FOPE service and made the changes described here, your organization’s e-mail will no longer be routed through the FOPE datacenter for filtering.