365labs - Microsoft 365 and cybersecurity consultancy

View Original

How to Efficiently Send Large Volumes of Internal Emails using HVE (Public Preview)

How to Efficiently Send Large Volumes of Internal Emails: A Comprehensive Guide for Businesses

A question we frequently get asked is how a business should go about sending out a large volume of internal emails. While traditional services like MailChimp and SendGrid are excellent for marketing campaigns, they are primarily designed for external communications. These platforms are tailored to manage large mailing lists, create visually appealing emails, and track detailed analytics for campaigns. However, their focus on external communication means they might not be the best fit for internal bulk email distribution within an organization. Typically for alerts, notifications and similar, for internal systems and processes. In the past we handled this using the internal Exchange server, but as most organisations have migrated away to the cloud, this is no longer an option.

This is where Microsoft 365's new feature, High Volume Email (HVE), comes into play. Recently launched in public preview, HVE is specifically designed to handle large-scale internal email communications, providing a robust alternative to traditional email services.

High Volume Email in Microsoft 365 offers several advantages. During the public preview phase, HVE allows businesses to send emails to up to 100,000 internal recipients per day per tenant. This capacity is expected to increase once the feature reaches general availability. Such high recipient limits make it an excellent choice for organizations with extensive internal communication needs, such as company-wide announcements or notifications sent from line-of-business applications.

The primary intention of HVE is to facilitate internal communications. Microsoft designed this service to enable businesses to send large volumes of internal messages beyond the typical limits of Exchange Online. For external communication needs, there is a limit of 2,000 external recipients per day.

Setting Up HVE

Administrators can create and manage up to 20 HVE accounts through the Exchange admin center. These accounts are specifically configured to handle high volumes of email traffic, ensuring that internal messages are delivered efficiently without the constraints of typical rate limits imposed on standard Exchange Online accounts. The setup process involves creating HVE accounts within accepted domains and configuring the necessary authentication settings. Currently, HVE uses SMTP Basic Authentication, but support for OAuth is expected in the future, enhancing security and integration capabilities.

Authentication Considerations:

To ensure HVE functions correctly, there are several important authentication settings to consider:

1. Security Defaults: If Security Defaults is enabled, all basic authentication, including SMTP, is disabled, making HVE non-functional. Therefore, it is essential to disable Security Defaults if using HVE.

2. SMTPClientAuthenticationDisabled: HVE accounts can still operate even if SMTPClientAuthenticationDisabled is set to True within TransportConfig, thanks to a custom SMTP endpoint designed for HVE.

3. AllowBasicAuthSmtp: It is crucial to enable AllowBasicAuthSmtp in the policy that applies to the HVE account to avoid any impact from authentication policies. Custom authentication policies can be applied to HVE accounts as needed.

4. Federated Users: Federated users must be created on-premises and synced using the Microsoft Azure Active Directory Sync Tool, making them inapplicable for HVE.

5. Conditional Access Policies: Given the need to disable Security Defaults for HVE, implementing Conditional Access policies is a good practice to enhance security. Conditional Access allows you to define conditions under which HVE accounts can access resources, thereby mitigating risks associated with disabling Security Defaults. For example:

  • Restrict Access Locations: Limit the IP addresses or geographical locations from which HVE accounts can authenticate, reducing exposure to potential attacks.

One of the significant benefits of using HVE is its seamless integration with the existing Microsoft 365 environment. This eliminates the need for additional third-party services, simplifying the management of internal communications. Moreover, during the public preview, HVE is available at no cost, offering substantial savings compared to traditional bulk email solutions. Administrators can also take advantage of detailed usage reports available in the Exchange admin center, providing insights into email volumes and account activity. This level of monitoring ensures that businesses can maintain control over their internal communication strategies and make data-driven decisions.

The implementation of HVE is not only cost-effective but also aligns with Microsoft 365’s robust security infrastructure. This ensures that internal communications remain secure and compliant with organizational policies. With the ability to customize recipient limits on a per-account basis, businesses have the flexibility to manage their email distribution according to their specific needs.

While MailChimp and SendGrid remain excellent choices for external marketing and transactional emails, Microsoft 365’s High Volume Email feature presents a compelling alternative for internal bulk email needs. By offering high recipient limits, customizable account settings, and seamless integration with Microsoft 365, HVE stands out as a vital tool for businesses looking to enhance their internal communication strategies.

For more information on setting up and managing HVE, you can refer to the official Microsoft Learn documentation. If you have any questions or need further assistance, feel free to reach out to our consultancy team.