RAPS Email Safe Links Exclusion Policy
-
Requisition Approval Processing Suite (RAPS)
RAPS Setup RAPS Utilities RAPS Requisition Entry RAPS Requisition Approval RAPS Convert Approved Reqs RAPS Purchase Order Cancel RAPS Delegation Maintenance RAPS Contract Module RAPS Expediting Module RAPS Pre-Revision Quotation Module RAPS - ATC Process (Approval to Commit) RAPS Enquiry by PSA Air Department RAPS Cost Controllers RAPS Unbudgeted/Budgeted RAPS Change Order Mode
- AP - Automated Invoice Workflow
- AP - Payment Approval Management
- Global Upload Program (GUP)
- Document Register (DocReg)
- Rotables / Component Changeout
- PSA Mining Template Functions
- Standard Pronto Functions
- PSA Mining Report Suite
- PSA HelpDesk
Safe Links is protection system in Microsoft Exchange that scans and executes links inside emails to determine if they are malicious or not.
When a user clicks on a link inside an email, it first gets executed by Safe Links, then if links is safe it will execute it again as the user. This causes an issue with RAPS approval emails as the links inside those emails contain a one time use token. Those tokens get consumed by Safe Links and when the user actually opens the link they get told that the token is invalid. However, the approval inside Pronto already occurred since Safe Links already executed the link.
To prevent this from happening a policy needs to be created to exclude Pronto server links from Safe Links.
The following steps will show how to configure this policy:
- Login to: https://security.microsoft.com
- Navigate to Email & collaboration > Policies & rules > Threat policies

- Under Policies, click Safe Links

- Click Create
- Name the policy and optionally provide a description

- Click Next
- Assign the policy to either specific users, groups, or domains

- Click Next
- Click Manage 0 URLs
- Depending on how tightly you want to configure this enter either your Pronto Server or a wildcard with stratusmanagedcloud.com domain and click Save.
Example:xi.customer.stratusmanagedcloud.com(replace with URL of your Pronto server) or*.customer.stratusmanagedcloud.com(replace with URL of your Pronto server) or*.stratusmanagedcloud.com
- Click Done
- Click Next > Next > Submit
- Make sure that the priority on this policy is higher than any other policy that would not have these exclusions

- The policy can take anywhere from 5 minutes to 24 hours to apply, but usually is applied within a few minutes.