SafeToOpen Email Security
Email Security Deployment Guides
Roll out SafeToOpen Email Security to Outlook and Gmail across an organisation, license every mailbox without activation links, and run it from the Business Console.
Overview: how Email Security is deployed and licensed
Add-ins, seats, how a mailbox becomes a licensed member with no activation link, workspaces, and what the console controls. Start here.
Outlook: Microsoft 365 deployment
Integrated apps from AppSource or the branded manifest per workspace, group import from Entra ID, multi-tenant for MSPs, verification.
Gmail: Google Workspace deployment
Marketplace domain install by organisational unit, sign-in without invites, Google Groups import, verification.
Workspace policies and branding
The five enforced behaviours, the deferred verdict, the URL scan service, branding and the branded add-in, report inboxes, alert recipients and analysts, and Outlook versus Gmail coverage.
Incidents, alerts and integrations
What becomes an incident, severities, alert cadence, and feeding events to ticketing and SIEM tools.
Platform coverage and user freedom
Outlook and Gmail on desktop, web and mobile, what other clients cannot do, and what a user can still change.
Response actions: mail platforms, gateways, identity, chat and paging
What each integration lets you do, in one table, then per integration: what you need, the vendor-side and console set-up step by step, and the actions with scope and undo. Eight mail platforms and gateways, three identity providers, Slack, Teams, PagerDuty and Opsgenie.
Which guide do I need?#
- Everyone — Read the Overview first: seats, how a mailbox is licensed without an activation link, workspaces, and what the console controls.
- Outlook on Microsoft 365 — Guide 2: Integrated apps, the branded manifest per workspace and Entra ID group import.
- Gmail on Google Workspace — Guide 3: Marketplace domain install and CSV import.
- Then — Guide 4 for policies and branding, guide 5 for incidents, alerts and SIEM or ticketing, guide 6 for what each client can and cannot do.
- Acting on incidents — Guide 7: connect Microsoft 365 and Entra ID so a confirmed incident junks the sender and locks down a compromised user.
Before you start#
You need an Owner or Co-administrator login to https://plus.safetoopen.com/business-console#/es/settings. Seats are bought there under Plan & billing; people are added under People.