SafeToOpen Browser Security
Overview: how Email Security is deployed and licensed
Add-ins, seats, how a mailbox becomes a licensed member with no activation link, workspaces, and what the console controls
SafeToOpen Email Security is an add-in inside the mail client: “SafeToOpen Email Verification” for Outlook (Microsoft 365) and “SafeToOpen Email Security” for Gmail (Google Workspace). It scores every message the user opens or asks about, checks sender authentication, links, attachments and impersonation, and reports what it finds to your Business Console. Rolling it out is two jobs, and both are silent for the user:
- Install — The tenant administrator deploys the add-in to mailboxes from the Microsoft 365 admin center or the Google Admin console. The user cannot remove it.
- License — The add-in signs the user in with their Microsoft or Google identity. If that address is on your People page, the mailbox is licensed on the spot. No activation email, no link, no password.
This guide explains the pieces that the platform guides rely on.
1. Seats and members#
| Plus seat | Executive seat | |
|---|---|---|
| Protection | Trust score, sender authentication, link and attachment checks, phishing reports | Everything in Plus, plus Deeper Analysis on demand or enforced by policy, executive impersonation and writing-style checks, unlimited analyses |
| Who | Everyone | Leadership, finance, HR, anyone targeted by CEO fraud and invoice fraud |
| Where set | People page: per member, CSV column, per Entra ID group, or per Google Group |
A member is an email address on the People page. Members are added by hand, by CSV, by importing Entra ID groups (Microsoft 365) or by importing Google Groups (Google Workspace). Each member uses one seat of the chosen type. Seats are bought and adjusted in Settings → Plan & billing.
2. How a mailbox becomes licensed#
- The address is on the People page (added, imported or synced).
- The add-in is present in the user’s mail client (deployed by the admin, or installed by the user where you allow it).
- The first time the add-in opens it signs the user in silently: Outlook through Office single sign-on with their Microsoft 365 account, Gmail through their Google account. The address from that sign-in is matched to the member, the member becomes active and the seat is in use.
A member who is removed on the People page loses the add-in’s features at the next check, usually within a minute, and the seat is freed.
3. Workspaces#
Workspaces split an organisation into sites, departments or MSP client tenants. Each has its own policies and branding (guide 4), its own report inbox and alert recipients, and its own analysts who see only that workspace’s incidents. Members belong to one workspace or to the organisation default. Entra ID groups map to workspaces on import.
4. What the console controls#
| Page | What you do there |
|---|---|
| Incidents | User reports, dangerous and suspicious verdicts, executive impersonation; triage, notes, status. |
| Dashboard | Volumes and trends per workspace. |
| People | Members, seats, workspace, invite emails, Entra ID import, removal. |
| Microsoft 365 | Connect one or several Entra ID tenants, map groups to workspaces and seat types, choose whether imports email people. |
| Google Workspace | Connect one or several Google Workspace domains through a service account, map Google Groups to workspaces and seat types, same switches as Microsoft 365. |
| Workspaces | Create workspaces, report inbox, alert recipients, analysts, and policies and branding per workspace. |
| Integrations | Export tokens, signed webhooks, SIEM formats and STIX for Email Security events. |
| Response actions | Connect Microsoft 365 and Entra ID; rules that junk a confirmed sender or lock down a compromised user, automatically or on Confirm. Gateway and EDR blocking of URLs lives in Browser Security, because email incidents carry a sender, not a link. |
| Activity log | Every administrative change with who and when. |
| Settings | Organisation name, default report inbox, alert cadence, invite emails, plan and billing, seats, and administrator access: co-admins that follow a Microsoft 365 or Google group, and required SSO for administrators. |
5. Administrator access#
Settings → Administrator access (plan owner). Choose a group in a connected Microsoft 365 or Google Workspace directory; its members become console co-admins and people who leave the group lose access at the next hourly sync, with manually added co-admins left alone (up to 25 co-admins). A second switch requires the organisation’s administrators to sign in with Microsoft or Google, refusing password sign-in; the console will not enable it until your own account has such a sign-in linked. Details and the MSP overview screen are in the Browser Security guide “MSP Operations”: https://plus.safetoopen.com/docs/browser-security/integrations/msp.html.
6. What the user sees#
A button in the Outlook ribbon or reading pane (“Verify Email”, or the name you set), and a side panel in Gmail. The panel shows your organisation’s logo and name, the trust score and reasons, and the actions your policy allows. Settings that your policy enforces are shown but cannot be changed, with a note that the organisation manages them.
7. Verifying a deployment#
- The add-in appears in the user’s client without them doing anything (Outlook: within 24 hours of the Integrated apps deployment, often sooner; Gmail: at the next Gmail load).
- Opening it shows your organisation’s branding and no sign-in prompt.
- The People page shows the member as active with a “joined” time.
- A test message reported from the add-in appears on the Incidents page within a minute.
8. Which guide next#
- Outlook and Microsoft 365, with Entra ID group import: guide 2. Gmail and Google Workspace, with Google Groups import: guide 3.
- Policies, branding and the branded add-in: guide 4. Incidents, alerts and SIEM or ticketing: guide 5.
- What each client can and cannot do, and what users can still change: guide 6.
- Acting on confirmed incidents in Microsoft 365 and Entra ID: guide 7.