I am a Zivver admin
Configure and manage Zivver
Installation manual Zivver OWA add-in
Introduction
Use the Zivver Outlook Web Access Add-in to securely send and receive messages directly from Outlook Web Access (OWA). This manual describes how to install the add-in in Exchange Online (part of Microsoft Office 365). The Zivver OWA add-in is available for Exchange Online.
Technical requirements
You can install the Zivver OWA add-in in Exchange Online. To use the OWA add-in, you must meet these requirements:
- Use Exchange Online
- The users’ workstations (Windows or Mac) have the latest General Available (GA) or Stable version of one of these modern browsers installed:
- Microsoft Edge based on Chromium (recommended)
- Google Chrome / Chromium (for Android/iOS) (recommended)
- Mozilla Firefox
- Apple Safari (for iOS)
- Allow cookies in the browser for these exact URL’s. Read more about CookiesAllowedForUrls in Edge (this setting is identical in Chrome)
- [*.]office.com
- [*.]office365.com
- [*.]zivver.com
The Zivver add-in stores the active session of a user inLocalStorage
. Blocking cookies for these domains will cause users to log in after every page refresh
- Allow pop-ups in the browser for these exact URL’s. Read more about PopupsAllowedForUrls in Edge (this setting is identical in Chrome)
- [*.]office.com
- [*.]office365.com
- [*.]zivver.com
The Zivver add-in uses pop-ups to log users in. Blocking pop-ups for these domains will prevent users from being able to log in to Zivver
- An Entra ID admin account with Global Administrator privileges
- A Zivver administrator account
Installation
You can install the Zivver OWA add-in via either Microsoft 365 admin center or PowerShell. Both are explained in this manual.
Deploy and configure the Zivver OWA add-in via Microsoft 365 admin center
- Log in to the Microsoft 365 admin center.
- Click add Deploy Add-In.
- Click Next.
- Select Upload custom apps under Deploy a custom add-in.
- Enter
https://owa-v6.zivver.com/manifest.xml
as the URL of the OWA Add-in manifest file.Make sure to includehttps://
, even though this is already mentioned in the user interface. - Click Upload.
A Configure add-in screen is shown. - Choose which users get assigned the Zivver OWA add-in:
- Everyone
All users in your organization can use the add-in. Select "Everyone" to roll out the add-in to your entire organization. For example when going Live with Zivver. - Specific users / groups
Only make the add-in available for specific users or groups. Select this for a pilot of when only specific users use OWA. - Just me
Only makes the add-in available for your logged in admin account. Select this if you only want to test yourself.
Microsoft does not support the assignment of add-ins to nested groups. Read more about this in their documentation. - Everyone
- Select how the add-in is deployed to users:
- Fixed (Default)
Recommended. The add-in is enabled by default for assigned users, and they can't disable the add-in. - Available
Not recommended. The add-in is disabled by default, but assigned users can install the add-in when they want. - Optional
The add-in is enabled by default for assigned users, but they can disable the add-in when they want.
- Fixed (Default)
- Click Deploy.
- Read the Microsoft notice and click Next.
- Click Close.
The Zivver OWA add-in is now installed and configured for your Office 365 organization. It may take up to 24 hours for the change to be implemented in Exchange Online. See Microsoft's documentation for more information. - Continue with the steps for the admin consent.
Give admin consent to the required Graph API permissions
Zivver OWA add-in requires admin consent for your organization in order to work seamlessly with the Microsoft Graph API.
Prerequisites
- Have a user mailbox with the Zivver OWA add-in deployed
This user mailbox is required to have a Zivver account. This user mailbox is not required to admin privileges. - Have global administrator credentials available when performing the steps below
Either via the user mailbox that has the OWA add-in deployed or separate administrator credentials
- Open
outlook.office.com
with the user mailbox that has the Zivver OWA add-in deployed - Open the Zivver OWA add-in by opening a new draft email and clicking the Zivver icon, or via Apps from the top ribbon and selecting Zivver from here
The login proces should start, opening a flyout window from login.microsoftonline.com If you are logged in with an administrator account, then select Consent on behalf of your organization and click Accept.
If you are logged in with a user mailbox without administrator privileges, then select Have an admin account? Sign in with that account. After you have succesfully authenticated your administrator account, you can select Consent on behalf of your organization and click Accept.Proceed with the required additional settings
Create an Exchange rule for Zivver messages
Set this rule must to prevent OWA from sending a Zivver message as unencrypted, regular email.
- Log in to the Exchange admin center.
- Click mail flow in the left side pane.
- Select the Rules tab.
- Click add Add a rule > Create a new rule.
- Give the rule the name
zivver-action: discard
. - Under Apply this rule if select the option The message headers … and the sub-option matches these text patterns.
- Click Enter text.
specify header name opens. - Enter
zivver-action
. Then, click Save. - Click Enter words.
specify words or phrases opens. - Enter
discard
. - Click Add.
- Click Save.
- Under Do the following the option Block the message, and the sub-option delete the message without notifying anyone.
- Click Next.
Set rule settings opens. - Set the Rule mode to Enforce.
- Set Severity to Low.
- Select Stop processing more rules.
- Set Match sender address in message to Header.
- Click Next. Then, click Finish.
- Wait a few seconds. Then, click Done.
Now you can set the priority. - Select the new rule.
- Enable the rule.
- Click Edit.
Zivver-action:discard opens - Click Settings.
- Set the priority of the
zivver-action:discard
rule to0
A mail flow rule has now been created that prevents Zivver messages from being sent as unencrypted, regular email. - Click Save. Then, click Done.
Required additional settings
Enable Inbound Direct Delivery
Inbound Direct Delivery (IDD) allows your users to read inbound Zivver messages directly from the reading pane instead of having to open the Zivver side pane. To enable, follow the procedure described in the Inbound Direct Delivery manual.
Allow cookies in Edge/Chrome
Allow cookies in the browser for these exact URL’s. Read more about CookiesAllowedForUrls in Edge (this setting is identical in Chrome).
- [*.]office.com
- [*.]office365.com
- [*.]zivver.com
The Zivver add-in stores the active session of a user inLocalStorage
. Blocking cookies for these domains will cause users to log in after every page refresh
Allow pop-ups in Edge/Chrome
Allow pop-ups in the browser for these exact URL’s. Read more about PopupsAllowedForUrls in Edge (this setting is identical in Chrome).
- [*.]office.com
- [*.]office365.com
- [*.]zivver.com
The Zivver add-in uses pop-ups to log users in. Blocking pop-ups for these domains will prevent users from being able to log in to Zivver
Configure Exempt Domains
Configure Exempt domains from scanning during sending to exempt internal domains from Smart Classification.
Add-in behaviour
Configure Automatically use Zivver when a business rule recommends to be set to On, Mandatory on the Add-in Settings page. Read more about Outlook Web Access Add-in integration settings.
Trusted websites in Internet Options
For Windows users only.
Add these locations to the Trusted sites zone of Internet Options. This prevents a white screen during logging into the OWA add-in.
- Open the control panel.
- Click Network and Internet.
- Click Internet Options.
- Click the Security tab.
- Click Trusted websites.
- Click the Websites button.
- Add these URLs as trusted websites:
- Zivver OWA add-in:
https://owa-v6.zivver.com
- Zivver web app:
https://app.zivver.com
- OWA:
https://outlook.office.com
- Zivver OWA add-in:
- Click Close.
- Click OK.
MacOS Safari privacy settings
For MacOS users only.
- At Settings > Privacy make sure “Prevent cross-site tracking” is unchecked.
- At Settings > Privacy make sure “Block all cookies” is unchecked.
- At Websites > Pop-up windows make sure “outlook.office.com” is allowed.
Verify the installation was successful
- Click New to create a new message.
- Set up a message as usual with a recipient, subject and body.
- Click on the three dots in the Outlook toolbar at the top of your screen.
- Click the Zivver link in the menu.
The Zivver side panel opens on the right side. - Log in to Zivver if you are not logged in automatically.
- Turn on Secure mail.
- Click Recipient verification.
A new screen listing all recipients opens. - Complete the recipient verification where necessary.
Learn more about Recipient verification - Click Apply.
- Click Send to send the message.
A Zivver pop-up can show to check the email and attachments on sensitive information. - Verify in the recipients’ inbox that a Zivver message has been received and no unencrypted, regular email has been received.
You have now verified the installation was successful.
Remove the Zivver OWA Add-in from Microsoft 365 admin center
If you want to remove the Zivver add-in, follow these steps to uninstall it from the Exchange admin center.
- Log in to the Microsoft 365 admin center.
- Select Zivver.
The Zivver Add-in screen appears in a right side pane. - Scroll down on the Zivver side pane and click Delete add-in at the bottom of the side pane.
- Confirm by clicking Delete. The Zivver OWA add-in has now been removed.
Remove the Zivver Exchange rule
Do these steps to remove the Zivver Exchange rule from the Exchange admin center.
- Log in to the Exchange admin center.
- Click mail flow in the left side pane.
- Select the Rules tab.
- Select the mail flow rule zivver-action:discard.
- Delete the rule delete .