Getting protected: the nine setup steps

Written By Matt Sywulak

Last updated About 1 hour ago

Everything your trial can show you depends on mail reaching INKY. Until that happens the Overview has no charts, the message feed has no messages, and INKY has found nothing. The console calls this milestone Mail reaches INKY, and it runs to nine checks.

You will find it on the trial Home page as a checklist with a progress meter reading N of 9. It is the only part of the trial with a total, because it is the only part with a correct answer. Everything after it is optional.

The nine checks, in order

Each check passes or it does not. Six are things you do. Three are things INKY confirms on its own once the earlier work lands.

1. A license exists for this team

Pick your platform and domain in Team Setup. INKY issues the license for your tenant.

See Platform Setup Guide. Then, depending on whether you are protecting your own organization or a customer's, Installing INKY for your organization's own team or Installing INKY for a customer organization.

2. The license is redeemed

Redeeming needs a Microsoft administrator to approve INKY's access. Team Setup walks you through it.

3. INKY has access to this tenant

INKY needs directory and remediation permissions before it can read or act on mail. Granting them opens a Microsoft sign-in.

This is the step that stalls most often, almost always for one reason. That sign-in asks for a Microsoft 365 or Exchange global administrator account on the tenant being protected, which is often not the account you signed in to the INKY console with. If the consent screen refuses you, sign in there as a global admin for the tenant. An incognito window stops your browser reusing the wrong account.

4. Your domains are routed

Every domain you want protected has to route through INKY. A domain you leave unrouted is not protected, because INKY never sees its mail.

List every domain that receives mail for your staff, including any you use for one department or one brand.

5. INKY is installed

This runs the setup against your mail platform, creating the connectors and rules INKY needs on the Microsoft 365 or Google Workspace side.

Google Workspace takes more platform-side configuration and has its own set of guides. Start at Google Workspace. For Microsoft 365, see Microsoft 365.

6. The install finished cleanly

INKY checks the install completed rather than stalling part-way. Nothing to do here. It either confirms or it does not.

If it has not confirmed within a few minutes, the install hit something on the platform side. Two common causes have their own articles: "Organization settings customization has been enabled, but this has not yet taken effect" and "Unable to discover the tenant address".

7. Mailboxes are protected

On Microsoft 365, the include and exclude groups in Tenant Operations decide who INKY covers. On Google Workspace you set this in Google.

How you set this group shapes the rest of the trial. Protecting a small pilot group first is a legitimate way to run one, but a handful of quiet mailboxes gives INKY very little to analyze, and the trial will look emptier than the product is. See Group Management and Deployment Strategy.

8. The changes have taken effect

Mail platforms take a while to pick up new routing. Nothing to do here but wait.

9. Mail is flowing through INKY

The moment this turns green, INKY is analyzing your mail. The trial home page changes its verdict to INKY is protecting this team's mail, and the optional tracks below the checklist unlock.

How to read the checklist

Each row carries one of four labels.

  • Done. The check passes.

  • To do. Not yet, and it is yours to do. The row has a button that takes you to the right page.

  • Not available yet. Waiting on an earlier step. Nothing to do until that one clears.

  • Not tracked. INKY could not decide this check either way. It is not a failure and it does not block you. It shows up most often when you are looking at an organization rollup rather than a single team, so switch the team selector to the tenant itself and read the checklist there.

Below the verdict, the page nominates one row and gives it the only prominent button on the page, labelled Do this next, so you always know what to do now. Follow it and the nine resolve in order.

If a step will not go green

  • You did the work but the check has not caught up. Several checks read the state of your mail platform, which does not update instantly. Wait a few minutes and reload.

  • Mail is not flowing and nothing is outstanding. If the checklist is complete and step 9 is still not green, mail is not routing to INKY. Confirm every protected domain's MX records point at INKY, and confirm the mailboxes you expected in scope are in scope. A message trace on the platform side shows where mail is going. See Run a Message Trace in Microsoft 365 or Run an Email Log Search in Google Workspace.

  • Mail is flowing but staff report odd sender formatting. Your SPF record probably needs updating for INKY. See Update Your SPF Record for INKY.

  • You are stuck. Contact the Kaseya helpdesk at helpdesk.kaseya.com. Setup problems spend trial days, and there is no reason to spend them.

Before you tell your staff

Once mail is flowing, your users start seeing INKY's banner on their messages. That is the part of INKY they interact with every day, and it lands better if someone told them it was coming. See End-User Rollout Guide and INKY Email Assistant Explained.