The following instructions only describes locking down access to Exchange Active Sync using the ExchangeActiveSync protocol definition. You can expand the scope of the protocol lockdown per the Protocols definition referenced in the Client Access Rules in Exchange Online documentation from Microsoft.
If you have existing Client Access Rules defined, ensure that you set the priority number of the Jamf Connect's Zero Trust Network Access rules so as not to overwrite the existing configuration.
- Open a new Notepad file.
- Paste in the Cloud Internet Gateway IP addresses for Zero Trust Network Access. See Zero Trust Network Access Cloud Internet Gateways.
- Open a PowerShell terminal and log into Exchange as an administrator.
- Copy and paste each command from Notepad into the terminal to execute the settings, or upload the file and execute as a PowerShell script.