Host a static MTA-STS policy file at https://mta-sts.contoso.com/.well-known/mta-sts.txt to ensure that emails to the domain are sent securely.
The app will be created to host a policy which is in testing
mode first. Later this should be changed to enforce
mode to ensure that protections start being applied to incoming emails.
Install-Module -Name Az -Scope CurrentUser -Repository PSGallery -Force
Connect-AzAccount
New-AzResourceGroup -Name "MTASTSRG" -Location "westeurope"
New-AzResourceGroupDeployment -ResourceGroupName "MTASTSRG" -TemplateFile ./main.bicep
# Or pass it a custom prefix name:
New-AzResourceGroupDeployment -ResourceGroupName "MTASTSRG" -TemplateFile ./main.bicep -resourceNamePrefix "ContosoMtaSts"
# Or use a different MX record within the mta-sts.txt policy instead of the default *.mail.protection.outlook.com
New-AzResourceGroupDeployment -ResourceGroupName "MTASTSRG" -TemplateFile ./main.bicep -mxRecord "mail.contoso.com"
or