Skip to content

Barracuda Email Gateway Defense Setup ​

Junto connects to Barracuda Email Gateway Defense to check customer account status, inspect protected domains, and report on inbound email threats. Use it to prepare security reviews, summarize what Barracuda stopped, or investigate a change in threat activity.

The integration is read-only. It supports reporting, including Forensics & Incident Response entitlement checks, but does not release quarantined messages, change sender policies, manage users, or perform incident remediation.

How Junto Connects ​

Connect Barracuda once for your organization using Barracuda Token Service credentials. Choose the region where those credentials were created, then map Barracuda customer accounts to Junto companies. The agent uses these mappings to retrieve the correct customer's data.

Junto supports the United States and United Kingdom regions. Barracuda currently describes the Email Gateway Defense API as a beta release; see its API overview.

Prerequisites ​

  • Admin or Owner access in Junto.
  • A Barracuda Cloud Control account with administrator access to Email Gateway Defense and visibility into the customers you want to connect.
  • A registered Barracuda Token Service application with a Client ID and Client secret for the correct region. See Barracuda's API getting-started guide for registration requirements.
  • Read permissions for Email Gateway Defense and Forensics account information: ess:account:read and forensics:account:read.
  • The corresponding customer companies already present in Junto.

Step 1: Register a Barracuda Application ​

  1. Open the Barracuda Token Service for your region: United States or United Kingdom. Sign in with your Barracuda Cloud Control account.
  2. Click ADD APPLICATION and give the application a name, such as Junto.
  3. Under Application Scope, select read access for Email Gateway Defense and Forensics account information (ess:account:read and forensics:account:read).
  4. Click ADD APPLICATION, then copy the Client ID and Client Secret from the application's details page.

Barracuda makes the secret available to view or copy for 15 minutes after creation. Store it securely; if you miss that window, reset it to obtain a new value. See Barracuda's application registration instructions.

Step 2: Configure in Junto ​

  1. Go to Settings > Integrations > Barracuda Email Gateway Defense.
  2. Click Add configuration.
  3. Complete the fields below.
  4. Leave Active enabled and click Add configuration to save. Junto validates the connection before saving.
  5. Click Test connection on the configuration card. A successful test reports how many Barracuda accounts are visible.
FieldWhat to enter
RegionUnited States or United Kingdom, matching the region where the Token Service credentials were created
Client IDThe ID of your registered Barracuda Token Service application
Client secretThe application's secret
ActiveKeep enabled to make the integration available to the agent

Check the region first

Credentials work only in the region where they were created. A region mismatch can appear as an invalid-credentials error even when the Client ID and secret are correct.

Junto handles access-token retrieval and renewal. You do not need to copy an access token into the settings page.

Step 3: Map Companies ​

  1. On the configuration card, click Map companies.
  2. Review the Barracuda accounts and their protected domains.
  3. Click Auto-map to match Barracuda accounts to Junto companies. Exact matches are saved automatically; suggested matches remain available for review.
  4. Check each selection and choose the correct Junto company for any unmatched or ambiguous account.
  5. Click Save mappings to save your selections and confirm suggestions.

Each Junto company can map to one Barracuda account, and each Barracuda account can map to one Junto company. Leave an account as Not mapped if you do not want the agent to use it.

Unmapped customers return no Barracuda results and are excluded from reports across mapped customers. Auto-map leaves ambiguous domain matches for manual selection; check the displayed domains carefully when accounts have similar names.

What the Agent Can Do ​

All Barracuda capabilities are low-risk reads and do not require approval by default.

CapabilityDescription
Account statusCheck whether a customer's Email Gateway Defense account is active or disabled
Protected domainsList a customer's mail domains and inspect their verification status
Email statisticsRead inbound message counts by verdict and threat category for a whole account or one domain
Threat summarySummarize threats blocked or quarantined, the stopped rate, and the leading threat categories
Threat trendCompare the newer and older halves of a reporting window to assess changes in threats stopped
Security postureCombine account status, domains, recent inbound statistics, and Forensics & Incident Response entitlement in one customer overview

Through a connected AI client (MCP), fleet reporting tools can also find disabled or inaccessible mapped accounts, identify missing Forensics entitlement, and rank mapped customers by threats stopped. Customers without a mapping are excluded from these reports.

Example requests:

  • "Summarize Acme's Barracuda email security over the last 30 days."
  • "Which mail domains does Barracuda protect for Acme?"
  • "Has the volume of threats stopped for Acme increased recently?"

Reporting Limits ​

  • Recent history only -- Statistics cover up to the most recent 30 daily buckets or 168 hourly buckets. Arbitrary historical date ranges and 90-day reports are unavailable.
  • Inbound mail only -- Outbound statistics are unavailable through this integration. Missing outbound data should not be read as zero outbound threats.
  • Disabled accounts are distinct -- Empty results from a disabled account mean the service is off, not that the customer has no threats. Junto checks account status before summarizing statistics.
  • Trends split one window -- A 30-day comparison uses the newer 15 days and the older 15 days within that window; it does not compare two full 30-day periods.
  • Threats stopped is a security measure -- It counts blocked or quarantined messages in threat categories. Policy-only blocks and clean mail are excluded.
  • Forensics visibility is entitlement only -- The integration checks whether an account has Forensics & Incident Response access; it does not retrieve or remediate incidents.

Updating or Removing the Connection ​

Click Edit to rotate credentials or change the region. Leave the Client ID and Client secret fields blank to keep their stored values. Junto revalidates changes to credentials or region before saving.

Turn Active off to pause the integration while keeping its configuration and mappings. Delete removes the configuration and its company mappings; reconnect and map companies again to restore access.

Troubleshooting ​

  • Invalid credentials -- Confirm the region first, then recheck the Client ID and secret from Barracuda Token Service.
  • Access denied -- Check that the application has the required Email Gateway Defense and Forensics read permissions.
  • No accounts returned -- Confirm that the Barracuda account used to register the application can access the customer accounts you need.
  • No results for a customer -- Confirm the configuration is active and the customer's company mapping is saved. Check whether the mapped Barracuda account is still visible to your credentials.
  • Mapping cannot be saved -- Ensure you have not selected the same Junto company for more than one Barracuda account.
  • Statistics are empty or unavailable -- Check the account's active status and request a supported reporting window. Outbound statistics are unavailable.