← Glossary

Integrated Cloud Email Security (ICES)

Integrated Cloud Email Security (ICES) is the API-based email security category that works inside Microsoft 365 and Google Workspace instead of rerouting mail.

Updated

Integrated Cloud Email Security (ICES) is the category of email security that connects via API inside cloud email platforms like Microsoft 365 and Google Workspace, analyzing mail behaviorally after the platform''s native filtering, without rerouting mail flow. The term was popularized by industry analysts to distinguish this architecture from the traditional secure email gateway.

Key facts

  • ICES deploys via API in minutes: no MX record changes, no mail rerouting, no appliances.
  • Because it sits inside the platform, it sees internal mail, historical mail and OAuth events, which gateways never see.
  • Detection is typically behavioral and AI-driven, aimed at the targeted attacks (spear phishing, BEC) that pass both native filtering and gateways.

ICES vs SEG

ICESSecure email gateway
DeploymentAPI connection in minutesMX record change; mail rerouted through the gateway
VisibilityInbound, outbound, internal and historical mail, plus OAuth and login eventsInbound, sometimes outbound, mail at the perimeter only
DetectionBehavioral and AI-driven: relationship, intent, contextSignatures, reputation, sandboxing of payloads
Payload-free attacksA core design targetLargely invisible
RemediationRemove from mailboxes after delivery, across the tenantBlock or quarantine at the gateway; nothing once delivered
Native filteringRuns alongside Microsoft and GoogleOften replaces it, or scans the same mail twice

Why the category emerged

Cloud platforms made the gateway''s original job partly redundant: Microsoft and Google now do solid bulk filtering natively. What remained unsolved was the targeted remainder: payload-free BEC, AI-written phishing, account takeover, and those require context a perimeter box cannot have: who normally mails whom, what normal looks like, which apps hold access. ICES is the architectural answer: put the intelligence where the context is.

What to evaluate in an ICES product

Detection approach (behavioral/AI-native or rules with AI labels), coverage beyond inbound mail (internal mail, OAuth/app layer, account takeover signals), remediation (automatic and retroactive across mailboxes), and evidence quality (can verdicts be audited). Sentaro is an ICES platform built AI-native, with the OAuth/app layer as a first-class citizen rather than an add-on.

Questions we get asked.

What does ICES stand for?

Integrated Cloud Email Security: email security integrated via API inside cloud email platforms, as opposed to gateways that reroute mail in front of them.

Do I need both a SEG and an ICES solution?

Increasingly rarely. Native platform filtering plus an ICES layer covers what most organizations bought gateways for, which is why "SEG replacement" is a common migration path.

Is ICES the same as API-based email security?

Effectively yes; ICES is the analyst-coined category name for API-based, behaviorally focused email security inside cloud platforms.

Which attacks is ICES designed for?

The targeted remainder that passes bulk filtering: spear phishing, business email compromise, account takeover and OAuth-based attacks like consent phishing.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.