Barracuda Email Gateway Defense (Beta)
Quick DetailsRecommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Barracuda EGD Child Inspectors (one per account)
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: Barracuda Email Gateway Defense Inspector Summary
Overview
Barracuda Email Gateway Defense Inspector (Beta)
Barracuda Email Gateway Defense (EGD) is Barracuda's cloud-native email security service — inbound and outbound mail filtering, spam/phishing/malware blocking, and domain protection for customer email domains, managed through Barracuda Cloud Control (BCC). The Barracuda Email Gateway Defense Inspector (Beta) connects to your BCC partner application and pulls account configuration, managed-domain verification status, and 30-day mail-flow statistics for every EGD account your MSP manages — giving you a single view of customer email security posture without logging into BCC account by account.
What you can monitor
- EGD account status (Active/Suspended/Disabled) and region (US/UK)
- Managed domain inventory, type (ESS/CPL), and verification status (Verified/Unverified/Disabled)
- 30-day mail-flow totals: allowed, blocked, deferred, quarantined
- 30-day blocked-threat breakdown — phishing, malware, spam, domain impersonation — at both the account and per-domain level
How it works
A parent launchpoint authenticates to Barracuda Token Service (BTS) using OAuth 2.0 client credentials and enumerates every EGD account visible to your BCC partner application. Liongard automatically creates a child launchpoint per account, mapped to a Liongard Environment by account name, and tracks that account's domains and mail-flow statistics independently.
Benefits
- Confirm every managed customer's EGD account is Active and every managed domain is Verified from one dashboard.
- Catch a domain that drops to Unverified or Disabled before a customer's mail flow breaks.
- Pull 30-day allowed/blocked/phishing/malware counts straight into monthly customer reviews.
- New customers onboarded to EGD are picked up automatically on the next parent run — no manual launchpoint setup required.
Inspector Setup Preparation
Prerequisites & Access RequirementsTo configure the Barracuda Email Gateway Defense Inspector, ensure you have the following:
- Partner-tier access to Barracuda Cloud Control (BCC) for the account that owns your managed customers' EGD accounts
- Ability to register an application in Barracuda Token Service (BTS)
- Knowledge of which region (US or UK) your managed customers' EGD accounts live in — separate launchpoints are required per region
Inspector Setup:
Step 1: Create the API Credential in Barracuda
- Sign in to Barracuda Cloud Control as the partner-tier account that owns the customer accounts you want surfaced in Liongard.
- Navigate to the Barracuda Token Service registration page:
https://login.bts.barracudanetworks.com/register. - Select ADD APPLICATION (top right). Name the application (e.g., "Liongard EGD Inspector"), set the scope to
ess:account:read, and submit. - Copy the Client ID (shown permanently on the application detail page) and the Client Secret (displayed only once, for 15 minutes after creation) — if you lose it, regenerate it from the same page.
Region-pinned tokensA token issued by the US Barracuda Token Service host will not authenticate against the UK API host, and vice versa. If you manage customers in both regions, you'll need a separate BCC application — and a separate Liongard parent launchpoint — per region.
Step 2: Configure the Barracuda Email Gateway Defense Inspector in Liongard
- Log in to the Liongard platform.
- Navigate to Admin > Inspectors > Inspector Types > Navigate to the Barracuda Email Gateway Defense Inspector > Select Add System.
Since Barracuda EGD is a multi-tenant system where a single BCC application manages many customer accounts, you'll set up a single "Parent" Inspector with your BTS credential that will then auto-discover a "Child" Inspector for each EGD account.
Fill in the following information:
- Type of Inspector: Parent
- Environment: Select your MSP's Environment
- Friendly Name: Suggested Naming: [Customer Name] Barracuda EGD Parent
- Agent: Select the appropriate Agent
- Inspector Version: Latest
- Barracuda Cloud Control Client ID: The Client ID from Step 1
- Barracuda Cloud Control Client Secret: The Client Secret from Step 1
- Region: US or UK — must match where the BCC account and its managed customers live
- Scheduling: The Inspector will default to run once a day at the time it's set up. Here you can adjust the schedule
Select Save. The Inspector will now be triggered to run within the minute.
Step 3: Child Inspector Setup
After the first run of the Parent Inspector, every EGD account visible to your BCC application will be auto-discovered and surfaced on the Discovered Systems tab on the Inspectors > Barracuda Email Gateway Defense Inspector page.
- Activate your Discovered Systems by ensuring they're mapped to the correct Environment > Select the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints.
- Archive Discovered Systems the same way, using Archive Launchpoints instead.
Flexible Asset/Configuration Auto-Updating
This inspector does not yet contribute to Flexible Assets/Configurations — no ConnectWise or IT Glue asset mappings ship with it today, so turning on those auto-updating toggles will not produce any data for this inspector.
Troubleshooting
- HTTP 401 on token request: The Client Secret is wrong, expired by rotation, or the BCC application was deleted. Regenerate the secret from the BTS application registration page.
- HTTP 401 on data endpoints: The access token expired mid-run. Re-run the inspector — a fresh token is acquired automatically. If 401s persist after a re-run, the
ess:account:readscope was revoked; re-add it to the BCC application. - HTTP 403 / 404 on a specific account: The BCC credential lost access to that account. The inspector skips it and continues — the affected child reports empty domains and zero-valued statistics. Check BCC partner-account assignment for that customer.
- Parent run discovers zero accounts: The BCC application is registered against an account with no managed customers, or against a single-tenant (not partner-tier) BCC account. Confirm in BCC that the registering account has visibility into the customer accounts.
- Region mismatch ("Unauthorized" on every data call despite a clean token response): Verify the configured Region matches where the BCC account lives (US vs. UK).
Known V1 LimitationsNo message log, individual message detail, message bodies, or attachments. No quarantine queue contents. No user-level allow/block lists. No sender-authentication policy detail (DKIM keys, DMARC policy strings, SPF includes) beyond domain status. No ATP/sandboxing or encryption configuration. No user/mailbox enumeration. No audit log or syslog forwarding configuration. The inspector does not write to the EGD API at all — the only available scope is read-only.
Updated about 3 hours ago

