Auditing - Ensure Mail Forwarding Rules Are Reviewed At Least Weekly

 









Summary

E-mail can be forwarded automatically after configuring the Exchange Online environment with the help of Transport Rules in Admin Center, Auto Forwarding per mailbox, and client-based rules in Outlook. Administrators and users both are provided with many methods to automatically and quickly e-mails outside of an organization.

Reason

By reviewing the rules weekly, the Messaging Administrator can gain insight into possible attempts to exfiltrate data from an organization; it can also help in creating a recognition of baseline, legitimate activity of users which in turn can aide in identifying the more malicious activity of bad actors when/if they chose to use this side-channel.

What If?

There is no impacting to reviewing these reports.

How to?

To review mail forwarding rule, use the Microsoft 365 Admin Center:
  1. Go to Exchange admin center.
  2. Expand Reports then pick Mail flow.
  3. Now, click on Auto forwarded messages report.
  4. Review.
Note: Mail flow reports cannot be viewed from the Classic Exchange Admin Center

Monitor:

To verify mail forwarding rules are being reviewed at least weekly, confirm that the necessary procedures are in place and being followed by the assigned employee.























Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements