How to find users who have automatic email forwarding configured in Microsoft 365?
+
Though we have configured external email forwarding rules for a specific external domain, it is highly essential to track the forwarding configured users to identify risky forwarding rules that could lead to data leaks or breaches.
The Auto Forwarded Messages report in the Exchange Online admin center provides details on users who have automatically forwarded messages to external recipients. Also, this report provides insights into how messages are being automatically forwarded from your organization's mailboxes to external recipients.
Additionally, it contains the following details that will help you to detect potential unauthorized or non-compliant email forwarding practices.
- User Information: It displays which users have set up automatic forwarding on their mailboxes.
- Recipient Details: Shows the external recipients to whom emails are being forwarded.
- Forwarding Methods: Provide details on how the forwarding is set up, whether through inbox rules or other configurations.
- Date and Time Stamps: Provides information on when the forwarding rules were created or when emails were forwarded.
- Volume of Forwarded Emails: Indicates the number of emails forwarded over a specified period.
However, the report might not provide the deep forensic details necessary for complex investigations.
You can use the alert policy template ‘Creation of external forwarded rule’ to generate alerts when a new external forwarded email rule is created in Outlook by Microsoft 365 users.
To create an alert policy from templates,
- Navigate to the ‘Alert Policy Templates’ under Alerts.
- Click the ‘Preview & Deploy’ button to configure an alert policy and get alerted whenever the external forwarding rule has been created.
- Pro Tip: Make use of the different scopes available to set up AdminDroid alerts based on specific properties instead of organization-wide notifications.