Microsoft 365 Security Audit for Small Business: Alert on New Inbox Forwarding Rules

▶ Watch the short explainer for this tip
Every small to medium Australian business relies on email, making it a prime target for cybercriminals. One sneaky tactic they use is setting up forwarding rules to silently siphon off your emails. This tech tip explains how to configure a critical Microsoft 365 alert policy that instantly notifies you when new inbox forwarding rules are created, helping you stay ahead of potential business email compromise (BEC) attempts.
What is an inbox forwarding rule alert?
An inbox forwarding rule alert is a security setting in Microsoft 365 that automatically notifies you when a new rule is created to forward emails from any mailbox. This includes both internal and external forwarding rules, ensuring you're aware of any new email redirection activity.
Why should you set up an alert for new forwarding rules?
You should set up this alert because malicious actors often create inbox forwarding rules after compromising an email account. This allows them to monitor your communications, collect sensitive information, or even redirect payments without you knowing, until it's too late. Prompt alerts enable you to detect and respond to compromises much faster. Want to discuss other ways to harden your email security? Book a complimentary 15-minute chat with Neil about an audit at https://calendly.com/netlogyx/m365audit.
What are the risks if you don't enable this alert?
If you don't enable this alert, a compromised email account could have forwarding rules silently installed, leading to significant financial losses from business email compromise (BEC) attacks, notifiable data breaches (NDB), and damage to your business reputation. Undetected email forwarding can also jeopardise your cybersecurity insurance claims and expose you to privacy law infringements. The longer an attacker goes unnoticed, the more damage they can inflict.
How to set up the inbox forwarding rule alert in Microsoft 365
Here are the verified steps to set up this essential alert in the Microsoft Defender portal: 1. Sign in to security.microsoft.com and go to Email & collaboration > Policies & rules > Alert policy. 2. Check the built-in policy Creation of forwarding/redirect rule is set to On. 3. Select New alert policy, name it, choose the activity New-InboxRule or Set-InboxRule, and set the severity to High. 4. Under Notifications add your own address and any co-admin, tick Send email notifications, then Save.
How to verify the alert works and what to watch out for
To verify the alert works, create a harmless inbox rule in a test mailbox – the alert email should arrive within a few minutes. Busy tenants might generate noise from legitimate rules, so use a daily notification limit rather than switching the alert off entirely. You may also need to warn staff that they might receive these alerts if they legitimately create forwarding rules, so they don't panic unnecessarily. This is a key control we look for in any Microsoft 365 security audit for small business. Book a complimentary 15-minute chat with Neil at https://calendly.com/netlogyx/m365audit.
Important Disclaimer
These steps are accurate at the time of publishing but email platform menus and defaults change. If you are not confident, you should not change settings yourself, because incorrect changes can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Setting up an alert for new inbox forwarding rules is a simple, effective way to significantly reduce your risk of business email compromise. Don't let an attacker silently redirect your emails – get notified immediately and protect your business.
Disclaimer: These steps are accurate at the time of publishing but email platform menus and defaults change. If you are not confident, you should not change settings yourself, because incorrect changes can disrupt email service. SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.
Frequently asked questions
- What is business email compromise (BEC)?
- Business email compromise (BEC) is a type of scam where cybercriminals trick businesses into transferring money or sensitive information to them, often by impersonating executives or trusted partners through compromised email accounts. Setting up forwarding rules is a common tactic used in BEC attacks.
- Will this alert prevent all email compromises?
- While this alert is a critical safeguard, it doesn't prevent all email compromises on its own. It's a crucial early warning system that helps you detect compromises quickly, but a comprehensive cybersecurity strategy, including multi-factor authentication (MFA) and user training, is also essential for a Microsoft 365 security audit for small business.
- Why might legitimate users create forwarding rules?
- Legitimate users might create forwarding rules for various reasons, such as directing emails to a shared mailbox, another department, or for temporary out-of-office arrangements. This is why it's important to use daily notification limits and inform staff that alerts might be triggered by legitimate actions.
- How often should I review my Microsoft 365 alert policies?
- You should review your Microsoft 365 alert policies regularly, at least quarterly, or after any significant changes to your IT environment or staffing. This ensures that your security configurations remain effective and aligned with your business needs.
Sources
Every reference below was link-checked when this article was published.
- 1.Microsoft Defender for Office 365 security recommendationsMicrosoft Learn
- 2.Control automatic external email forwardingMicrosoft Learn
- 3.Security defaults in Microsoft Entra IDMicrosoft Learn
Want to know where your own tenant stands?
The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.


