SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Stop external auto-forwarding and enable forwarding alerts in Microsoft 365

A practical, step-by-step guide for Australian businesses. Block attackers from silently exfiltrating email through external forwarding rules, and configure alerts that catch suspicious mailbox-rule activity.

Microsoft 365 email shield blocking external auto-forwarding with alert bell

Recommended method: block external auto-forwarding tenant-wide, then alert on exceptions

External forwarding allows email received by a Microsoft 365 mailbox to be automatically sent to an address outside the organisation. Attackers commonly create forwarding rules after compromising an account so they can silently receive confidential emails. Microsoft recommends blocking automatic external forwarding unless there is a documented business requirement. Internal forwarding between users in the same Microsoft 365 organisation is not affected.

Before you begin

You will need:

  • An account with appropriate administrative permissions, such as Security Administrator, Exchange Administrator or Global Administrator.
  • Use a separate administrative account for these changes.
  • Confirm that you have emergency administrative access before changing security policies.
1

Check for existing external forwarding

Before blocking forwarding, identify any users or systems that currently depend on it.

  • Sign in to the Microsoft Defender portal.
  • Go to Reports.
  • Select Email & collaboration.
  • Open the Auto-forwarded messages report.
  • Review forwarding activity for the previous 30 to 90 days.
  • Record the originating mailbox, the external destination, the volume of forwarded email, whether the forwarding is still required, and the business owner who approved it.
  • Investigate any forwarding that is unexpected or cannot be explained.

If malicious forwarding is suspected

  • Preserve the details rather than simply deleting the rule.
  • Investigate the user’s sign-in activity.
  • Reset their credentials and revoke active sessions.
  • Review the mailbox for additional malicious rules.

Microsoft documents the available reporting and forwarding controls in its external email forwarding guidance.

2

Block external automatic forwarding

Recommended tenant-wide configuration:

  • Sign in to the Microsoft Defender portal.
  • Go to Email & collaboration → Policies & rules.
  • Select Threat policies.
  • Under Policies, select Anti-spam.
  • Locate Outbound spam filter policy (Default).
  • Select the policy and then select Edit protection settings.
  • Find Automatic forwarding rules.
  • Select Off – Forwarding is disabled.
  • Select Save.
  • Confirm that the policy remains enabled and applies to all users not covered by a higher-priority outbound spam policy.

Do not leave this setting as Automatic – System-controlled. Microsoft notes that its behaviour can differ between organisations. Selecting Off – Forwarding is disabled makes the intended configuration explicit.

When Microsoft 365 identifies an automatically forwarded message to an external recipient, it will block the message. The sender may receive an NDR containing error 5.7.520, advising that the organisation does not permit external forwarding.

3

Create controlled exceptions, if necessary

Avoid changing the default policy back to On simply because one mailbox requires forwarding. Where there is a genuine and approved business requirement:

  • Return to Email & collaboration → Policies & rules → Threat policies → Anti-spam.
  • Select Create policy → Outbound.
  • Enter a descriptive name, such as Approved External Forwarding Exception.
  • Add only the specifically approved users, groups or domains.
  • Set Automatic forwarding rules to On – Forwarding is enabled.
  • Give the exception policy a higher priority than the default outbound policy.
  • Save the policy.
  • Test the forwarding with non-confidential email.
  • Document the mailbox, forwarding destination, business reason, approving person, and review or expiry date.
  • Review exceptions regularly and remove them when no longer required.

An approved exception should preferably use a managed company-owned destination rather than a personal Gmail, Outlook.com or ISP mailbox.

4

Enable Microsoft’s forwarding-related alerts

Microsoft Defender can generate alerts for suspicious forwarding and inbox-rule behaviour.

  • Sign in to the Microsoft Defender portal.
  • Go to System → Settings.
  • Select Microsoft Defender XDR → Email & collaboration.
  • Open Alert policy. Depending on the portal layout, alert policies may instead appear under Email & collaboration → Policies & rules → Alert policy.
  • Search for forwarding-related policies, including Suspicious email forwarding activity, Suspicious inbox manipulation rule, and Creation of forwarding/redirect rule if available in your tenant.
  • Open each applicable policy.
  • Confirm that its status is Enabled.
  • Review the policy severity and notification settings.
  • Add monitored recipients, such as the IT administrator, the managed service provider, or a dedicated security-alert mailbox.
  • Save any changes.

The available policies and ability to edit them can depend on the organisation’s Microsoft 365 and Defender licensing.

Microsoft provides an investigation process for suspicious inbox forwarding rules.

Important limitation about “any forwarding rule”

Microsoft’s built-in Defender alerts are threat-based. They may alert only when forwarding behaviour is considered suspicious; they should not automatically be assumed to notify you about every legitimate or attempted forwarding configuration.

For reliable monitoring of every relevant change, the Microsoft Purview audit log should also be monitored for operations such as:

  • New-InboxRule
  • Set-InboxRule
  • Remove-InboxRule
  • Set-Mailbox

These records can identify who created or modified mailbox rules. Microsoft explains these audit events in its mailbox-rule investigation guidance.

Organisations requiring near-real-time notification for every rule change may need Microsoft Sentinel, Power Automate, a third-party Microsoft 365 monitoring platform or another system that regularly analyses the audit log. Alerts must also be filtered carefully because New-InboxRule and Set-InboxRule include ordinary mailbox rules, not only external forwarding rules.

5

Test the protection

  • Use a designated test mailbox rather than a production executive or finance mailbox.
  • Create an Outlook rule that attempts to forward email to an external test address.
  • Send a harmless test message to the Microsoft 365 mailbox.
  • Confirm that the message is not delivered to the external address.
  • Check whether the sender receives an NDR.
  • Review Microsoft Defender alerts, the Auto-forwarded messages report, and Microsoft Purview audit records.
  • Confirm that alert notifications are delivered to the nominated security recipients.
  • Remove the test rule when testing is complete.

Policy changes, reports and alerts may not appear immediately. Allow time for Microsoft 365 to distribute the policy and process audit information.

Warnings

  • Blocking external forwarding can interrupt legitimate workflows, including forwarding to personal accounts, ticketing systems, CRMs, archiving platforms or external service providers.
  • Users may receive non-delivery reports after the policy is enabled.
  • Do not create broad exception policies for all users or entire domains without a documented requirement.
  • A forwarding alert can indicate an account compromise. Investigate the account rather than treating the alert only as a configuration issue.
  • Removing a malicious rule does not remove an attacker’s access. Reset credentials, revoke sessions, confirm MFA registration and review sign-in and mailbox activity.
  • Transport rules, remote-domain settings and outbound spam policies can interact. Where one setting allows forwarding and another blocks it, the blocking control will generally take precedence.
  • Do not test using sensitive, personal, legal, medical or financial information.
  • Regularly review approved exceptions, alert recipients and the auto-forwarding report.

Recommended final configuration

Default outbound spam policyOff – Forwarding is disabled
ExceptionsOnly individually approved and documented mailboxes
Defender forwarding alertsEnabled
NotificationsSent to an actively monitored security mailbox
Audit-log monitoringEnabled for rule creation and modification
Review frequencyAt least monthly and after every forwarding alert

Microsoft 365 disclaimer

These instructions are general security guidance and may not match every Microsoft 365 tenant, licence or business workflow. Microsoft changes portal layouts and feature availability over time. Blocking external forwarding can interrupt legitimate mail delivery or third-party integrations.

Before making changes, review existing forwarding activity, document required exceptions, test with a limited group where practical and ensure emergency administrative access is available. If you are uncertain about the effect on your organisation, engage a qualified Microsoft 365 engineer or managed service provider to assess, implement and verify the configuration.