Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
An Exchange Online organization that allows automatic forwarding of email to external domains at the tenant level is vulnerable, because it removes a control point that would otherwise limit a threat actor’s ability to exfiltrate data after a single mailbox is compromised. A threat actor exploits this after a phishing or credential-theft attack: once the actor has access to a mailbox, they create a silent forwarding rule and keep receiving sensitive correspondence even after you reset the compromised credentials. Restricting automatic forwarding at the tenant level closes this path, because email stops leaving the organization even when a mailbox forwarding rule survives the password reset.
Example: The organization’s remote domain settings and outbound spam filter policy allow automatic forwarding to external addresses. After a successful phishing attack against an executive’s mailbox, the threat actor configures forwarding of all email to an external address and keeps access to sensitive communications after the compromised password is changed. When automatic forwarding is restricted at the tenant level, and exceptions require approval, the forwarded email is blocked and the threat actor loses that access.
D3FEND: Defend Tactics
In the Exchange admin center, turn off automatic forwarding for every remote domain, and then allow it only for the remote domains that your organization has approved.
In the Microsoft Defender portal, confirm that the outbound anti-spam policy also blocks automatic forwarding.
Note: When Anti-spam outbound policy (Default) is set to Off – Forwarding is disabled, the outbound policy acts as a hard block and takes precedence over remote domain settings. Microsoft Defender for Office 365 then blocks all automatic external forwarding, even for remote domains where your organization allows it.
More information: Control external email forwarding and fix 5.7.520 errors
An Exchange Online organization that allows automatic forwarding of email to external domains at the tenant level means that email can be forwarded to external addresses without any restrictions, potentially exposing sensitive data to unauthorized access through SMTP relay.
This configuration is considered high severity because it removes a control point that limits a threat actor's ability to exfiltrate data after a single mailbox is compromised, making it easier for attackers to access sensitive information via email forwarding.
Attackers can abuse this configuration by creating a silent forwarding rule in a compromised mailbox, allowing them to receive sensitive correspondence via email forwarding even after the compromised credentials are reset.
Cayosoft Guardian continuously monitors for Exchange Online organization that allows automatic forwarding to external domains and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Exchange Online and Entra ID for this condition and flags it when detected.
Cayosoft Guardian helps reduce the risk of Exchange Online organization that allows automatic forwarding to external domains by alerting administrators when the condition is detected and providing visibility into the affected mailboxes, inbox rules, and permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack