Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
An inbound connector that accepts email without requiring authentication or a restricted, verified sender IP range is a vulnerability, because it allows any external system to relay email through your organization’s infrastructure as if that system were internal or trusted. A threat actor exploits this by sending spoofed or malicious email through the misconfigured connector, which bypasses some of the spam and authentication checks that would otherwise apply to ordinary inbound email. Restricting inbound connectors to known sources that are authenticated or IP-restricted mitigates this exposure.
Example: A hybrid mail flow connector intended for a legacy on-premises application is left configured to accept email from any IP address without authentication. A threat actor discovers the connector and relays spoofed executive-impersonation email through it. Downstream filters treat that email with elevated trust because it arrived through an internal connector. Restricting the connector to specific verified source IP addresses, and requiring TLS and authentication, removes this abuse path.
D3FEND: Defend Tactics
In the Exchange admin center, restrict each inbound connector so that it rejects email that isn’t sent over TLS or doesn’t come from a verified IP address range. Then remove or turn off the connectors that your organization no longer needs.
To handle a connector that your organization no longer needs, do one of the following:
More information: Configure mail flow using connectors in Exchange Online
An inbound connector that accepts email without requiring authentication or a restricted, verified sender IP range, allowing any external system to relay email through your organization's infrastructure as if that system were internal or trusted.
This vulnerability allows attackers to send email through the misconfigured connector without being subject to the same spam and authentication checks as ordinary inbound email, potentially leading to spoofed or malicious email being delivered to users.
Attackers can exploit this vulnerability by sending spoofed or malicious email through the misconfigured connector, which is treated with elevated trust by downstream filters because it arrived through an internal connector, allowing them to bypass some security checks.
Cayosoft Guardian continuously monitors for Exchange Online connector allowing unauthenticated inbound relay and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Exchange Online and Entra ID for this condition and flags it when detected.
Cayosoft Guardian helps reduce the risk of Exchange Online connector allowing unauthenticated inbound relay by alerting administrators when the condition is detected and providing visibility into the affected mailboxes, inbox rules, and permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack