CTD-000211

Exchange Online connector allowing unauthenticated inbound relay

Critical
Entra ID Exchange Online
Impact Initial Access

Signature Identity

CTD-000211
Threat ID
Version
IOE
Indicator Type

Threat Description

An inbound connector that accepts email without requiring authentication or a restricted, verified sender IP range is a vulnerability, because it allows any external system to relay email through your organization’s infrastructure as if that system were internal or trusted. A threat actor exploits this by sending spoofed or malicious email through the misconfigured connector, which bypasses some of the spam and authentication checks that would otherwise apply to ordinary inbound email. Restricting inbound connectors to known sources that are authenticated or IP-restricted mitigates this exposure.

Example: A hybrid mail flow connector intended for a legacy on-premises application is left configured to accept email from any IP address without authentication. A threat actor discovers the connector and relays spoofed executive-impersonation email through it. Downstream filters treat that email with elevated trust because it arrived through an internal connector. Restricting the connector to specific verified source IP addresses, and requiring TLS and authentication, removes this abuse path.

MITRE ATT&CK: Attack Tactics

Impact Initial Access

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

In the Exchange admin center, restrict each inbound connector so that it rejects email that isn’t sent over TLS or doesn’t come from a verified IP address range. Then remove or turn off the connectors that your organization no longer needs.

  1. Sign in to the Exchange admin center.
  2. Under Mail flow, select Connectors.
  3. In the connector list, select the name of the inbound connector that you want to change.
  4. In the Security restrictions section, select Edit restrictions.
  5. Select the Reject email messages if they aren’t sent over TLS checkbox.
  6. Optional: To also validate the partner’s certificate, select And require that the subject name on the certificate that the partner uses to authenticate with Office 365 matches this domain name, and then enter the partner’s domain name.
  7. Select the Reject email messages if they aren’t sent from within this IP address range checkbox, and then enter only the verified, trusted IP ranges.
  8. Select Save.
  9. Repeat steps 3 through 8 for each remaining inbound connector in the list.

To handle a connector that your organization no longer needs, do one of the following:

  • To delete the connector permanently:
    1. In the connector list, select the connector.
    2. Select Delete, and then confirm the deletion.
  • To turn off the connector without deleting it:
    1. In the connector list, select the name of the connector.
    2. In the Status section, select Edit name or status.
    3. Clear the Turn it on checkbox.
    4. Select Save.

More information: Configure mail flow using connectors in Exchange Online

Frequently Asked Questions

What does Exchange Online connector allowing unauthenticated inbound relay mean?

An inbound connector that accepts email without requiring authentication or a restricted, verified sender IP range, allowing any external system to relay email through your organization's infrastructure as if that system were internal or trusted.

This vulnerability allows attackers to send email through the misconfigured connector without being subject to the same spam and authentication checks as ordinary inbound email, potentially leading to spoofed or malicious email being delivered to users.

Attackers can exploit this vulnerability by sending spoofed or malicious email through the misconfigured connector, which is treated with elevated trust by downstream filters because it arrived through an internal connector, allowing them to bypass some security checks.

Cayosoft Guardian continuously monitors for Exchange Online connector allowing unauthenticated inbound relay and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Exchange Online and Entra ID for this condition and flags it when detected.

Cayosoft Guardian helps reduce the risk of Exchange Online connector allowing unauthenticated inbound relay by alerting administrators when the condition is detected and providing visibility into the affected mailboxes, inbox rules, and permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Privileged Access Management
Attack Tactics
Impact Initial Access
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical