CTD-000209

Exchange Online organization that allows automatic forwarding to external domains

High
Entra ID Exchange Online
Exfiltration

Signature Identity

CTD-000209
Threat ID
Version
IOE
Indicator Type

Threat Description

An Exchange Online organization that allows automatic forwarding of email to external domains at the tenant level is vulnerable, because it removes a control point that would otherwise limit a threat actor’s ability to exfiltrate data after a single mailbox is compromised. A threat actor exploits this after a phishing or credential-theft attack: once the actor has access to a mailbox, they create a silent forwarding rule and keep receiving sensitive correspondence even after you reset the compromised credentials. Restricting automatic forwarding at the tenant level closes this path, because email stops leaving the organization even when a mailbox forwarding rule survives the password reset.

Example: The organization’s remote domain settings and outbound spam filter policy allow automatic forwarding to external addresses. After a successful phishing attack against an executive’s mailbox, the threat actor configures forwarding of all email to an external address and keeps access to sensitive communications after the compromised password is changed. When automatic forwarding is restricted at the tenant level, and exceptions require approval, the forwarded email is blocked and the threat actor loses that access.

MITRE ATT&CK: Attack Tactics

Exfiltration

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

In the Exchange admin center, turn off automatic forwarding for every remote domain, and then allow it only for the remote domains that your organization has approved.

  1. Sign in to the Exchange admin center.
  2. Under Mail flow, select Remote domains.
  3. Select a remote domain in the list.
  4. Under Email reply types, select Edit reply types.
  5. Clear the Allow automatic forwarding checkbox.
  6. Select Save.
  7. Leave Allow automatic forwarding selected only for domains that your organization has approved, and only if you keep the outbound anti-spam policy set to Automatic – System-controlled.

In the Microsoft Defender portal, confirm that the outbound anti-spam policy also blocks automatic forwarding.

  1. Sign in to the Microsoft Defender portal.
  2. Under Email & collaboration, select Policies & rules.
  3. Select Threat policies.
  4. Select Anti-spam policies.
  5. Select Anti-spam outbound policy (Default).
  6. Select Edit protection settings.
  7. Under Forwarding rules, set Automatic forwarding rules to Off – Forwarding is disabled.
  8. Select Save.

Note: When Anti-spam outbound policy (Default) is set to Off – Forwarding is disabled, the outbound policy acts as a hard block and takes precedence over remote domain settings. Microsoft Defender for Office 365 then blocks all automatic external forwarding, even for remote domains where your organization allows it.

More information: Control external email forwarding and fix 5.7.520 errors

Frequently Asked Questions

What does Exchange Online organization that allows automatic forwarding to external domains mean?

An Exchange Online organization that allows automatic forwarding of email to external domains at the tenant level means that email can be forwarded to external addresses without any restrictions, potentially exposing sensitive data to unauthorized access through SMTP relay.

This configuration is considered high severity because it removes a control point that limits a threat actor's ability to exfiltrate data after a single mailbox is compromised, making it easier for attackers to access sensitive information via email forwarding.

Attackers can abuse this configuration by creating a silent forwarding rule in a compromised mailbox, allowing them to receive sensitive correspondence via email forwarding even after the compromised credentials are reset.

Cayosoft Guardian continuously monitors for Exchange Online organization that allows automatic forwarding to external domains and alerts administrators when the condition is detected. This provides visibility into the exposure so security teams can review the finding and determine whether investigation or response is required. Guardian monitors Exchange Online and Entra ID for this condition and flags it when detected.

Cayosoft Guardian helps reduce the risk of Exchange Online organization that allows automatic forwarding to external domains by alerting administrators when the condition is detected and providing visibility into the affected mailboxes, inbox rules, and permissions. This helps security teams identify exposure more quickly and respond before the issue contributes to a larger security event.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Mailbox protection
Attack Tactics
Exfiltration
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical