Why forwarding deserves a scheduled review
Business email compromise does not always announce itself with a locked account. An attacker who gains mailbox access may create forwarding rules, add delegates, or alter inbox processing so messages continue flowing to an unauthorized destination. The account owner may still sign in normally while invoices, legal correspondence, or customer information are copied elsewhere.
Microsoft provides administrators with controls and audit records for mailbox forwarding and inbox rules. A small Central Florida business can turn those capabilities into a short recurring review.
1. Define the review population
Start with executives, finance staff, administrators, shared mailboxes, and people who handle confidential records. Include recently transferred and departed employees. Record the mailbox owner, business purpose, approved delegates, and whether external forwarding is permitted.
2. Check mailbox-level forwarding
Review the forwarding address and the option to retain a copy in the original mailbox. An unexpected destination, especially an external address, requires investigation. Do not assume a familiar-looking address is legitimate; validate it through a known contact method and compare it with an approved change record.
3. Inspect inbox rules and delegates
Look for rules that forward, redirect, delete, hide, or move messages involving payments, passwords, security alerts, or executives. Review Send As, Send on Behalf, and Full Access permissions. Confirm that each delegate still has a current business need and that access was approved by the mailbox owner or responsible manager.
4. Review audit evidence
Microsoft Purview audit can help identify rule creation and mailbox permission changes, subject to licensing and retention. Record the date range reviewed, the events available, who reviewed them, and any gaps. If suspicious activity is found, preserve evidence before making broad changes.
5. Respond as an identity incident
An unauthorized rule may indicate compromised credentials or sessions. Follow the incident plan: disable or contain access, revoke sessions, reset credentials, verify multifactor authentication methods, inspect connected applications, and determine what information may have been exposed. Coordinate legal, insurance, and reporting decisions as appropriate.
Make the check repeatable
Run the review quarterly and after employee departures, payment fraud attempts, suspicious sign-ins, or administrative changes. Keep a simple evidence record: mailboxes reviewed, exceptions found, approvals confirmed, remediation completed, and next review date.
The goal is not to ban every legitimate workflow. It is to make hidden mail movement visible, attributable, and periodically revalidated.
Human-reviewed draft; verify Microsoft licensing, current interface behavior, retention, and legal duties before publication.

