Exchange Auto forwarded message report filter?

M00nshine 40 Reputation points
2023-04-06T09:43:30.3133333+00:00

Hello, We currently utilise the Auto forwarded message report Auto forwarded message report feature on Exchange (Reports > Mailflow > Auto forward message report). We are alerted into Defender for any new auto-forward rules set up in our estate which are forwarding to external domains. The function however, comes across as quite crude. For example, the alerts do not contain the actual user(s) who have triggered the alert - they essentially only state that a new user has been detected. Our current process of checking who the perpetrator is, is by exporting the list of users who have triggered it in the last 7 days, and manually comparing that with a list of 'approved users' we have stored on our SP to highlight the new unique values. There is an option to filter the results you get from the last 7 days, and you can 'create new filter'. We've tried this by manually crafting the filter to 'ignore' our approved users, however it's not very dynamic so isn't worth using (I also can't find any documentation on how to fully utilise this [even to the point of deleting old filters] anywhere so any tips are appreciated). I'm looking for a better way for this to be managed. Ideally we would like the auto-forward feature to check against a pre-determined list of approved users, before alerting us to potential new forwarders. If the new perpetrator could be included in the alert details, then bonus! However, any ideas on how we can better utilise this function would be great. Thanks!

Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
446 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
{count} votes

Accepted answer
  1. Aholic Liang-MSFT 13,826 Reputation points Microsoft Vendor
    2023-04-14T06:47:14.6466667+00:00

    Hi @ M00nshine, Perhaps you can set up a mail flow rule that, when it detects that a message has been auto forward outside your organization, automatically forwards the message for review by a designated administrator, and then sets up exception recipients.

    User's image


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Aholic Liang-MSFT 13,826 Reputation points Microsoft Vendor
    2023-04-07T09:00:34.6166667+00:00

    Hi @ M00nshine, Welcome to the Microsoft Q&A platform!

    Kindly note that this forum mainly focuses on general usage issues and is not the suitable place for feedback.

    If you would like to submit feedback to Microsoft, please consider posting in the Exchange Server · Community (microsoft.com).

    Many features of our current products are designed and upgraded based on customers’ feedback. With requirements like this increase, the problem may well be released in the future.

    Thanks for your understanding and support.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread

    0 comments No comments

  2. M00nshine 40 Reputation points
    2023-04-11T10:36:57.1166667+00:00

    Hello, I appreciate my question did include feedback, however it did so to justify my request for assistance. I requested any tips/utilisation ideas from other users and how they may manage this type of security issue, so I believe this Q resides in the correct place. Thanks

    0 comments No comments