Dev.to AI 🤖 Ai 👁 0 📖 2 min read

How to Audit Microsoft 365 Mailboxes for Hidden Forwarding Rules

When a business mailbox gets compromised, resetting the password is only half the job. Attackers often leave behind forwarding rules that quietly copy every new email to an outside address, even after the password has ch

When a business mailbox gets compromised, resetting the password is only half the job. Attackers often leave behind forwarding rules that quietly copy every new email to an outside address, even after the password has changed.

This guide shows how to audit for those leftovers in Microsoft 365 using PowerShell.

Why this matters

Common persistence tricks after account takeover:

  • Inbox rules that forward or redirect mail externally
  • Mailbox-level forwarding (ForwardingSmtpAddress)
  • Rules that move replies to hidden folders so the owner never sees them
  • OAuth apps with mailbox permissions

If you only reset the password, these can keep working.

Prerequisites

  • An admin account with permission to read mailbox settings
  • The Exchange Online module
Install-Module ExchangeOnlineManagement -Scope CurrentUser
Connect-ExchangeOnline

Test in a non-production tenant or on a single mailbox first, and follow your organization's change policy.

1. Check mailbox-level forwarding

This lists every mailbox that forwards mail somewhere else:

Get-Mailbox -ResultSize Unlimited |
  Where-Object { $_.ForwardingSmtpAddress -ne $null -or $_.ForwardingAddress -ne $null } |
  Select-Object DisplayName, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward

Anything pointing to an external address you don't recognise deserves a closer look.

2. Check inbox rules for one mailbox

Get-InboxRule -Mailbox user@yourdomain.com |
  Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo } |
  Select-Object Name, Enabled, ForwardTo, ForwardAsAttachmentTo, RedirectTo

3. Check inbox rules across all mailboxes

For larger tenants, loop through mailboxes (this can take time):

Get-Mailbox -ResultSize Unlimited | ForEach-Object {
  Get-InboxRule -Mailbox $_.UserPrincipalName |
    Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo } |
    Select-Object @{n='Mailbox';e={$_.MailboxOwnerId}}, Name, Enabled, ForwardTo, RedirectTo
}

4. Remove a suspicious rule

Remove-InboxRule -Mailbox user@yourdomain.com -Identity "Rule Name"

To clear mailbox-level forwarding:

Set-Mailbox -Identity user@yourdomain.com -ForwardingSmtpAddress $null -ForwardingAddress $null

5. Sign out active sessions

Using the Microsoft Graph PowerShell module:

Connect-MgGraph -Scopes "User.ReadWrite.All"
Revoke-MgUserSignInSession -UserId user@yourdomain.com

Post-incident checklist

  • [ ] Reset the password from a trusted device.
  • [ ] Enforce MFA for the account.
  • [ ] Remove unknown forwarding rules and mailbox forwarding.
  • [ ] Revoke active sessions.
  • [ ] Reviewed connected apps and consented to OAuth permissions
  • [ ] Review recently sent items for fraud attempts.
  • [ ] Check whether regulated data was exposed (e.g., HIPAA, PCI-DSS).

Prevent it next time

  • Block automatic external forwarding with an outbound spam policy
  • Turn on audit logging and alerts for new inbox rules.
  • Require MFA for every user
  • Run this audit on a schedule, not only after incidents.

Wrapping up

Hidden forwarding is one of the most common ways account takeovers continue silently. A short scheduled audit catches it early.

I'm Paul, founder of Zia Networks, a managed IT provider supporting small businesses across New Mexico. We also publish a free version for non-technical owners.

What other persistence tricks have you seen after mailbox compromises? Share in the comments.

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.