Microsoft Exchange Online security audit
Corporate email is the favorite channel for CEO fraud, targeted phishing and persistence after an account compromise. We analyze your Exchange Online beyond MFA: forwarding rules, delegated permissions, connectors and domain authentication.
Do you know what an attacker could do with access to a mailbox in your company?
Most email security reviews stop at whether MFA is enabled. But CEO fraud, persistence after an account compromise and much of the lateral movement that follows go through hidden forwarding rules, unreviewed delegated permissions, misconfigured connectors and overly permissive accepted domains. A real Exchange Online audit confirms what an attacker could actually do with access to a mailbox, not just whether the right checkbox is ticked.
What the Exchange Online audit covers
- Malicious forwarding rules: detecting persistence after an account compromise
- Delegated permissions and mailbox access: who can read or send on behalf of others
- Connectors and accepted domains: the risk of becoming an open relay
- Transport rules (mail flow rules): possible bypasses of anti-phishing filters
- Domain authentication: correct SPF, DKIM and DMARC configuration
- Mailbox Audit Log and log retention
How we run the Exchange audit
- Scope and access: We agree which mailboxes and domains are in scope. We only need a read-only role over Exchange Online, no user credentials.
- Configuration review: We analyze transport rules, connectors, accepted domains and anti-phishing policies against the CIS Benchmark.
- Delegated permissions analysis: We review who has full access, "send on behalf of" or "send as" rights on each critical mailbox.
- Persistence vector simulation: We check whether hidden forwarding rules can be created or misconfigured connectors abused, the way an attacker would after compromising an account.
- Report and remediation: We deliver risk-prioritized findings with concrete remediation steps.
Deliverables
- Executive report with risk in business terms
- Technical report with each finding and step-by-step remediation
- Map of delegated permissions and active forwarding rules
- Exchange Online hardening checklist against the CIS Benchmark
- Closing meeting with your IT team
- Optional re-test to verify fixes
Who needs this service?
- Companies that have suffered CEO fraud or targeted email phishing
- Organizations that have never audited their forwarding rules or delegated permissions
- Companies migrating from on-premise Exchange to Exchange Online
- Regulated sectors that need to evidence email security controls for NIS2, ENS or ISO 27001
- Companies with several mail administrators and no periodic permission review
Frequently asked questions
Does this replace the general Microsoft 365 audit?
Not necessarily. If email is your most critical system or you've already had an email-related incident, it makes sense as a standalone engagement. If you want a full tenant review (Entra ID, SharePoint, Teams, OAuth apps), the Microsoft 365 audit is the better fit.
Do you need global admin access?
No. A read-only role over Exchange Online (for example, Exchange Recipient Administrator) is enough for most of the analysis.
Does it disrupt mail flow?
No. The analysis covers configuration and permissions, and doesn't affect production mail flow.
Can you detect an ongoing compromise?
Analyzing forwarding rules and delegated permissions can reveal the persistence of an attacker who already compromised an account, though this isn't an incident response service.
Is the report valid for regulatory compliance?
Yes. The report is valid as technical control evidence for corporate email security under NIS2, ENS or ISO 27001.