Technical guide · Exchange Online

Exchange Online Security Assessment Checklist

Use this checklist to examine the Exchange control plane around mailboxes, administrative access, routing, forwarding, legacy protocols, auditing, and domain trust. It complements, but does not duplicate, a Defender for Office 365 review.

Environment map

1. Document how mail and administration reach Exchange Online.

Begin with accepted domains, mailbox populations, shared and resource mailboxes, hybrid dependencies, third-party gateways, application senders, connectors, and the administrators or service principals that can change Exchange. The goal is to establish the real trust boundary before evaluating individual settings.

  • List accepted, authoritative, internal relay, and unused domains, including subdomains used to send mail.
  • Map inbound and outbound routing, MX targets, third-party filters, hybrid servers, partner paths, applications, printers, and bulk senders.
  • Inventory Exchange administrative roles, role groups, delegated administration, service principals, and emergency access dependencies.
  • Identify mailbox types, executive or payment-sensitive users, external forwarding requirements, and high-impact shared mailboxes.
  • Record business owners for mail flow rules, connectors, accepted domains, forwarding exceptions, and application-sending methods.
Identity and mailbox access

2. Review who can administer, impersonate, delegate, and forward.

Exchange exposure is shaped by both tenant-wide settings and per-mailbox exceptions. Sample high-impact populations rather than assuming the organization default tells the whole story.

Administrative roles

Review Exchange Administrator and role-group membership, custom management roles, delegated access, standing privilege, inactive administrators, separation of duties, and whether privileged access is protected through Entra ID controls.

Mailbox permissions

Inspect Full Access, Send As, Send on Behalf, folder delegation, shared mailbox ownership, inactive delegates, automapping assumptions, and access granted to applications or service accounts.

Forwarding and Inbox rules

Identify mailbox forwarding, forwarding SMTP addresses, external Inbox rules, remote-domain behavior, and justified exceptions. Microsoft notes that compromised accounts can use forwarding to disclose information.

Legacy and application access

Review authentication policies, POP and IMAP use, application sending patterns, OAuth use where supported, service-account lifecycle, and Conditional Access dependencies. Do not break production senders without a tested replacement.

Mailbox lifecycle

Examine conversion to shared mailboxes, former-employee access, inactive mailboxes, litigation or retention dependencies, aliases, group ownership, and removal of stale permissions after job changes or departures.

Mail flow and trust

3. Trace every path that changes filtering or sender trust.

Rules and connectors often accumulate around business systems. Review their continued need and combined effect before recommending removal.

Mail flow rules

Export enabled and disabled rules with priority, conditions, exceptions, actions, dates, and owners. Pay particular attention to SCL bypass, broad allow logic, redirects, Bcc or journaling behavior, attachment actions, header changes, and rules that stop further processing.

Connectors

Confirm the business scenario, direction, scope, TLS requirements, certificate or IP restrictions, validation status, and overlap for each connector. Microsoft notes that most cloud-only organizations do not need connectors for ordinary internet mail flow.

Third-party gateways

Where mail is filtered before Microsoft 365, validate the original sender path, inbound connector restrictions, and Enhanced Filtering for Connectors. Broad filtering bypass can prevent Microsoft controls from evaluating messages as intended.

Application and device mail

Inventory printers, scanners, line-of-business systems, marketing platforms, relays, direct send, SMTP AUTH, and connector-based delivery. Confirm sender restrictions, monitoring, ownership, and a supported replacement for obsolete methods.

Accepted and remote domains

Review unused or stale domains, relay behavior, default remote-domain settings, external automatic replies, forwarding controls, and whether partner-specific behavior remains justified.

Transport security

Review partner connectors that require TLS, certificate or domain validation, fallback behavior, and operational monitoring. A TLS setting without validated scope and partner coordination can create either exposure or avoidable delivery failure.

Domain authentication

4. Validate every legitimate sending source.

  • SPF records include the intended senders without multiple records, obsolete services, or excessive lookup risk.
  • DKIM signing is enabled for each custom domain or subdomain that sends through Microsoft 365.
  • DMARC policy and alignment match the actual sender inventory and a staged enforcement plan.
  • Parked or non-sending domains have an explicit anti-spoofing strategy.
  • Third-party senders use an agreed alignment pattern instead of silently weakening the organizational domain.
  • Aggregate reports, failures, and DNS ownership have named reviewers and a change process.

Microsoft’s DKIM guidance states that DKIM is only one part of the strategy and should be used with SPF and DMARC.

Outbound protection

Control forwarding and compromised senders.

  • Review default and custom outbound spam policy coverage and precedence.
  • Verify automatic external forwarding behavior and every population-specific exception.
  • Inspect alert recipients and the process for users restricted from sending.
  • Use the auto-forwarded messages and outbound messages reports as operational evidence.
  • Separate legitimate bulk or application mail from ordinary user mailboxes where appropriate.
  • Document who can restore sending and what identity investigation must happen first.

Microsoft documents the available controls in its guidance for external email forwarding and outbound spam policies.

Audit and operations

5. Verify that the evidence needed after an incident will exist.

Mailbox auditing

Microsoft states that mailbox auditing is on by default, but reviewers should verify the organization setting, default audit sets, mailbox-specific changes, bypass associations, licensing, retention, and access to search. A default is not evidence that no one changed it.

Mail flow reporting

Review message trace and reports for forwarding, outbound activity, transport rules, non-accepted domains, and delivery failures. Confirm retention, permissions, escalation, and whether the team knows how to retrieve evidence under time pressure.

Change governance

Identify how rules, connectors, permissions, domains, and forwarding exceptions are requested, tested, approved, recorded, monitored, and retired. Sample recent changes to determine whether the process operates.

Assessment boundary: review produces findings and an action plan. Mail flow, DNS, authentication, and mailbox changes should be implemented under a separately approved plan with testing and rollback.
Decision-ready result

Organize findings by attack path and operational consequence.

A useful Exchange Online assessment does more than list PowerShell output. It connects each observed condition to affected mailboxes or domains, effective scope, business purpose, evidence, plausible abuse, current monitoring, and a safe corrective sequence.

  • Administrative and mailbox-access findings with affected identities and owners
  • Mail flow map with rules, connectors, bypasses, and application senders
  • Forwarding, protocol, domain-authentication, and outbound-control findings
  • Audit and response gaps that limit investigation or containment
  • Prioritized remediation roadmap with dependencies and validation steps

Review the Exchange Online assessment service, pair it with the Defender for Office 365 checklist, or inspect the sample assessment.

Frequently asked questions

Clarify scope before evidence collection.

Is an Exchange Online assessment only an email-filtering review?

No. A useful review also considers administrative access, mailbox delegation, forwarding, SMTP AUTH, mail flow rules, connectors, accepted domains, auditing, alerting, and domain authentication. Defender for Office 365 is a related but distinct protection layer.

Should all mail flow rules and connectors be removed?

No. Many support legitimate applications, partners, hybrid routing, or policy requirements. The objective is to validate ownership, scope, precedence, security conditions, and continued business need, then remove or redesign only what is unjustified.

Is mailbox auditing enough for incident response?

No. Mailbox auditing is one evidence source. Useful response also depends on audit availability and retention, alert routing, message trace and investigation capabilities, identity telemetry, documented ownership, and practiced procedures.

Will this assessment configure SPF, DKIM, or DMARC?

Assessment identifies observed conditions and a recommended sequence. DNS and tenant changes belong in a separately approved remediation scope with testing, rollback, and responsibility clearly assigned.

Understand who can change mail, redirect it, or bypass protection.

Request an Exchange Online assessment to turn roles, mailbox access, routing, forwarding, authentication, and audit evidence into a prioritized plan.