Governance guide

How to govern Security in Exchange

A step-by-step guide to governing Security in Exchange with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Security in Exchange means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Exchange with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.

Steps

  1. Inventory Exchange

    Connect Exchange and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Security in Exchange to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Exchange reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Exchange controls for Security

Grounded in the Rencore catalog. See the full Exchange catalog on the Exchange connector page.

  • Mailboxes with external redirect rules

    Shows mailboxes which have redirect rules that redirect to external domains

    Severity: High
  • Mailboxes with excessive redirect rules

    Shows mailboxes with more than 10 redirect rules; a known attacker-persistence pattern.

    Severity: Medium
  • Mailboxes auto-replying to all external senders

    Shows mailboxes whose auto-reply is enabled and configured to reply to all external senders.

    Severity: Medium
  • Calendars shared with external users

    Shows calendar permissions granted to users outside of the organization.

    Severity: Medium
  • Calendars with write/delegate access

    Shows calendar permissions that grant write or delegate access to other users.

    Severity: Low
  • Tenant allows external auto-forwarding

    Detects when the outbound spam policy 'AutoForwardingMode' is not set to 'Off', allowing users to auto-forward mail externally.

    Severity: High
  • Remote domain permits auto-forward

    Detects remote domains where automatic forwarding is allowed.

    Severity: High
  • Admin audit log disabled

    Detects when the Exchange admin audit log is disabled, preventing forensic reconstruction of admin actions.

    Severity: High
  • Journal rule sends to external recipient

    Detects Exchange journal rules whose journal mailbox is in an external domain.

    Severity: High
  • EWS application access unrestricted

    Detects when no EWS application access policy is configured, allowing all apps to call EWS.

    Severity: Medium
  • Transport rule modified

    Detects audit events where an Exchange transport rule was created, modified, or removed.

    Severity: High
  • Mailbox permission granted

    Detects audit events where mailbox or recipient permissions were added or removed.

    Severity: Medium
  • Mailbox forwarding setting changed

    Detects audit events whose parameters indicate a mailbox forwarding setting was changed.

    Severity: High
  • Transport rule redirecting to external recipients

    Detects mail flow rules that silently redirect or BCC messages to external domains.

    Severity: High
  • Mail flow connector with wildcard domain

    Detects inbound or outbound connectors with wildcard sender or recipient domains.

    Severity: Medium
  • Accepted domain without DKIM signing

    Detects accepted domains where DKIM signing is not enabled.

    Severity: Medium
  • Distribution group accepts external mail

    Detects distribution lists that allow external senders to deliver messages.

    Severity: Medium
  • Account excluded from mailbox audit

    Detects accounts whose mailbox activity is excluded from audit logging.

    Severity: High
  • Direct role assignment bypassing role groups

    Detects Exchange RBAC role assignments granted directly to users instead of via role groups.

    Severity: Medium
  • Defender policy drifts from Standard baseline

    Detects Defender / EOP security policies that deviate from Microsoft's recommended Standard preset.

    Severity: Medium
Explore the full Exchange governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern