How to govern Security in Exchange
A step-by-step guide to governing Security in Exchange with Rencore: detect, review by owner and severity, and remediate with an audit trail.
Governing Security in Exchange means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Exchange with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.
Steps
-
Inventory Exchange
Connect Exchange and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Security in Exchange to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Exchange reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Exchange controls for Security
Grounded in the Rencore catalog. See the full Exchange catalog on the Exchange connector page.
-
Mailboxes with external redirect rules
Shows mailboxes which have redirect rules that redirect to external domains
Severity: High -
Mailboxes with excessive redirect rules
Shows mailboxes with more than 10 redirect rules; a known attacker-persistence pattern.
Severity: Medium -
Mailboxes auto-replying to all external senders
Shows mailboxes whose auto-reply is enabled and configured to reply to all external senders.
Severity: Medium -
Calendars shared with external users
Shows calendar permissions granted to users outside of the organization.
Severity: Medium -
Calendars with write/delegate access
Shows calendar permissions that grant write or delegate access to other users.
Severity: Low -
Tenant allows external auto-forwarding
Detects when the outbound spam policy 'AutoForwardingMode' is not set to 'Off', allowing users to auto-forward mail externally.
Severity: High -
Remote domain permits auto-forward
Detects remote domains where automatic forwarding is allowed.
Severity: High -
Admin audit log disabled
Detects when the Exchange admin audit log is disabled, preventing forensic reconstruction of admin actions.
Severity: High -
Journal rule sends to external recipient
Detects Exchange journal rules whose journal mailbox is in an external domain.
Severity: High -
EWS application access unrestricted
Detects when no EWS application access policy is configured, allowing all apps to call EWS.
Severity: Medium -
Transport rule modified
Detects audit events where an Exchange transport rule was created, modified, or removed.
Severity: High -
Mailbox permission granted
Detects audit events where mailbox or recipient permissions were added or removed.
Severity: Medium -
Mailbox forwarding setting changed
Detects audit events whose parameters indicate a mailbox forwarding setting was changed.
Severity: High -
Transport rule redirecting to external recipients
Detects mail flow rules that silently redirect or BCC messages to external domains.
Severity: High -
Mail flow connector with wildcard domain
Detects inbound or outbound connectors with wildcard sender or recipient domains.
Severity: Medium -
Accepted domain without DKIM signing
Detects accepted domains where DKIM signing is not enabled.
Severity: Medium -
Distribution group accepts external mail
Detects distribution lists that allow external senders to deliver messages.
Severity: Medium -
Account excluded from mailbox audit
Detects accounts whose mailbox activity is excluded from audit logging.
Severity: High -
Direct role assignment bypassing role groups
Detects Exchange RBAC role assignments granted directly to users instead of via role groups.
Severity: Medium -
Defender policy drifts from Standard baseline
Detects Defender / EOP security policies that deviate from Microsoft's recommended Standard preset.
Severity: Medium