Exchange Online security posture after a brutal year for mail

Exchange Online security after ProxyLogon year: reduce on-prem surface, MFA, legacy auth, external forwarding, and hybrid server hardening.

2021 taught the industry that on-prem Exchange on the open internet is a gift to attackers. Even estates that moved mailboxes to Exchange Online still inherit risk through hybrid servers, legacy auth, forwarding abuse, and admin sprawl. This post is a November security posture checklist for Microsoft 365 mail — practical controls after ProxyLogon-era urgency.

Shrink what remains on-prem

If hybrid Exchange still exists:

  • Not on the public internet if avoidable
  • Patched on an emergency cadence
  • Admin access jump-boxed
  • Clear timeline to minimize role

Every month of “temporary hybrid forever” is residual risk.

Identity controls that protect mail

  • MFA enforced for users
  • Legacy authentication blocked
  • CA for Exchange Online
  • Limited global admins; use role-specific admins
  • Audit sign-ins for mail-related legacy protocols

Tenant mail hygiene

  • External forwarding rules reviewed and restricted
  • Auto-forwarding policies intentional
  • Elevated scrutiny on new inbox rules for VIPs
  • Connector inventory — who can send as your domains
  • DKIM/DMARC progression beyond “we set SPF once”

Monitoring

Alert on suspicious forwarding, mass access, and admin role changes. Mail is still the #1 business system; treat it like one in the SOC backlog.

User reporting

Make phish reporting easy. Technology without human sensors misses social engineering that bypasses gateways.

Hybrid server hardening checklist

  • Latest supported CU/SU applied
  • Not published to anonymous internet if avoidable
  • Admin access via PAW/jump only
  • Localized monitoring and EDR coverage
  • Documented decommission or minimize date

Forwarding and BEC-oriented controls

Business email compromise often abuses forwarding rules and consent. Review mailbox rules for external forwards, restrict automatic forwarding in transport, and educate finance on invoice fraud patterns. Technology and awareness both count.

Privileged access to mail

Who can open any mailbox? Limit discovery and eDiscovery roles. Audit use. Separation of duties matters when the same admin can change CA and read executives’ mail.

Incident tabletop

Run a one-hour tabletop: suspected compromised shared mailbox. Who disables rules, resets credentials, reviews audit logs, and communicates? If roles are unclear in the tabletop, they will be unclear in the incident.

Metrics for the security steering group

MetricTarget direction
Internet-facing on-prem Exchange countDown to zero or isolated
Legacy auth sign-insNear zero
MFA coverageUp
External forward rulesReviewed and minimized
Standing Global AdminsDown to break-glass + minimal

Scenario walkthrough

Consider a mid-size organization with hybrid identity, mixed desktop delivery, and a mandate to reduce risk without stopping the business. Week one is inventory and sponsor alignment. Week two is a written target state with two options and explicit out-of-scope items. Weeks three and four are pilot build and measurement. Only then does broad change begin. Compressing that sequence into a single weekend is how outages are born.

Along the way, three conversations dominate: who owns identity decisions, who pays for platform capacity, and what residual risk leadership accepts in writing. When those conversations are avoided, engineers improvise under pressure and the organization inherits accidental architecture.

We keep a living risk register with severity, mitigation, residual risk, and owner. The register is reviewed in the same meeting as the delivery burn-down. Risks that never move owners are the ones that become incidents.

If you're facing this

If mail is in the cloud but security still thinks like 2015 perimeter, run this posture pass. We harden Microsoft 365 identity and Exchange hybrid residuals — bring admin center access and hybrid server inventory.

// related notes
// still relevant?

Facing a migration, platform, or AI build like this one?

This note is part of an archive spanning a decade of infrastructure work. The playbook evolved; the discipline didn't. Tell us what you're trying to ship — we reply within one business day.

Start a project →

← Back to notes