2021 taught the industry that on-prem Exchange on the open internet is a gift to attackers. Even estates that moved mailboxes to Exchange Online still inherit risk through hybrid servers, legacy auth, forwarding abuse, and admin sprawl. This post is a November security posture checklist for Microsoft 365 mail — practical controls after ProxyLogon-era urgency.
Shrink what remains on-prem
If hybrid Exchange still exists:
- Not on the public internet if avoidable
- Patched on an emergency cadence
- Admin access jump-boxed
- Clear timeline to minimize role
Every month of “temporary hybrid forever” is residual risk.
Identity controls that protect mail
- MFA enforced for users
- Legacy authentication blocked
- CA for Exchange Online
- Limited global admins; use role-specific admins
- Audit sign-ins for mail-related legacy protocols
Tenant mail hygiene
- External forwarding rules reviewed and restricted
- Auto-forwarding policies intentional
- Elevated scrutiny on new inbox rules for VIPs
- Connector inventory — who can send as your domains
- DKIM/DMARC progression beyond “we set SPF once”
Monitoring
Alert on suspicious forwarding, mass access, and admin role changes. Mail is still the #1 business system; treat it like one in the SOC backlog.
User reporting
Make phish reporting easy. Technology without human sensors misses social engineering that bypasses gateways.
Hybrid server hardening checklist
- Latest supported CU/SU applied
- Not published to anonymous internet if avoidable
- Admin access via PAW/jump only
- Localized monitoring and EDR coverage
- Documented decommission or minimize date
Forwarding and BEC-oriented controls
Business email compromise often abuses forwarding rules and consent. Review mailbox rules for external forwards, restrict automatic forwarding in transport, and educate finance on invoice fraud patterns. Technology and awareness both count.
Privileged access to mail
Who can open any mailbox? Limit discovery and eDiscovery roles. Audit use. Separation of duties matters when the same admin can change CA and read executives’ mail.
Incident tabletop
Run a one-hour tabletop: suspected compromised shared mailbox. Who disables rules, resets credentials, reviews audit logs, and communicates? If roles are unclear in the tabletop, they will be unclear in the incident.
Metrics for the security steering group
| Metric | Target direction |
|---|---|
| Internet-facing on-prem Exchange count | Down to zero or isolated |
| Legacy auth sign-ins | Near zero |
| MFA coverage | Up |
| External forward rules | Reviewed and minimized |
| Standing Global Admins | Down to break-glass + minimal |
Scenario walkthrough
Consider a mid-size organization with hybrid identity, mixed desktop delivery, and a mandate to reduce risk without stopping the business. Week one is inventory and sponsor alignment. Week two is a written target state with two options and explicit out-of-scope items. Weeks three and four are pilot build and measurement. Only then does broad change begin. Compressing that sequence into a single weekend is how outages are born.
Along the way, three conversations dominate: who owns identity decisions, who pays for platform capacity, and what residual risk leadership accepts in writing. When those conversations are avoided, engineers improvise under pressure and the organization inherits accidental architecture.
We keep a living risk register with severity, mitigation, residual risk, and owner. The register is reviewed in the same meeting as the delivery burn-down. Risks that never move owners are the ones that become incidents.
If you're facing this
If mail is in the cloud but security still thinks like 2015 perimeter, run this posture pass. We harden Microsoft 365 identity and Exchange hybrid residuals — bring admin center access and hybrid server inventory.