Insights

Changes to external email forwarding in Microsoft 365

Changes are being made to how mail from Office 365 is forwarded to external email accounts.

Office 365 has allowed users to create rules to automatically forward email to external email addresses. This is useful when you want to share certain emails automatically with an external party (for example, e-mails from school being sent to your partner) or send information into another system.

But unfortunately, like many things intended for good, this can also be used for evil. Often automatic forwarding rules can be set up by hackers to extract sensitive information from a company email address and forward it to a third party automatically.

As a result, Microsoft is changing the default “posture” for email forwarding to external recipients to be disabled. This means that users will no longer be able to automatically forward emails to an e-mail address outside their company, unless it is explicitly allowed by an admin. This change comes into effect next Tuesday (1st September).

In a few months, they will also reset the policy for any existing forwards that have not been explicitly allowed under the new rules.

We’re working with our customers that might be affected to help them identify an appropriate policy for their organisation and to put in place sensible defaults.

You can read more about the planned change on the Microsoft 365 Roadmap here.

Enjoyed this? Subscribe.

New posts on cybersecurity, cloud and the real-world problems we solve — straight to your inbox.

Email me about

We’ll email you new posts and you can unsubscribe anytime. See our privacy policy.

Want to talk it through?

If this raised questions about your own setup, call us — no pressure, just a conversation.

1300 798 718