When a business mailbox gets compromised, resetting the password is only half the job. Attackers often leave behind forwarding rules that quietly copy every new email to an outside address, even after the password has changed.
This guide shows how to audit for those leftovers in Microsoft 365 using PowerShell.
Why this matters
Common persistence tricks after account takeover:
- Inbox rules that forward or redirect mail externally
- Mailbox-level forwarding (
ForwardingSmtpAddress) - Rules that move replies to hidden folders so the owner never sees them
- OAuth apps with mailbox permissions
If you only reset the password, these can keep working.
Prerequisites
- An admin account with permission to read mailbox settings
- The Exchange Online module
Install-Module ExchangeOnlineManagement -Scope CurrentUser
Connect-ExchangeOnline
Test in a non-production tenant or on a single mailbox first, and follow your organization's change policy.
1. Check mailbox-level forwarding
This lists every mailbox that forwards mail somewhere else:
Get-Mailbox -ResultSize Unlimited |
Where-Object { $_.ForwardingSmtpAddress -ne $null -or $_.ForwardingAddress -ne $null } |
Select-Object DisplayName, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward
Anything pointing to an external address you don't recognise deserves a closer look.
2. Check inbox rules for one mailbox
Get-InboxRule -Mailbox user@yourdomain.com |
Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo } |
Select-Object Name, Enabled, ForwardTo, ForwardAsAttachmentTo, RedirectTo
3. Check inbox rules across all mailboxes
For larger tenants, loop through mailboxes (this can take time):
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
Get-InboxRule -Mailbox $_.UserPrincipalName |
Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo } |
Select-Object @{n='Mailbox';e={$_.MailboxOwnerId}}, Name, Enabled, ForwardTo, RedirectTo
}
4. Remove a suspicious rule
Remove-InboxRule -Mailbox user@yourdomain.com -Identity "Rule Name"
To clear mailbox-level forwarding:
Set-Mailbox -Identity user@yourdomain.com -ForwardingSmtpAddress $null -ForwardingAddress $null
5. Sign out active sessions
Using the Microsoft Graph PowerShell module:
Connect-MgGraph -Scopes "User.ReadWrite.All"
Revoke-MgUserSignInSession -UserId user@yourdomain.com
Post-incident checklist
- [ ] Reset the password from a trusted device.
- [ ] Enforce MFA for the account.
- [ ] Remove unknown forwarding rules and mailbox forwarding.
- [ ] Revoke active sessions.
- [ ] Reviewed connected apps and consented to OAuth permissions
- [ ] Review recently sent items for fraud attempts.
- [ ] Check whether regulated data was exposed (e.g., HIPAA, PCI-DSS).
Prevent it next time
- Block automatic external forwarding with an outbound spam policy
- Turn on audit logging and alerts for new inbox rules.
- Require MFA for every user
- Run this audit on a schedule, not only after incidents.
Wrapping up
Hidden forwarding is one of the most common ways account takeovers continue silently. A short scheduled audit catches it early.
I'm Paul, founder of Zia Networks, a managed IT provider supporting small businesses across New Mexico. We also publish a free version for non-technical owners.
What other persistence tricks have you seen after mailbox compromises? Share in the comments.
Top comments (0)