2026 Critical Enterprise Intrusion Chain Detection: External Mail Forwarding Configured on Compromised Mailbox

Detects mailbox configuration changes in Exchange Online where email forwarding (ForwardingSmtpAddress, ForwardingAddress, or DeliverToMailboxAndForward) is enabled to an external, non-tenant domain. This technique is commonly used for persistence and data exfiltration following account compromise, allowing attackers to redirect incoming communications to an external mailbox even after the original account credentials have been reset.