edit severity forwarding/redirect rule from informational to High

Ray Waldron 41 Reputation points
2023-04-26T13:48:21.1933333+00:00

Hiya, we have an information alert regarding forwarding/redirect rule. We are not firing emails off for informational else we would be swamped with emails. Is there a way to change this forwarding/redirect rule. to high rather than informational , or is there a way to create a new rule to catch this activity, ie ( if a user creates a forwarding rule ( especially to external email ) We already have an active rule in defender (Suspicious inbox forwarding rules ) that is high , but this hasn't fired when a user creates a forwarding rule. And do we have to maintain alerts in 2 sections for 365 ? 1 exchange admin centre - alert policies 2 Microsoft 365 defender - policies and rules. Any help please.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,516 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,626 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,371 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
203 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
143 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Nisreen Faleh Salim 0 Reputation points
    2023-04-26T20:21:38+00:00

    To review the Suspicious Email Forwarding Activity alert, open the Alerts page to see the Activity list section then follow steps shown by Microsoft 365 defender

    0 comments No comments

  2. Aholic Liang-MSFT 13,856 Reputation points Microsoft Vendor
    2023-04-27T09:31:26.5966667+00:00

    Hi @ Ray Waldron,

    Not sure if I understood you correctly, if there is a mistake please correct me.

    Do you mean you want to be able to get alert messages when users create automatic forwarding rules?

    Did the alert policy you created resemble the screenshot below?

    User's image

    If you tested as soon as you created it, not capturing this activity may be expected. Rules or policies created on the cloud take a while to deploy, and we recommend that you wait a few hours before testing to see if anything changes.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.