To review the Suspicious Email Forwarding Activity alert, open the Alerts page to see the Activity list section then follow steps shown by Microsoft 365 defender
edit severity forwarding/redirect rule from informational to High
Hiya, we have an information alert regarding forwarding/redirect rule. We are not firing emails off for informational else we would be swamped with emails. Is there a way to change this forwarding/redirect rule. to high rather than informational , or is there a way to create a new rule to catch this activity, ie ( if a user creates a forwarding rule ( especially to external email ) We already have an active rule in defender (Suspicious inbox forwarding rules ) that is high , but this hasn't fired when a user creates a forwarding rule. And do we have to maintain alerts in 2 sections for 365 ? 1 exchange admin centre - alert policies 2 Microsoft 365 defender - policies and rules. Any help please.
2 answers
Sort by: Most helpful
-
-
Aholic Liang-MSFT 13,856 Reputation points Microsoft Vendor
2023-04-27T09:31:26.5966667+00:00 Hi @ Ray Waldron,
Not sure if I understood you correctly, if there is a mistake please correct me.
Do you mean you want to be able to get alert messages when users create automatic forwarding rules?
Did the alert policy you created resemble the screenshot below?
If you tested as soon as you created it, not capturing this activity may be expected. Rules or policies created on the cloud take a while to deploy, and we recommend that you wait a few hours before testing to see if anything changes.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.