Managing Inbox Rule for specific users groups or domains

Anielka Oliveros 110 Reputation points
2024-04-09T20:47:11.38+00:00

I have a large tenant with different domains, and having some issues with compromised accounts creating inbox rules and sending to all students phishing emails. Is there any possible way to block the creation of inbox and/or forwarding rules for a specific domain or group (or other category like Custom Attribute or similar)?

Or is there any policy I can configure to manage the type of characters allowed in the inbox rule (OWA or Outlook Client)?

I saw a post in Microsoft but is not possible for Outlook client.

I hope someone have an answer with some examples.

Thanks in advance

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,189 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jake Zhang-MSFT 1,235 Reputation points Microsoft Vendor
    2024-04-10T08:40:16.08+00:00

    Hi @Anielka Oliveros ,

    I did some research on your question and found that it is indeed not possible to block the creation of inbox rules and forwarding rules for specific domains or groups, and there is no relevant policy to manage the types of characters allowed in inbox rules.

    However, there may be other ways you can solve the problem you are experiencing, and I have some ideas to suggest:

    1. You can use the following format of the command in the Exchange Online Management shell to prevent a single user from creating any new rules in your server:

    Set-Mailbox -Identity [User's Email Address] -RulesQuota 0

    2.If you receive a phishing email with a fixed sender, subject, body, etc., you can set up a mail flow rule to block emails from that recipient/subject/body, etc. For specific operations, you can refer to the screenshot below to set up blocking fixed senders in the Exchange Online Management Center.

    Inkedimage (1)_LI