O365 Security & Compliance Center Default Alert Policies

Anonymous
2018-06-14T20:06:09+00:00

Default Rule "Creation of forwarding/redirect rule"

So last night this rule triggered for the first time, wasn't really aware of it in the first place.

Severity:● Low

Time:6/13/2018 10:00:00 PM (UTC)

Activity:MailRedirect

User:******@email.com

Details: MailRedirect. This alert is triggered whenever someone gets access to read your user's email.

Description: This alert is triggered when someone in your organization creates an email forwarding or redirect inbox rules using Outlook web app or Powershell -V1.0.0.2

Now to me this is an incredibly frightening message to receive, since this person has access to extremely sensitive financial information.  So since I was thinking this person had been compromised, I sprung out of bed, changed the password on the users account, logged in as the user so I could find out where this persons email was going.  Come to find out that this person was accessing their OWA and forwarding to another user in the department because they are leaving for vacation.

I have 250 odd users, I couldn't imagine a large environment the staff being barraged by this alert.  It would literally numb them to the situation until the day they got compromised and have zero idea because they turned the rule off.  It is counter productive to what it is trying to do.

Being summer we have a lot of users that go on vacation (or take days off) that forget to forward email.  I have given them instructions to use the OWA in those situations.  I would like to suggest in the least, maybe some information like which email account is it being forwarded to as then all a person has to do and look at the message, without having to dig into the issue.  Or maybe if the email is being forwarded intercompany that the alert does not trigger.  

There does not appear to be a way to edit this alert.  It is either on or off.

Am I missing something?

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2018-06-15T04:22:04+00:00

    Hello Joel,

    Thanks for your posting here. When we use the default alert policy, we can do:

    1. Turn it off.
    2. Set up a list of recipients to send email notifications to.
    3. Set a daily notification limit.

    The other settings for this policy can't be edited.

    For deatiled information, please see:

    https://support.office.com/en-us/article/alert-policies-in-the-office-365-security-compliance-center-8927b8b9-c5bc-45a8-a9f9-96c732e58264#managingalerts

    If you still need to edit the default alert policy, we recommend you feedback your requirement to our related team via the link below:

    https://office365.uservoice.com/forums/289138-office-365-security-compliance

    You can vote an exist idea or post a new there.

    If you need further help, please feel free to let us know.

    Regards,

    Rudy

    Rudy,

    I appreciate your response, honestly the links you provided have long been Googled before I asked my question.

    The resolutions provided are unacceptable as they negate the usefulness of the alert system altogether.

    1. Turn it off.. makes it useless.
    2. The alerts go to me... hence why I asked the question.
    3. What if my company is hit by a malware and I set the threshold at 10, I may not know every account compromised. 

    This feature was executed with an embarrassing level of thought.  Yes I am sure they will update it (I hope) but dumping a this level of beta into an ecosystem is disgusting.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-06-16T16:34:31+00:00

    I think you have misunderstood me.  The users are not sharing account information.

    User X logged into their OWA and forwarded their email to user Y.  User Y does not know users X's password.  User Y is just handling users X's email while user X is on vacation. 

    I understand using groups and team mailboxes are the optimal position for some situations but in this case there are items that are directed specifically toward user X which are time sensitive thus the necessity for the robust "forward email to another user" system built into the Microsoft Office 365. 

    The feedback I have is as I asked in the initial post is a way to either turn off the alert for users who forward email to another user inside the domain or what would be the best situation is adding language in the alert email (which was copied and pasted from in the first post) is a line stating which email address the user forwarded their email to.

    Example in bold below

    *Severity:* Low

    Time:6/13/2018 10:00:00 PM (UTC)

    Activity:MailRedirect

    User:*****@email.com*

    **forwarded their email to ****@DOMAIN.COM

    Details: MailRedirect. This alert is triggered whenever someone gets access to read your user's email.

    Description: This alert is triggered when someone in your organization creates an email forwarding or redirect inbox rules using Outlook web app or Powershell -V1.0.0.2

    This one simple line added to the alert email, I could determine if any action needs to be taken within seconds instead of having to chase down false positives.

    Thanks for your time

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-06-14T23:36:51+00:00

    Hello Joel,

    Thanks for your posting here. When we use the default alert policy, we can do:

    1. Turn it off.
    2. Set up a list of recipients to send email notifications to.
    3. Set a daily notification limit.

    The other settings for this policy can't be edited.

    For deatiled information, please see:

    https://support.office.com/en-us/article/alert-policies-in-the-office-365-security-compliance-center-8927b8b9-c5bc-45a8-a9f9-96c732e58264#managingalerts

    If you still need to edit the default alert policy, we recommend you feedback your requirement to our related team via the link below:

    https://office365.uservoice.com/forums/289138-office-365-security-compliance

    You can vote an exist idea or post a new there.

    If you need further help, please feel free to let us know.

    Regards,

    Rudy

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-06-17T14:41:03+00:00

    Hello Joel,

    I'm agree with you. It is a great idea that adding a detailed explanation of what the user did causing the alert to trigger. We strongly recommend you feedback it to our releated team via that link I mentioned above if you haven't done it. If you have done it, we welcome you share the link here to let more users who have the same requirement with you to vote it.

    Thanks for your clarification and effort.

    Regards,

    Rudy

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-06-16T01:39:27+00:00

    Hello Joel,

    Thanks for your reply. From your description above, this user's colleague access to his/her messages and forward the messages to others which shows that they have shared the account information with each other. Actually, we recommend not sharing personal account information with others, even colleagues.

    From a safe and convenient point of view, we have mail enabled Office 365 Group and Shared Mailbox for team-assisted work. And the group and shared mailbox memebers can send and receive emails in their own mailbox. In this way, the alerts will not be easily triggered.

    Meanwhile, as I mentioned above, you can feel free to feedback any suggestion about your requirement to our related team. Your time is appreciated.

    Regards,

    Rudy

    Was this answer helpful?

    0 comments No comments