A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Hi @Mani
Thank you for reaching out via the Microsoft Q&A forum regarding this issue.
Based on your goal to block external email forwarding across the organization but still allow some specific exceptions, here’s a setup you might want to try:
1. Disable External Forwarding
To begin, you can turn off automatic external forwarding in your anti-spam policy:
- In the Microsoft Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Anti-spam.
- Click on the Anti-spam outbound policy.
- Go to Outbound forwarding rules.
- Under Automatic forwarding, set it to “Off” – this blocks all external forwarding. To allow exceptions, you must create a separate outbound spam policy where automatic forwarding is enabled for specific users. Mail flow rules do not override this setting.
More details can be found here: Configuring and controlling external email forwarding in Microsoft 365
2. Create Security Groups for Approved Users
- Create a security group with users allowed to forward externally.
- Maintain a list of trusted external domains.
3. Configure Mail Flow Rules
In Exchange Admin Center > Mail flow > Rules, create the following rules in this order:
- Rule 1: Allow specific users to forward to specific external recipients
- Rule 2: Allow members of the “ApprovedForwarders” group to forward to trusted domains
- Rule 3: Block all other external auto-forwarding
Make sure the rules are ordered in that sequence, so exceptions are processed before the default block applies.
Important note: This approach should give you the flexibility you need to manage forwarding safely. However, if you've configured everything correctly and forwarding still doesn’t work as expected, it may be due to current platform limitations in Exchange Online. In that case, this would be the closest solution available at the moment.
Feel free to test it out and let us know how it goes, we’re happy to help further if needed!
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.